Commit graph

941 commits

Author SHA1 Message Date
Martin Wilke
476cb9b104 2007-11-22 x11-themes/indubstrial: yes
2008-01-14 x11-themes/gtk-smooth-engine: Redundant port (now included in gtk-engines), no release since 2005
2007-09-21 security/amavis-perl: depends on misc/compat3x, which has security problems
2007-12-31 sysutils/cdbakeoven: Abandonware
2008-01-04 net/gnu-finger: no active development and known security vulnerabilities.
2007-11-16 misc/seizedesktop: development stalled for years, outdated, unmaintained
2008-02-28 01:07:11 +00:00
Rong-En Fan
a2eafa3950 EasyPG is an all-in-one GnuPG interface for Emacs. It consists of two
parts: EasyPG Assistant and EasyPG Library.

EasyPG Assistant is a set of convenient tools to use GnuPG from
Emacs. EasyPG Library is a sort of an elisp port of GPGME, a wrapper
library which provides API to access some of the GnuPG functions.

WWW: http://sourceforge.jp/projects/epg/

PR:		ports/119008
Submitted by:	Shota Iwazaki <iwazaki8 at yahoo.co.jp>
2008-02-26 05:58:58 +00:00
Martin Wilke
b05569d999 This Module decrypts all kind of Cisco encrypted hashes
also referred to as type 7 passwords. Further you can
encrypt any given string into a encrypted hash that will
be accepted by any Cisco device as an encrypted type 7 password.

WWW:	http://search.cpan.org/dist/Cisco-Hash/

PR:		ports/120498
Submitted by:	Tsung-Han Yeh <snowfly at yuntech.edu.tw>
2008-02-16 23:24:00 +00:00
Martin Wilke
389e237156 Implementation of the Diffie-Hellman Key Exchange cryptographic protocol
in PHP5. Enables two parties without any prior knowledge of each other
establish a secure shared secret key across an insecure channel
of communication.

WWW: http://pear.php.net/package/Crypt_DiffieHellman/

PR:		ports/120010
Submitted by:	Ditesh Shashikant Gathani <ditesh at gathani.org>
2008-02-12 22:43:48 +00:00
Lars Engels
972df28ee3 FCheck is an open source PERL script providing intrusion detection and policy
enforcement of Windows 95/98/NT/3.x and Unix server administration through the
use of comparative system snapshots. FCheck can provide notification of any
differences found through use of your event management system, printer, and/or
email when any monitored files or directories are altered, including any
additions and/or deletions.

WWW:    http://www.geocities.com/fcheck2000/
2008-02-07 23:34:08 +00:00
Rong-En Fan
68e4044efb Sqlninja is a tool targeted to exploit SQL Injection vulnerabilities on
a web application that uses Microsoft SQL Server as its back-end.

Its main goal is to provide a remote shell on the vulnerable DB server,
even in a very hostile environment. It should be used by penetration
testers to help and automate the process of taking over a DB Server when
a SQL Injection vulnerability has been discovered.

WWW: http://sqlninja.sourceforge.net/

PR:		ports/117276
Submitted by:	Valerio Daelli <valerio.daelli at gmail.com>
2008-02-07 16:57:28 +00:00
Wesley Shields
e2ac57bf22 New port: p5-Snort-Rule.
A module that facilitates the dynamic creation of rules for snort.

PR:		ports/120193
Submitted by:	Paul Schmehl <pauls@utdallas.edu>
Approved by:	garga (mentor)
2008-02-06 16:23:07 +00:00
Martin Wilke
b53d9e87d0 Network Security Monitoring Console is a framework for performing
analysis on packat capture files.

WWW:	http://thnetos.wordpress.com/nsm-console/

PR:		ports/119682
Submitted by:	Tomoyuki Sakurai <cherry at trombik.org>
2008-01-21 11:56:43 +00:00
Beech Rintoul
7e39acb4e5 - New Port maia-1.0.2a
- Maia Mailguard is a web-based interface and management system based on
  the popular amavisd-new e-mail scanner and SpamAssassin. Written in Perl
  and PHP, Maia Mailguard gives end-users control over how their mail is
  processed by virus scanners and spam filters, while giving mail administrators
  the power to configure site-wide defaults and limits.

