1 Jun 1999 14:54
argus 1.8 suggestions list
Carter Bullard <cbullard <at> nortelnetworks.com>
1999-06-01 12:54:29 GMT
1999-06-01 12:54:29 GMT
Gentle People,
I'm finishing up on the 1.8 changes, and there
have been a number of suggestions for changes in
some of the programs and utilities. I would like
to get a feel for what the wish list would look
like. If you would like to alpha/beta test 1.8
please send me mail.
Here is the list as I have it today. Most are
related to ra(). I know that this is not complete
so if there is anything missing, please send mail.
Any suggestion is welcome.
Argus()
1. read compress and gzip'd files automatically.
Ra() (all argus clients)
1. extend filter expression.
I've already added new tokens for:
1. TCP states (syn synack data fin finack)
2. ICMP types (echo unreach redirect)
I'm looking into supporting 'greater' and 'less'
for port numbers.
2. reverse '-n' flag logic.
use the -n to turn on name resolution,
default is no resolution.
2. modify and internationalize default time output.
(Continue reading)
First data from server in detail mode:
argus <at> k-meter argus]$ grep '\.80 ' june/139.80.75.71
Wed 06/23 16:03:09 icmp xxx.yy.75.71 -> 130.216.85.131 1 0 ECO
Wed 06/23 16:03:09 icmp xxx.yy.75.71 <-> 130.216.85.131 1 1 ECO
Wed 06/23 16:03:24 tcp xxx.yy.75.71.41325 <?> 130.216.85.131.80 1 0 0 0 EST
Wed 06/23 16:03:24 tcp xxx.yy.75.71.41325 <| 130.216.85.131.80 0 1 0 0 RST
the same session reported by the other server was:
Wed 06/23 16:03:09 icmp xxx.yy.75.71 <-> 130.216.85.131 1 1 ECO
Wed 06/23 16:03:24 tcp xxx.yy.75.71.41325 <| 130.216.85.131.80 1 1 0 0 RST
This caught my eye because traffic to that address should be blocked
at our packet filter (the argus machines are outside the packet
filter).
These are the first packets of the scan i.e. a ping followed by a tcp
packet to port 80. These were followed by a normal port scan with
RSS Feed