Commit graph

1109 commits

Author SHA1 Message Date
Andrew Pantyukhin
19e642669c Add port security/clamtk:
ClamTk is a GUI front-end for ClamAV using gtk2-perl. It is designed to
be an easy-to-use frontend for Unix systems.

WWW: http://clamtk.sourceforge.net/
Author: Dave M <dave.nerd@gmail.com>
2007-08-09 09:22:28 +00:00
Pav Lucistnik
df7a9ca51e Shibboleth is standards-based, open source middleware software which
provides Web Single SignOn (SSO) across or within organizational
boundaries. It allows sites to make informed authorization decisions
for individual access of protected online resources in a
privacy-preserving manner.

This software is a C++ implementation of the Service Provider
component of the Shibboleth can be used in Apache Web servers.  The
service provider manages secured resources. User access to resources
is based on assertions received by the service provider (SP) from
an identity provider.

WWW:	http://shibboleth.internet2.edu/

PR:		ports/114663
Submitted by:	Janos Mohacsi <janos.mohacsi@bsd.hu>
2007-08-03 23:21:25 +00:00
Martin Wilke
d52ce20c04 2007-07-31 x11-fm/endeavour: Development ceased, this port should be updated to Endeavour Mark II
2007-08-01 security/p5-openxpki-client-soap-lite: No longer maintained by Developers.
2007-06-26 net-mgmt/aircrack: Please use net-mgmt/aircrack-ng.
2007-08-01 15:32:50 +00:00
Chin-San Huang
c68800dd9c Add chntpw 070409, utility to set the password and edit registry on
Microsoft NT system.

PR:		ports/114897
Submitted by:	buganini at gmail.com
Approved by:	rafan (mentor, implicit)
2007-07-27 14:41:07 +00:00
Cheng-Lung Sung
9b79dc3cb4 Lasso is a free software C library aiming to implement the Liberty
Alliance standards; it defines processes for federated identities,
single sign-on and related protocols. Lasso is built on top of
libxml2, XMLSec and OpenSSL and is licensed under the GNU General
Public License  (with an OpenSSL exception).

WWW:	http://lasso.entrouvert.org/

PR:		ports/114639
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-25 07:18:22 +00:00
Rong-En Fan
58c41ab013 - Retire security/metasploit-devel since security/metasploit is now
up-to-date

PR:		ports/114196
Submitted by:	Yonatan <onatan at gmail.com> (maintainer)
2007-07-23 02:11:22 +00:00
Christian S.J. Peron
8c8929eab3 Hook bsmtrace into build for the security category
Reminded by:	Pav
2007-07-15 18:35:24 +00:00
Martin Wilke
744da227f0 Crypt::Camellia_PP is a pure perl implementation of Camellia, a 128-bit
symmetrical block cipher with 128-bit, 192-bit, and 256-bit key from
NTT and Mitsubishi Electric Corporation.  It is one of the approved
encryption methods to be used by European Union as well as specified
in several Internet RFCs.

See also: http://info.isl.ntt.co.jp/crypt/eng/camellia/index.html
WWW: http://search.cpan.org/dist/Crypt-Camellia_PP/

PR:		ports/114525
Submitted by:	Yoshisato YANAGISAWA
2007-07-12 18:37:16 +00:00
Cheng-Lung Sung
7352095793 ZXID aims at full stack implementation of all federated identity
management and identity web services protocols. Initial goal is
supporting SP role, followed by ID-WSF WSC and IdP roles.

ZXID is light weight, has a small foot print, and is implemented in C.
It is suitable for both high performance and embedded applications.
Scripting languages are supported using SWIG, including Perl, PHP and
Java. The "full stack" nature of ZXID means it's self contained and
has minimal external library dependencies (see downloads).

WWW:	http://zxid.org/

PR:		ports/114346
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-09 02:24:04 +00:00
Cheng-Lung Sung
d925706034 This module priovides an Object Oriented interface for Yahoo!
Browser-Based Authentication.

This module is ported from the official PHP class which is located on
this page: http://developer.yahoo.com/php

WWW:	http://search.cpan.org/dist/Yahoo-BBAuth/

PR:		ports/114345
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-09 02:16:06 +00:00
Brooks Davis
c12838c984 Add ca_root_nss:
Root certificates from certificate authorities included in the Mozilla
NSS library and thus in Firefox and Thunderbird.
2007-07-06 21:37:35 +00:00
Brooks Davis
c8ff799714 Add pssh:
This package provides parallel versions of the openssh tools. Included
in the distribution:

 - Parallel ssh (pssh)
 - Parallel scp (pscp)
 - Parallel rsync (prsync)
 - Parallel nuke (pnuke)
 - Parallel slurp (pslurp)

What are these tools good for? Mainly for controlling large collections
of nodes in the wide-area.