	WWW: http://www.maiamailguard.com/

PR:		ports/119325
Submitted by:	Janky Jay <ek@purplehat.org> (maintainer)
Approved by:	linimon (mentor)
2008-01-20 06:38:05 +00:00
Martin Wilke
5fb3652239 This package provides an object oriented interface to GNU Privacy
Guard (GPG). It requires the GPG executable to be on the system.

Though GPG can support symmetric-key cryptography, this package is intended
only to facilitate public-key cryptography.

WWW: http://pear.php.net/package/Crypt_GPG/
2008-01-14 11:44:14 +00:00
Li-Wen Hsu
d1e8a9dcce Add shimmer 0.1.0, perl implementation that hides a valuable port on
your server.

PR:		ports/119512
Submitted by:	Felippe de Meirelles Motta <lippemail at gmail.com>
2008-01-10 05:24:33 +00:00
Beech Rintoul
13b02aa849 - New port phpdeadlock-1.0.1
- Web-based user authentication/password protection system

PR:		ports/117122
Submitted by:	Greg Larkin <glarkin@sourcehosting.net> (maintainer)
Approved by:	linimon (mentor)
2007-12-25 11:15:45 +00:00
Edwin Groothuis
4ed8e97ed0 XORSearch
XORSearch is a program to search for a given string in an XOR or
ROL encoded binary file. An XOR encoded binary file is a file where
some (or all) bytes have been XORed with a constant value (the key).
A ROL (or ROR) encoded file has it bytes rotated by a certain number
of bits (the key). XOR and ROL/ROR encoding is used by malware
programmers to obfuscate strings like URLs.

XORSearch will try all XOR keys (0 to 255) and ROL keys (1 to 7)
when searching. I programmed XORSearch to include key 0, because
this allows to search in an unencoded binary file (X XOR 0 equals
X).

If the search string is found, XORSearch will print it until the 0
(byte zero) is encountered or until 50 characters have been printed,
which ever comes first. 50 is the default value, it can be changed
with option -l. Unprintable characters are replaced by a dot.

WWW: http://blog.didierstevens.com/programs/xorsearch/
Author: Didier Stevens
2007-12-17 20:33:59 +00:00
Martin Wilke
b5d6c545e4 This program uses a brute force algorithm to guess your encrypted
compressed file's password. If you forget your encrypted file password,
this program is the solution. This program can crack zip,7z and rar file
passwords.

WWW: http://sourceforge.net/projects/rarcrack

PR:		ports/117630
Submitted by:	Philippe Audeoud <jadawin at tuxaco.net>
2007-10-29 22:57:12 +00:00
Chin-San Huang
ef000a009d Add uberkey, a keylogger for x86 systems.
WWW: http://www.linuks.mine.nu/uberkey/
2007-10-29 05:00:58 +00:00
Martin Wilke
1ed39dca71 pdfcrack is a command line, password recovery tool for PDF-files.
WWW: http://sourceforge.net/projects/pdfcrack

PR:		ports/117442
Submitted by:	Philippe Audeoud <jadawin at tuxaco.net>
2007-10-24 09:22:03 +00:00
Alejandro Pulver
28c8e95f4a This port contains the Shrew Soft ike daemon and client tools. The
software supports ike v1 communications between two gateways or a
a client and a gateway.

For more information please visit ...

WWW: http://www.shrew.net/

PR:		ports/116684
Submitted by:	mgrooms at shrew.net
2007-10-21 02:51:20 +00:00
Roman Bogorodskiy
3fe9e09bf3 OpenFWTK is an application proxy toolkit which inherits the ideology
of TIS fwtk and maintains API backwards compatibility. The design goal
is to make it simple yet powerful; no performance hacks allowed in the
code and library dependencies are reduced to minimum.

WWW: http://sourceforge.net/projects/openfwtk

PR:		ports/117194
Submitted by:	Anton Karpov <toxa at toxahost.ru>
2007-10-19 16:52:23 +00:00
Thomas Abthorpe
1e13747ed0 2007-09-10 security/p5-Digest-SHA2: Has numerious known bugs, deprecated in favor of Digest::SHA 2007-10-16 03:35:04 +00:00
Andrew Pantyukhin
123d815215 - Sort category Makefiles
Inspired by:	Jason Harris <jharris@widomaker.com>
Howto:		http://twiki.cenkes.org/Cenkes/SortingCategoryMakefiles
2007-10-05 23:33:27 +00:00
Rong-En Fan
2866a78221 Wapiti allows you to audit the security of your web applications.
It performs "black-box" scans, i.e. it does not study the source code of
the application but will scans the webpages of the deployed webapp,
looking for scripts and forms where it can inject data.
Once it gets this list, Wapiti acts like a fuzzer, injecting payloads to
see if a script is vulnerable.

