dos and ddos attacks
Gnome Attacks 0.3
Gnome Attacks is a bomb them down to the ground with one finger game. more>>
Gnome Attacks is a Gnome 2 game where you bomb cities into oblivion in order to make a flat surface for your rapidly-losing-height spaceship to land.
It is extremely accessible since you can control it "simply using one finger."
The current release allows you to flatten Londons most famous landmarks!
How to play:
- To Start: open a terminal and type "gnomeattacks" and then RETURN. Thats it.
- Keys: press any key to drop a bomb. Thats it.
- Objective: bomb all the buildings down to the ground. Thats it.
Enhancements:
- linc
Enhancements:
- A new level set using real photos of London was created.
- The capability to control the heights of buildings was introduced.
- The user can now create n

Titan Attacks! 1.9
An arcade game where you have to defend the Solar System from Evil Alien Invaders! more>>
Titan Attacks! 1.9 will provide hours of entertainment for everyone. This is designed as an arcade game where you have to defend the Solar System from Evil Alien Invaders!
The Earth is under attack from evil aliens from Titan! Only you can save us all using a hired space ship. Upgrade your ship with bounty money and drive back the Titans across the Solar System, and defeat them on their homeworld.
Titan Attacks has the same easy-to-learn and addictive gameplay of the classic arcade shoot 'em up, but is packed full of extras - new features, new strategies, and stylish neo-retro visuals. Battle swarms of alien fighters, bombers and giant boss motherships, over 5 unique worlds and 100 levels of frantic action! Earn bounty money and upgrade your ship with extra cannon, rockets and lasers!
You can destroy falling wrecks, dodge hurtling asteroids and capture escaping aliens - or blast them from the skies! Win prizes in sharp-shooter challenge stages and compete on the online hiscores table!
Major Features:
- 100 levels of frantic shooter action
- 5 giant boss motherships
- Upgrade your ship with extra cannon, rockets and lasers
- Challenge stages with prizes
- Online hiscore table
Requirements:
- Java 2 Standard Edition Runtime Environment
Break Attack 1
Break Attack is a remake of arkanoid. more>>
This game is a remake of arkanoid. You have to hit all these bricks with the ball and dont let the ball reach the bottom. This game is in spanish, sorry for that.
It was made to show the usage of Jedi-SDL library with Pascal. It compiles with freepascal.
4st Attack 2.1.4
4st Attack is a good looking connect-four with multiplayer support. more>>
4st Attack is a good looking connect-four with multiplayer support.
Port Scan Attack Detector 2.0.8
The Port Scan Attack Detector (psad) is a collection of three system daemons that are designed to work with the Linux Netfilter. more>>
Port Scan Attack Detector project features a set of highly configurable danger thresholds (with sensible defaults), verbose alert messages, email alerting, DShield reporting, and automatic blocking of offending IP addresses.
Psad incorporates many of the packet signatures included in Snort to detect various kinds of suspicious scans, and implements the same passive OS fingerprinting algorithm used by p0f.
Enhancements:
- A --gnuplot mode was added so that psad can output data that is suitable for plotting with gnuplot.
- The ability to negate match conditions on fields specified with the --CSV-fields argument was added.
- The Storable-2.16 module was added along with the --use-store-file argument so that in --gnuplot mode the Gnuplot data can be stored on disk and retrieved quickly.
- --analysis-fields was added so the iptables log messages that are parsed in -A mode can be restricted to those that meet certain criteria.
Sshguard 1.1 Beta 1
Sshguard protects networked hosts from the todays widespread brute force attacks against ssh servers. more>>
This project is BSD licensed.
How sshguard works
Sshguard monitors ssh servers from their logging activity. It reacts to messages about dangerous activity by blocking the source address with the local firewall.
Messages describing dangerous activity can be easily customized with regular expressions; this makes sshguard theorically usable with any login server, and in general anything that logs something, although no experiments have been made outside ssh.
Sshguard can operate all the major firewalling systems:
- PF (OpenBSD, FreeBSD, NetBSD, DragonFly BSD)
- netfilter/iptables (Linux)
- IPFIREWALL/ipfw (FreeBSD, Mac OS X)
Main features:
- a very large part of these tools are simple scripts. So, they require a permanent interpreter application which usually takes a lot of system memory. Which, on servers, is very precious.
Sshguard is written in C, and designed to be 0-impact on system resources.
- several tools require customization (hack & play).
Sshguard is designed for extreme ease of use (plug & play).
- many tools are OS- or firewall-specific (usually Linux).
Sshguard is designed to work on many OSes and can operate several firewall systems; see Compatibility.
- nearly all tools are constraintly written for their operating scenario.
Sshguard can be extended for operating with custom/proprietary firewalls with very very few effort.