WWW: http://www.theether.org/pssh/
2007-07-03 00:06:22 +00:00
Cheng-Lung Sung
b399e0595a Add p5-Sudo 0.31, perl extension for running a command line sudo.
PR:		ports/113056
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-07-02 01:00:27 +00:00
Renato Botelho
e4210f6e8d Scanhill is a Microsoft Messenger Protocol Sniffer. Currently it can only
intercept Instant Text Messaging. Optionally, intercepted text messages can be
stored onto an RDMBS (Only mySQL is supported for now). Given that mySQL is
used, stored instant messages can be read through a browser interface that is
written in PHP language. Please see the INSTALL.txt file for instructions on
how to install, configure and run EnderUNIX scanhill.

WWW:	http://www.enderunix.org/scanhill/
2007-06-25 12:34:07 +00:00
Andrew Pantyukhin
32f7edd735 Add port security/execwrap:
ExecWrap is a super-user exec wrapper for the lighttpd web-server, but
it can be used in any environment as long as arguments can be passed
from the server to its children via the environment.

WWW: http://cyanite.org/execwrap/
Author: Sune Foldager <cryo@cyanite.org>
2007-06-22 15:53:20 +00:00
Beech Rintoul
011d9c0fdb - Ports renamed for consistency
PR:		ports/112327
Repocopy by:	marcus
Approved by:	sat (maintainer)
2007-06-22 08:06:15 +00:00
Martin Wilke
75d624b2fe - Connect security/pidgin-encryption
- Fix category by pidgin-otr
2007-06-18 11:30:58 +00:00
Martin Wilke
35019547db - Update to 3.0.1
- Update pkg-descr
- Update MASTER_SITES
- Connect to build

PR:		112651
Submitted by:	Mike Smith<perlfu@gmail.com>
2007-06-18 11:07:42 +00:00
Cheng-Lung Sung
bf7b398dfa Add php-Auth_OpenID 1.2.2, PHP OpenID library.
PR:		ports/112079
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-06-14 02:41:41 +00:00
Ion-Mihai Tetcu
93171a0f66 Add slave port sshguard-ipfw, protect networked hosts from brute force attacks
against ssh using ipfw.

PR:		ports/112760
Submitted by:	Mij <mij at bitchx.it>
2007-06-12 20:15:04 +00:00
Ion-Mihai Tetcu
63a94afab9 Add slave port sshguard-pf, protect networked hosts from brute force attacks
against ssh usinh pf

PR:		ports/112759
Submitted by:	Mij <mij at bitchx.it>
2007-06-12 20:10:34 +00:00
Yen-Ming Lee
6879ca51f6 - add Crypt::OpenSSL::X509 0.5
This implement a large majority of OpenSSL's useful X509 API.

  The email() method supports both certificates where the
  subject is of the form:
  "... CN=Firstname lastname/emailAddress=user@domain", and also
  certificates where there is a X509v3 Extension of the form
  "X509v3 Subject Alternative Name: email=user@domain".

Submitted by:	kftseng@iyard.org
2007-06-11 09:11:46 +00:00
Martin Wilke
12072bf97c This plugin enables Off-The-Record encryption for
Kopete.

WWW: http://kopete-otr.follefuder.org/

PR:		ports/112575
Submitted by:	Dave Grochowski <malus.x at gmail.com>
2007-06-06 10:33:24 +00:00
Maxim Sobolev
b5297f4098 Re-add pvk under proper name. 2007-06-04 20:46:04 +00:00
Maxim Sobolev
b34d0c185c Add pvt 20070406, tool to convert a RSA key in PEM format into a PVK
file and vice versa.
2007-06-04 19:51:34 +00:00
Gabor Kovesdan
a5a79ff2eb Remove expired ports:
2007-04-27 security/op: no longer available from any mastersite
2007-05-15 shells/bash2: Old, unmaintained version, use shells/bash instead
2007-05-19 sysutils/xperfmon: irrelevant for supported FreeBSD releases
2007-06-04 15:01:37 +00:00
Edwin Groothuis
1a66b2caf9 New port: security/smap
smap is a simple scanner for SIP enabled devices

    smap sends off various SIP requests awaiting responses from SIP
    enabled DSL router, proxies and user agents. It could be considered
    a mashup of nmap and sipsak ;)