WWW: http://wapiti.sourceforge.net/

PR:		ports/116873
Submitted by:	Philippe Audeoud <jadawin at tuxaco.net>
2007-10-04 13:21:39 +00:00
Martin Wilke
797fbf53b1 2007-08-29 security/vncrypt: not supported on any current version of FreeBSD
2007-09-15 net-mgmt/ocs-unix-agent: Use net-mgmt/ocsinventory-agent instead
2007-09-18 15:14:53 +00:00
Jose Alonso Cardenas Marquez
56016e8f40 - New port: security/fpc-openssl
Free Pascal unit for OpenSSL
2007-09-18 06:39:28 +00:00
Edwin Groothuis
eb818ba0a8 new port: security/afterglow, a collection of graph-generating scripts
AfterGlow is a collection of scripts which facilitate the
	process of generating event graphs and treemaps. AfterGlow
	1.x is written in Perl and generates output that can be
	read by GraphViz or LGL.  All the scripts and other files
	for afterglow are installed in ${DATADIR}

	WWW: http://sourceforge.net/projects/afterglow

PR:		ports/115186
Submitted by:	Paul Schmehl <pauls@utdallas.edu>
2007-09-08 05:49:35 +00:00
Edwin Groothuis
a0125022d7 new port security/ssss - Shamir's Secret Sharing Scheme
ssss is an implementation of Shamir's secret sharing scheme
	for UNIX/linux machines. It is free software, the code is
	licensed under the GNU GPL. ssss does both: the generation
	of shares for a known secret and the reconstruction of a
	secret using user provided shares. The software was written
	in 2006 by B. Poettering, it links against the GNU libgmp
	multiprecision library (version 4.1.4 works well) and
	requires the /dev/random entropy source.

PR:		ports/115949
Submitted by:	Lukasz Komsta <luke@novum.am.lublin.pl>
2007-09-07 11:55:09 +00:00
Edwin Groothuis
4e8d63bcc7 New port: security/seccure - SECCURE Elliptic Curve Crypto Utility for Reliable Encryption
The seccure toolset implements a selection of asymmetric
	algorithms based on elliptic curve cryptography (ECC). In
	particular it offers public key encryption / decryption,
	signature generation / verification and key establishment.

	ECC schemes offer a much better key size to security ratio
	than classical systems (RSA, DSA). Keys are short enough
	to make direct specification of keys on the command line
	possible (sometimes this is more convenient than the
	management of PGP-like key rings). seccure builds on this
	feature and therefore is the tool of choice whenever
	lightweight asymmetric cryptography -- independent of key
	servers, revocation certificates, the Web of Trust or even
	configuration files -- is required.

PR:		ports/115943
Submitted by:	Lukasz Komsta <luke@novum.am.lublin.pl>
2007-09-07 08:15:24 +00:00
Edwin Groothuis
934dc5b816 new port: security/hamachi (supersedes ports/110850)
New port of Hamachi VPN, using Linux official binary and a
	patch on tuncfg.c based on the official OSX release.

	Hamachi is a software that eases the creation of secure
	VPNs even between nodes that would not be able to connect
	to each other (server-assisted connection can be established
	from two NATted client, if at least one of the two NAT
	associates the port to the client not checking remote host).

	UPX port is required in order to decompress the linux binary
	and avoid run-time dependency on /proc.

PR:		ports/112982
Submitted by:	Lapo Luchini <lapo@lapo.it>
2007-09-07 07:47:07 +00:00
Joe Marcus Clarke
d84f52593e As promised, remove net-im/gaim, and all dependent ports. Gaim has been
replaced by net-im/pidgin.
2007-09-07 03:47:30 +00:00
Edwin Groothuis
028101c0d6 New port: security/openvpn-auth-ldap - LDAP authentication plugin for OpenVPN
The OpenVPN Auth-LDAP Plugin implements username/password
	authentication via LDAP for OpenVPN 2.x. It also includes
	some integration with the OpenBSD packet filter, supporting
	adding and removing VPN clients from PF tables.