Enhancements:
- support suspension
- fix parser bug when recognizing certain IPv6 addresses
- support debug mode at runtime for helping users in problem solving
- *EXPERIMENTAL* support for ipfilter as blocking backend
- *EXPERIMENTAL* support for log messages authentication
scanlogs 2.2.6
scanlogd is a TCP port scan detection tool, originally designed to illustrate various attacks. more>>
This release of scanlogd can be built with support for one of several packet capture interfaces. In addition to the raw socket interface on Linux (which does not require any libraries), scanlogd is now aware of libnids and libpcap.
The use of libpcap alone is not a good idea. If youre on a system other than Linux and/or want to monitor the traffic of an entire network at once, you should be using libnids in order to handle fragmented IP packets.
GNU/DOS 2006 SR1
GNU/DOS is a distribution of FreeDOS. more>>
Main features:
- Several core FreeDOS packages
- The DJGPP development environment with many GNU programs
- The Arachne Web browser and e-mail client
- The OpenGEM graphical user interface with many GEM programs
- The vim editor for developers
- The MTXE screen saver
- GPL, GPL with DJGPP exceptions, vim, Artistic License, Jason Hood License, and LGPL licensed source code for all of the above
GNU/DOS is very well suited for:
- Web and e-mail (no Java or other "plugins") through a dial-up modem (not a "Winmodem") or Ethernet connection
- Classic DOS and console UNIX applications and games
- Development (using the GNU Compiler Collection)
- And more!
Enhancements:
- This release features various updates, bugfixes, and new programs.
- Arachne 1.90 and vim 7.0 were included along with various DJGPP updates and a bootable CD installation option.
dotDefender Monitor for Apache Linux 3.84
dotDefender Monitor for Apache is the only way to know who is attacking your web site in real time. Residing on the server as webserver plug-in, dotDefender can be installed and implemented in minutes without influence on traffic or network archite more>>
dotDefender Monitor inspects the actual HTTP/HTTPS requests for suspicious patterns that may indicate an attack, regardless of their source URL. This includes requests in content such as HTML, SOAP and XML.
- Immediately identify web application attacks.
- Identify sources of insider attacks.
- Receive real-time information about attempts to attack websites and internal applications
- View detailed statistics about attackers and attack attempts
- Receive automatic updates for detecting new threats
- Gain insight into your web application security posture
Major Features:
- Installation: ISAPI filter for IIS & a module for Apache
- Configuration possibility
- Comprehensive Logging
- Central Management
- Applicure Support
Requirements: Requires Apache Server
WareSeeker Editor
Logscan 0.4
Logscan provides a tool to generate emails in response to security probes or attacks. more>>
Logscan is a tool to assist in generating complaint emails in response to security probes or attacks. Logscan scans through logs looking for patterns and if certain thresh-holds are reached it sends a template email to the local administrators for approval. If the administrator sees the attack is not a mistake they can forward the email to the ISP who owns the attacking IPs.
Logscan has the beginings of an interesting module/library called "whois" which is loosely based on work by Scott Hassan.
This module traverses the tree of various whois servers untill it finds the whois record for the ISP that owns the offending IP and then grabbing the emails of admins responsible there.
As this module evolves it will grab other pieces of information from the whois record (unfortunately there appears to be a variety of formats for whois records).
Panoptis 0.1.4
Panoptis plans to create a network security tool (N-IDS) to detect and block DoS and DDoS attacks. more>>
First, you need a router that exports NetFlow(TM) data. Versions 1, 5 and 8 are supported, although version 8 has not been tested AT ALL. You also need a server for accepting data and processing it.
In order to compile the software you need a C++ compiler (tested only with g++ for the time being) and the CommonC++ library, found at http://www.gnu.org/software/commonc++/CommonC++.html At the moment the software has been linked against and tested with commoncpp2-1.0.9
YOU WILL ALSO NEED g++ VERSION 3.x!!! This is very important! Compiling with g++ 2.95.x or earlier versions causes segmantation faults in some cases. This has to do with CommonC++, not Panoptis.
Before you can use the software, you must also have read SNMP access to your router. That is only needed by the speeds.py script that collects some initial information (the .py extention should already make you think youll need the Python programming language installed -- thats true.
Enhancements:
- Update so that Panoptis compiles and runs on newer systems (GCC 3.3.5, CommonC++2 1.5.3).
- No new features, unfortunately.
Block Attack - Raise of the Blocks 1.3.0
Block Attack - Raise of the Blocks is another block fall game based on Tetris Attack. more>>
Block Attack - Raise of the Blocks is a block fall game. Like Tetris Attack and Crack Attack, block are raising from the floor and the player must clear them before they touch the roof.
Blocks are cleared by making a line of three blocks in the same color horizontally or vertically, and blocks can only be changed horizontally.
