Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 24 Jun 2005 02:11:05 GMT
From:      Corey Smith <corsmith@gmail.com>
To:        freebsd-gnats-submit@FreeBSD.org
Subject:   ports/82596: New port: net/flowgrep TCP stream/UDP/IP payload 'grep' utility
Message-ID:  <200506240211.j5O2B5XV072660@www.freebsd.org>
Resent-Message-ID: <200506240220.j5O2KHn6085228@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help

>Number:         82596
>Category:       ports
>Synopsis:       New port: net/flowgrep TCP stream/UDP/IP payload 'grep' utility
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    freebsd-ports-bugs
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          change-request
>Submitter-Id:   current-users
>Arrival-Date:   Fri Jun 24 02:20:17 GMT 2005
>Closed-Date:
>Last-Modified:
>Originator:     Corey Smith
>Release:        5.4-STABLE
>Organization:
>Environment:
FreeBSD csmith-dt.corsmith.yi.org 5.4-STABLE FreeBSD 5.4-STABLE #0: Thu Jun 16 15:41:01 EDT 2005     root@:/usr/src/sys/i386/compile/MINIMAL  i386
>Description:
This new port depends on net/pynids available in ports/82593

flowgrep is a basic IDS/IPS tool written in python as a way to help you
investigate and manage your network. it works by sniffing traffic, reassembling TCP streams, and IP and UDP fragments into single packets, and allowing you to "grep" through their payloads using regular expressions. the quality of the regular expression engine is similar to Perl's. think of it as a marriage of tcpflow, tcpkill, and ngrep.

WWW: http://www.monkey.org/~jose/software/flowgrep/

- Corey Smith
corsmith@gmail.com
>How-To-Repeat:
      