    WWW: http://www.wormulon.net/
    Author: Hendrik Scholz <hscholz@raisdorf.net>
2007-05-24 22:16:25 +00:00
Cheng-Lung Sung
a7c65255b8 Add aespipe , an AES encrypting or decrypting pipe.
PR:		ports/112056
Submitted by:	Ekkehard 'Ekki' Gehm <gehm at physik.tu-berlin.de>
2007-04-24 08:00:28 +00:00
Anton Berezin
dbf2771921 Resurrect p5-Crypt-OpenPGP, now with a patch for CVE-2005-0366.
Seems OK:	simon, lth
2007-04-23 14:01:17 +00:00
Martin Wilke
1fa26157d1 - Add ossec-hids-client as slave port.
PR:		ports/111944
Submitted by:	Valerio Daelli <valerio.daelli at gmail.com>
2007-04-20 21:33:44 +00:00
Martin Wilke
24bea4ab44 - Add ossec-hids-local as slave port
PR:		ports/111944
Submitted by:	Valerio Daelli <valerio.daelli at gmail.com>
2007-04-20 21:32:20 +00:00
Martin Wilke
2ab3c923e5 OSSEC is an Open Source Host-based Intrusion Detection System.
It performs log analysis, integrity checking, Windows registry
monitoring, rootkit detection, time-based alerting and active
response.

WWW: http://www.ossec.net/

PR:		ports/111944
Submitted by:	Valerio Daelli <valerio.daelli at gmail.com>
2007-04-20 21:29:20 +00:00
Roman Bogorodskiy
966eac9a6b Add umit 0.9.3, UMIT is the nmap frontend developed with Python and
PyGTK.

PR:		ports/111959
Submitted by:	Elisey Savateev <b3k at mail.ru>
2007-04-20 18:05:55 +00:00
Martin Wilke
12f5d21f63 2007-03-27 emulators/kmamerun: Project was abandoned 4 years ago and expects an old version of XMAME, please use other frontends instead (like gxmame)
2007-03-28 graphics/hobbes-icons-xpm: Archaic port
2007-04-10 japanese/firefox-ja: Incomplete pkg-plist
2007-04-10 japanese/lookup-xemacs: Does not install
2007-04-10 lang/linux-hla: Does not compile
2007-04-10 mail/vmailmgr: Incomplete pkg-plist
2007-04-10 multimedia/qvamps: Touches filesystem prior to 'make install'
2007-03-10 net-mgmt/sting: Broken on all supported versions of FreeBSD
2007-04-10 net-mgmt/tas: Incomplete pkg-plist
2007-04-10 net-p2p/verlihub-plugins: Does not configure, it needs at least verlihub 1.0
2007-04-10 news/inn-stable: Fails to patch
2007-04-10 palm/malsync: Does not build with new pilot-link
2007-04-10 russian/elm.language: Leaves behind files on deinstall
2007-04-10 russian/pine.language: Leaves behind config file on deinstall
2007-04-01 science/py-scipy03: Replaced by py-scipy
2007-04-10 security/php4-cryptopp: Does not compile
2007-04-10 17:40:51 +00:00
Vanilla I. Shu
9ac356527f Add xyssl 0.6, a liteweight SSL and TLS toolkit for C developers.
PR:		ports/111279
Submitted by:	mdh <mdh at solitox.net>
2007-04-08 10:15:35 +00:00
Li-Wen Hsu
e847b772c8 Add py-gnutls 1.0.0, python wrapper for the GNUTLS library.
Approved by:    clsung (mentor)
2007-04-07 06:19:20 +00:00
Rong-En Fan
7bac20ed59 Add phpsecinfo 0.2.0, a PHP environment security auditing toool.
PR:		ports/111040
Submitted by:	chinsan
2007-04-01 13:09:57 +00:00
Rong-En Fan
98d1432393 - Add www/drupal5
- Rename drupal-* to drupal4-*
2007-03-25 09:48:25 +00:00
Cheng-Lung Sung
00dbce6310 Add cryptstring 0.2, crypto Strings for PHP.
PR:		ports/110764
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2007-03-25 04:13:33 +00:00
Martin Wilke
37a8237406 ocaml-ssl is a set of OCaml bindings for openssl.
WWW: http://savonet.sourceforge.net/wiki/OCamlLibs

PR:		ports/110303
Submitted by:	Jaap Boender <jaapb at kerguelen.org>
2007-03-16 11:57:30 +00:00
Martin Wilke
e66a031a4a F-Prot Antivirus BSD Mail Servers utilizes the renowned F-Prot Antivirus
scanning engine for primary scan but has in addition to that a system of
system of internal heuristics devised to search for unknown viruses.