	WWW: http://dpw.threerings.net/projects/openvpn-auth-ldap/

PR:		ports/113925
Submitted by:	Nick Barkas <snb@threerings.net>
2007-09-07 02:47:13 +00:00
Stefan Eßer
3da2dbd5f6 New port of w3af, the Web Application Audit and Attack Framework.
This is a Python based package of tools that can be used to assess
the security of a web server (including automated advanced tests,
e.g. for XSS or SQL injection vulnerabilities).

I did not get this port to work with the py-google port, there for
a local copy of pygoogle is included and packaged with this port.
2007-09-04 18:44:41 +00:00
Ion-Mihai Tetcu
29bb719115 Chaosreader is a perl script that parses snoop or tcpdump logs
and extracts sessions for a number of different appplications:
ssh, telnet, smtp, irc, ftp, etc.  The data are formatted into
an html file and can be used to replay some sessions.

Sshkeydata is a perl script that attempts to recreate ssh
sessions extracted by chaosreader by estimating what commands
may have been typed.

Both scripts are installed in ${PREFIX}/bin

WWW: http://sourceforge.net/projects/chaosreader

PR:		ports/115125
Submitted by:	pauls
2007-08-20 17:55:31 +00:00
Andrew Pantyukhin
c4fc19cf10 Add port security/p5-Net-Server-Mail-ESMTP-AUTH:
Net::Server::Mail::ESMTP::AUTH is an extension to provide
support for SMTP authentication with Net::Server::Mail::ESMTP
module.

Currently only LOGIN and PLAIN methods are supported.

WWW: http://search.cpan.org/dist/Net-Server-Mail-ESMTP-AUTH/
Author: Sylvain Cresto <scresto [_at_] gmail.com>

PR:		ports/114785 (with corrections)
Submitted by:	Zane C. Bowers <vvelox@vvelox.net>
2007-08-15 18:48:12 +00:00
Andrew Pantyukhin
19e642669c Add port security/clamtk:
ClamTk is a GUI front-end for ClamAV using gtk2-perl. It is designed to
be an easy-to-use frontend for Unix systems.

WWW: http://clamtk.sourceforge.net/
Author: Dave M <dave.nerd@gmail.com>
2007-08-09 09:22:28 +00:00
Pav Lucistnik
df7a9ca51e Shibboleth is standards-based, open source middleware software which
provides Web Single SignOn (SSO) across or within organizational
boundaries. It allows sites to make informed authorization decisions
for individual access of protected online resources in a
privacy-preserving manner.

This software is a C++ implementation of the Service Provider
component of the Shibboleth can be used in Apache Web servers.  The
service provider manages secured resources. User access to resources
is based on assertions received by the service provider (SP) from
an identity provider.

WWW:	http://shibboleth.internet2.edu/

PR:		ports/114663
Submitted by:	Janos Mohacsi <janos.mohacsi@bsd.hu>
2007-08-03 23:21:25 +00:00
Martin Wilke
d52ce20c04 2007-07-31 x11-fm/endeavour: Development ceased, this port should be updated to Endeavour Mark II
2007-08-01 security/p5-openxpki-client-soap-lite: No longer maintained by Developers.
2007-06-26 net-mgmt/aircrack: Please use net-mgmt/aircrack-ng.
2007-08-01 15:32:50 +00:00
Chin-San Huang
c68800dd9c Add chntpw 070409, utility to set the password and edit registry on
Microsoft NT system.

PR:		ports/114897
Submitted by:	buganini at gmail.com
Approved by:	rafan (mentor, implicit)
2007-07-27 14:41:07 +00:00
Cheng-Lung Sung
9b79dc3cb4 Lasso is a free software C library aiming to implement the Liberty
Alliance standards; it defines processes for federated identities,
single sign-on and related protocols. Lasso is built on top of
libxml2, XMLSec and OpenSSL and is licensed under the GNU General
Public License  (with an OpenSSL exception).