The goal is to either get as much points as possible, get as much point in two minutes, clear all blocks in limited moves and clear a number of lines.
Two player slit screen is available. Two players can compete in Time Trial (who gets most points in two minutes) or Vs. mode where clearing more than 3 blocks trows blocks at the opponent.
IDND 1.4
IDND is a Firefox extension that puts a little flag in the status bar that tells you whether you are visiting a TDN or a IDN. more>>
IDNs can be used for phishing or spoofing, so suspicious IDNs cause an optional alert box to appear further warning you to take care. This is in no way sufficient protection against all kinds of spoofing, but does add to your browsers defences.
In the status bar a green or blue flag shows whether the current page has a traditional (A-Z 0-9 -) or an international domain name. In this way you have more protection against homograph attacks.
Worm Warner 2.3
WormWarner is a tool designed to warn hosts that are probably infected by worms. more>>
Wormwarner has a simple pattern database which makes it easy to add new worm patterns as they appear. Another important feature is the build in rate and mail size control which avoids that wormwarner sends out to much email to an ISP. Wormwarner has also the option to excute external commands, which makes it easy to adapt i.e. firewalls based on the attacks and worms detected by wormwarner.
However there were features requests and the application grown in complexity. The goal of the wormwarner project is to provided users with a powerful and flexible, but benign tool to take action against worms and attacks on their webserver(s).
Enhancements:
- The attack complaint message was changed to a less offensive one.
- "GET /scripts/nsiislog.dll" was added to the attack patterns.
- Various formmail exploits were added to the attack patterns.
- Added the smtp option to specify a mailserver to use to send the warnings to the ISP.
- Patterns are now stored in pattern.db which makes it easier to add patterns.
- The IIS WebDAV exploit was added to the patterns
And-httpd 0.99.11
And-httpd is an HTTP server that currently only maps URLs to files. more>>
And-httpd cannot do CGI or other kinds of code execution. And-httpd cannot even dynamically create directory listings.
Design is a statemachine triggering off IO events, somewhat like thttpd and boa (among others).
Simple tests with ab show it to be about twice as fast as thttpd-2.20c (note that thttpd doesnt support keep-alive, which gives and-httpd a significant advantage -- mainly due to usage of Vstr).
Uses the following system utilities:
poll or epoll, multiplexing
multiple process support. for MP systems
sendfile or mmap, for file contents
LFS
TCP_CORK
TCP_DEFER_ACCEPT
posix_fadvise()
chroot, privilage de-escalation (can also easily be started as non-root)
does a bind mount for /dev/log when in a chroot.
socket filters
IP binding
Is HTTP/1.1 conditionally compliant, as far as I know (and I have tests to prove some of it :).
Supports optional HTTP/1.1 features:
Accept header for Content-Type.
0.9 HTTP compatability support
keep-alive, on by default for 1.1 and 1.0
virtual hosts (via. prefix directories and explicit configuration statements)
if-modified-since/if-unmodified-since
byte ranges (single and multipart/byteranges)
if-range
multipart/byteranges can also be limited to prevent DOS attacks.
accept-encoding/content-encoding for gzip/bzip2 (via. pre-generated files)
Also fully obeys identity
ETags
accept-language negotiation to serve multiple languages
Parses /etc/mime.types file plus extensions for disallowing certain file types.
Can be run "easily" Ie. "and-httpd foo" will start a web server listening on port 80 or 8008 (depending in if you are uid zero) serving the contents of the directory "foo".
Configuration file parser.
Also has optional "per request" configuration files (using the same code, and thus layout, as the main configuration files), allowing you to:
Generate explicit Content-Types.
Generate negotiated Content-Types for requests with multiple types.
Eg. http://www.and.org/vstr/examples/httpd.c is available as text/plain and text/html
Generate Content-MD5 data
Generate Content-Location data.
Generate Expires and Cache-Control data.
Generate all four types of redirects.
Generate the usable types of error conditions.
Change the file object used to serve the data.
Has a native ACL configuration (can also use Linux socket filters).
All "configuration parameters" done through policies.
Change configuration policy based on ip address connections.
Change configuration policy based on many parameters of the request.
Automatically generate the "right" Vary header based on which fields of the request were tested.
includes init.d file, and allows "local controller" connections for soft restarts, status information etc.
Converter to make log files that look like apache-httpd combined log files.
DOES NOT:
Auto generate directory listings (see ex_dir_list2html in Vstr examples)
SSI, or other file contents parsing (see ex_ssi in Vstr examples)
Run programs (doesnt call exec at all, only calls fork() at startup for MP systems).
Call any i18n/gettext libc functions (will be fixed).
Parse or honor the Accept-Charset header.
Full date parser (not a problem, string matches work well).