>Fix:
begin 644 flowgrep.shar
M(R!4:&ES(&ES(&$@<VAE;&P@87)C:&EV92X@(%-A=F4@:70@:6X@82!F:6QE
M+"!R96UO=F4@86YY=&AI;F<@8F5F;W)E"B,@=&AI<R!L:6YE+"!A;F0@=&AE
M;B!U;G!A8VL@:70@8GD@96YT97)I;F<@(G-H(&9I;&4B+B`@3F]T92P@:70@
M;6%Y"B,@8W)E871E(&1I<F5C=&]R:65S.R!F:6QE<R!A;F0@9&ER96-T;W)I
M97,@=VEL;"!B92!O=VYE9"!B>2!Y;W4@86YD"B,@:&%V92!D969A=6QT('!E
M<FUI<W-I;VYS+@HC"B,@5&AI<R!A<F-H:79E(&-O;G1A:6YS.@HC"B,)9FQO
M=V=R97`*(PEF;&]W9W)E<"]D:7-T:6YF;PHC"69L;W=G<F5P+W!K9RUD97-C
M<@HC"69L;W=G<F5P+TUA:V5F:6QE"B,*96-H;R!C("T@9FQO=V=R97`*;6MD
M:7(@+7`@9FQO=V=R97`@/B`O9&5V+VYU;&P@,CXF,0IE8VAO('@@+2!F;&]W
M9W)E<"]D:7-T:6YF;PIS960@)W,O7E@O+R<@/F9L;W=G<F5P+V1I<W1I;F9O
M(#P\("=%3D0M;V8M9FQO=V=R97`O9&ES=&EN9F\G"EA-1#4@*&9L;W=G<F5P
M+3`N."YT87(N9WHI(#T@864X9#`T-S!F9CAB-V0T-C`Q,#0R-S5A,6-C-V(R
M-F(*6%-)6D4@*&9L;W=G<F5P+3`N."YT87(N9WHI(#T@-S,Y-@I%3D0M;V8M
M9FQO=V=R97`O9&ES=&EN9F\*96-H;R!X("T@9FQO=V=R97`O<&MG+61E<V-R
M"G-E9"`G<R]>6"\O)R`^9FQO=V=R97`O<&MG+61E<V-R(#P\("=%3D0M;V8M
M9FQO=V=R97`O<&MG+61E<V-R)PI89FQO=V=R97`@:7,@82!B87-I8R!)1%,O
M25!3('1O;VP@=W)I='1E;B!I;B!P>71H;VX@87,@82!W87D@=&\@:&5L<"!Y
M;W4*6&EN=F5S=&EG871E(&%N9"!M86YA9V4@>6]U<B!N971W;W)K+B!I="!W
M;W)K<R!B>2!S;FEF9FEN9R!T<F%F9FEC+"!R96%S<V5M8FQI;F<*6%1#4"!S
M=')E86US+"!A;F0@25`@86YD(%5$4"!F<F%G;65N=',@:6YT;R!S:6YG;&4@
M<&%C:V5T<RP@86YD(&%L;&]W:6YG('EO=2!T;PI8(F=R97`B('1H<F]U9V@@
M=&AE:7(@<&%Y;&]A9',@=7-I;F<@<F5G=6QA<B!E>'!R97-S:6]N<RX@=&AE
M('%U86QI='D@;V8@=&AE"EAR96=U;&%R(&5X<')E<W-I;VX@96YG:6YE(&ES
M('-I;6EL87(@=&\@4&5R;"=S+B!T:&EN:R!O9B!I="!A<R!A(&UA<G)I86=E
M(&]F"EAT8W!F;&]W+"!T8W!K:6QL+"!A;F0@;F=R97`N"E@*6%=75SH@:'1T
M<#HO+W=W=RYM;VYK97DN;W)G+WYJ;W-E+W-O9G1W87)E+V9L;W=G<F5P+PI8
M"E@M($-O<F5Y(%-M:71H"EAC;W)S;6ET:$!G;6%I;"YC;VT*14Y$+6]F+69L
M;W=G<F5P+W!K9RUD97-C<@IE8VAO('@@+2!F;&]W9W)E<"]-86ME9FEL90IS
M960@)W,O7E@O+R<@/F9L;W=G<F5P+TUA:V5F:6QE(#P\("=%3D0M;V8M9FQO
M=V=R97`O36%K969I;&4G"E@C($YE=R!P;W)T<R!C;VQL96-T:6]N(&UA:V5F
M:6QE(&9O<CH)9FQO=V=R97`*6",@1&%T92!C<F5A=&5D.@D),C(@2G5N(#(P
M,#4*6",@5VAO;3H)"0E#;W)E>2!3;6ET:`I8(PI8(R`D1G)E94)31"0*6",*
M6`I84$]25$Y!344]"69L;W=G<F5P"EA03U)45D524TE/3CT),"XX"EA#051%
M1T]22453/0EN970@<V5C=7)I='D*6$U!4U1%4E]3251%4ST):'1T<#HO+W=W
M=RYM;VYK97DN;W)G+WYJ;W-E+W-O9G1W87)E+V9L;W=G<F5P+PI81$E35$Y!
M344]"69L;W=G<F5P+21[4$]25%9%4E-)3TY]"E@*6$U!24Y404E.15(]"6-O
M<G-M:71H0&=M86EL+F-O;0I80T]-345.5#T)5$-0('-T<F5A;2]51%`O25`@
M<&%Y;&]A9"`G9W)E<"<@=71I;&ET>0I8"EA254Y?1$5014Y$4ST))'M0651(
M3TY?4TE414Q)0D1)4GTO;FED<VUO9'5L92YS;SHD>U!/4E131$E2?2]N970O
M<'EN:61S"E@*6%5315]0651(3TX]"5E%4PI8"EA03$E35%]&24Q%4ST)<V)I
M;B]F;&]W9W)E<`I8"EA-04XX/0EF;&]W9W)E<"XX"E@*6"YI;F-L=61E(#QB
M<V0N<&]R="YP<F4N;6L^"E@*6&1O+6EN<W1A;&PZ"E@))'M)3E-404Q,7U-#
M4DE05'T@)'M74DM34D-]+V9L;W=G<F5P+G!Y("1[4%)%1DE8?2]S8FEN+V9L
M;W=G<F5P"E@))'M)3E-404Q,7TU!3GT@)'M74DM34D-]+V9L;W=G<F5P+C@@
M)'M04D5&25A]+VUA;B]M86XX+V9L;W=G<F5P+C@*6`I8+FEN8VQU9&4@/&)S
M9"YP;W)T+G!O<W0N;6L^"D5.1"UO9BUF;&]W9W)E<"]-86ME9FEL90IE>&ET
""@H`
`
end

>Release-Note:
>Audit-Trail:
>Unformatted:



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200506240211.j5O2B5XV072660>