WWW:	http://lasso.entrouvert.org/

PR:		ports/114639
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-25 07:18:22 +00:00
Rong-En Fan
58c41ab013 - Retire security/metasploit-devel since security/metasploit is now
up-to-date

PR:		ports/114196
Submitted by:	Yonatan <onatan at gmail.com> (maintainer)
2007-07-23 02:11:22 +00:00
Christian S.J. Peron
8c8929eab3 Hook bsmtrace into build for the security category
Reminded by:	Pav
2007-07-15 18:35:24 +00:00
Martin Wilke
744da227f0 Crypt::Camellia_PP is a pure perl implementation of Camellia, a 128-bit
symmetrical block cipher with 128-bit, 192-bit, and 256-bit key from
NTT and Mitsubishi Electric Corporation.  It is one of the approved
encryption methods to be used by European Union as well as specified
in several Internet RFCs.

See also: http://info.isl.ntt.co.jp/crypt/eng/camellia/index.html
WWW: http://search.cpan.org/dist/Crypt-Camellia_PP/

PR:		ports/114525
Submitted by:	Yoshisato YANAGISAWA
2007-07-12 18:37:16 +00:00
Cheng-Lung Sung
7352095793 ZXID aims at full stack implementation of all federated identity
management and identity web services protocols. Initial goal is
supporting SP role, followed by ID-WSF WSC and IdP roles.

ZXID is light weight, has a small foot print, and is implemented in C.
It is suitable for both high performance and embedded applications.
Scripting languages are supported using SWIG, including Perl, PHP and
Java. The "full stack" nature of ZXID means it's self contained and
has minimal external library dependencies (see downloads).

WWW:	http://zxid.org/

PR:		ports/114346
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-09 02:24:04 +00:00
Cheng-Lung Sung
d925706034 This module priovides an Object Oriented interface for Yahoo!
Browser-Based Authentication.

This module is ported from the official PHP class which is located on
this page: http://developer.yahoo.com/php

WWW:	http://search.cpan.org/dist/Yahoo-BBAuth/

PR:		ports/114345
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-09 02:16:06 +00:00
Brooks Davis
c12838c984 Add ca_root_nss:
Root certificates from certificate authorities included in the Mozilla
NSS library and thus in Firefox and Thunderbird.
2007-07-06 21:37:35 +00:00
Brooks Davis
c8ff799714 Add pssh:
This package provides parallel versions of the openssh tools. Included
in the distribution:

 - Parallel ssh (pssh)
 - Parallel scp (pscp)
 - Parallel rsync (prsync)
 - Parallel nuke (pnuke)
 - Parallel slurp (pslurp)

What are these tools good for? Mainly for controlling large collections
of nodes in the wide-area.

WWW: http://www.theether.org/pssh/
2007-07-03 00:06:22 +00:00
Cheng-Lung Sung
b399e0595a Add p5-Sudo 0.31, perl extension for running a command line sudo.
PR:		ports/113056
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-02 01:00:27 +00:00
Renato Botelho
e4210f6e8d Scanhill is a Microsoft Messenger Protocol Sniffer. Currently it can only
intercept Instant Text Messaging. Optionally, intercepted text messages can be
stored onto an RDMBS (Only mySQL is supported for now). Given that mySQL is
used, stored instant messages can be read through a browser interface that is
written in PHP language. Please see the INSTALL.txt file for instructions on
how to install, configure and run EnderUNIX scanhill.

WWW:	http://www.enderunix.org/scanhill/
2007-06-25 12:34:07 +00:00
Andrew Pantyukhin
32f7edd735 Add port security/execwrap:
ExecWrap is a super-user exec wrapper for the lighttpd web-server, but
it can be used in any environment as long as arguments can be passed
from the server to its children via the environment.

WWW: http://cyanite.org/execwrap/
Author: Sune Foldager <cryo@cyanite.org>
2007-06-22 15:53:20 +00:00
Beech Rintoul
011d9c0fdb - Ports renamed for consistency
PR:		ports/112327
Repocopy by:	marcus
Approved by:	sat (maintainer)
2007-06-22 08:06:15 +00:00
Martin Wilke
75d624b2fe - Connect security/pidgin-encryption
- Fix category by pidgin-otr
2007-06-18 11:30:58 +00:00
Martin Wilke
35019547db - Update to 3.0.1
- Update pkg-descr
- Update MASTER_SITES
- Connect to build

PR:		112651
Submitted by:	Mike Smith<perlfu@gmail.com>
2007-06-18 11:07:42 +00:00