Please note that the license explicitly permits that F-Prot Antivirus BSD
Mail Servers be used for evaluation purposes only, without charge for a
period of no more than 60 days.  If you use this software after the 60 day
evaluation period, then you must register and pay a license fee.

WWW: http://www.f-prot.com/

PR:		ports/110107
Submitted by:	Scot W. Hetzel <swhetzel at gmail.com>
2007-03-09 10:20:17 +00:00
Martin Wilke
54d0ea9212 py-bcrypt is a Python wrapper of OpenBSDs Blowfish password hashing code,
as described in A Future-Adaptable Password Scheme by Niels Provos and
David Mazières.

WWW:	http://www.mindrot.org/projects/py-bcrypt/
2007-03-07 13:49:59 +00:00
Cheng-Lung Sung
5a4a332130 Move zzuf-0.8.1 from devel/, transparent application input fuzzer.
Noted by:	kris
PR:		ports/109829
Submitted by:	Peter Johnson <johnson.peter at gmail.com>
2007-03-06 05:36:34 +00:00
Cheng-Lung Sung
761d545251 Add sshguard 0.91, protect networked hosts from brute force attacks
against ssh.

PR:		ports/109439
Submitted by:	Mij <mij at bitchx.it>
2007-03-01 01:36:56 +00:00
Alex Dupre
22f49b2d64 This is a library for the Java platform which makes PKCS#11 (also known
as Cryptoki) modules accessible from within Java. A PKCS#11 module is a
software library with a defined API which allows access to cryptographic
hardware. It usually comes with hardware security modules (HSM), smart
cards and crypto tokens (e.g. USB tokens). Thus, the PKCS#11 Wrapper
provides Java software access to almost any crypto hardware. For
example, a Java application can use it to integrate a HSM or a smart
card to create digital signatures, to decrypt data or to unwrap keys.

WWW: http://jce.iaik.tugraz.at/sic/products/core_crypto_toolkits/pkcs_11_wrapper
2007-02-23 07:06:58 +00:00
Andrew Pantyukhin
2fb21a3f65 Add port security/jeta:
Jeta is the Horde wrapper around various Java SSH applets.  It allows users
to login via a terminal window to the server on which the Horde application is
running.

WWW: http://www.horde.org/jeta/

PR:		ports/109095
Submitted by:	Beech Rintoul <beech@alaskaparadise.com>
2007-02-22 12:44:29 +00:00
Rong-En Fan
e981b6db40 Add p5-Authen-PluggableCaptcha 0.04, a pluggable Captcha framework for
Perl.

PR:		ports/109383
Submitted by:	chinsan
2007-02-22 05:42:33 +00:00
Rong-En Fan
c6b2d300e2 Add p5-HTML-Email-Obfuscate 1.00, obfuscates HTML email addresses that
look normal.

PR:		ports/109381
Submitted by:	chinsan
2007-02-21 14:47:02 +00:00
Rong-En Fan
504bdbc060 Add opensaml 1.1, open source implentation of SAML.
PR:		ports/109113
Submitted by:	Tony Maher
2007-02-14 23:12:25 +00:00
Rong-En Fan
ca4fbdd009 Add apache-xml-security-c 1.3.1, apache XML security libraries C
version.

PR:		ports/109112
Submitted by:	Tony Maher
2007-02-14 23:10:27 +00:00
Martin Wilke
097671613e snoopy is merely a shared library that is used as a wrapper
to the execve() function provided by libc as to log every call
to syslog (authpriv).  system administrators may find snoopy
useful in tasks such as light/heavy system monitoring, tracking other
administrator's actions as well as getting a good 'feel' of
what's going on in the system (for example apache running cgi
scripts).

WWW: http://sourceforge.net/projects/snoopylogger/

PR:		ports/108691
Submitted by:	Philippe Audeoud <jadawin at tuxaco.net>
2007-02-06 23:36:12 +00:00
Sergey Skvortsov
2886fac158 Add keepassx 0.2.2, Cross Platform Password Manager. 2007-02-06 11:49:15 +00:00
Pav Lucistnik
0d0d56457b Populate a new ports-mgmt category. List of moved ports:
devel/portcheckout -> ports-mgmt/portcheckout
  devel/portlint -> ports-mgmt/portlint
  devel/portmk -> ports-mgmt/portmk
  devel/porttools -> ports-mgmt/porttools
  misc/instant-tinderbox -> ports-mgmt/instant-tinderbox
  misc/porteasy -> ports-mgmt/porteasy
  misc/portell -> ports-mgmt/portell
  misc/portless -> ports-mgmt/portless
  misc/tinderbox -> ports-mgmt/tinderbox
  security/jailaudit -> ports-mgmt/jailaudit
  security/portaudit -> ports-mgmt/portaudit
  security/portaudit-db -> ports-mgmt/portaudit-db
  security/vulnerability-test-port -> ports-mgmt/vulnerability-test-port
  sysutils/barry -> ports-mgmt/barry
  sysutils/bpm -> ports-mgmt/bpm
  sysutils/kports -> ports-mgmt/kports
  sysutils/managepkg -> ports-mgmt/managepkg
  sysutils/newportsversioncheck -> ports-mgmt/newportsversioncheck
  sysutils/pib -> ports-mgmt/pib
  sysutils/pkgfe -> ports-mgmt/pkgfe
  sysutils/pkg-orphan -> ports-mgmt/pkg-orphan
  sysutils/pkg_cutleaves -> ports-mgmt/pkg_cutleaves
  sysutils/pkg_install -> ports-mgmt/pkg_install
  sysutils/pkg_install-devel -> ports-mgmt/pkg_install-devel
  sysutils/pkg_remove -> ports-mgmt/pkg_remove
  sysutils/pkg_rmleaves -> ports-mgmt/pkg_rmleaves
  sysutils/pkg_trackinst -> ports-mgmt/pkg_trackinst
  sysutils/pkg_tree -> ports-mgmt/pkg_tree
  sysutils/portbrowser -> ports-mgmt/portbrowser
  sysutils/portconf -> ports-mgmt/portconf
  sysutils/portdowngrade -> ports-mgmt/portdowngrade
  sysutils/portcheck -> ports-mgmt/portcheck
  sysutils/portmanager -> ports-mgmt/portmanager
  sysutils/portmaster -> ports-mgmt/portmaster
  sysutils/portscout -> ports-mgmt/portscout
  sysutils/portsearch -> ports-mgmt/portsearch
  sysutils/portsman -> ports-mgmt/portsman
  sysutils/portsnap -> ports-mgmt/portsnap
  sysutils/portsopt -> ports-mgmt/portsopt
  sysutils/portupgrade -> ports-mgmt/portupgrade
  sysutils/portupgrade-devel -> ports-mgmt/portupgrade-devel
  sysutils/port-authoring-tools -> ports-mgmt/port-authoring-tools
  sysutils/port-maintenance-tools -> ports-mgmt/port-maintenance-tools
  sysutils/psearch -> ports-mgmt/psearch
  sysutils/p5-FreeBSD-Portindex -> ports-mgmt/p5-FreeBSD-Portindex
  sysutils/qtpkg -> ports-mgmt/qtpkg
  textproc/p5-FreeBSD-Ports -> ports-mgmt/p5-FreeBSD-Ports

Repocopies by:	marcus
2007-02-05 01:08:46 +00:00
Gabor Kovesdan
f36b800832 This AOLserver module performs SHA1 hashes.
WWW: http://www.aolserver.com/

- Martin Matuska
martin@matuska.org

PR:		ports/105781
Submitted by:	Martin Matuska <martin@matuska.org>
Approved by:	erwin (mentor)
2007-02-02 14:13:13 +00:00
Gabor Kovesdan
51b7f90351 An AOLserver socket driver module which implements SSL/TLS encryption on
incomming sockets, and also adds an https client API.

WWW: http://www.aolserver.com/

- Martin Matuska
martin@matuska.org

PR:		ports/105781
Submitted by:	Martin Matuska <martin@matuska.org>
Approved by:	erwin (mentor)
2007-02-02 14:09:36 +00:00
Gabor Kovesdan
3308637099 AOLserver interface to mhash library
WWW: http://www.aolserver.cz/

- Martin Matuska
martin@matuska.org

PR:		ports/105781
Submitted by:	Martin Matuska <martin@matuska.org>
Approved by:	erwin (mentor)
2007-02-02 14:06:02 +00:00
Gabor Kovesdan
1f0f9dbfef AOLserver interface to mcrypt library
WWW: http://www.aolserver.cz/

- Martin Matuska
martin@matuska.org

PR:		ports/105781
Submitted by:	Martin Matuska <martin@matuska.org>
Approved by:	erwin (mentor)
2007-02-02 14:02:42 +00:00
Gabor Kovesdan
6a4dc8c396 This module Uses OpenSSL to encrypt using the
AES, Blowfish, Cast5, IDEA and DES cyphers.

WWW: http://www.aolserver.com/

- Martin Matuska
martin@matuska.org

PR:		ports/105781
Submitted by:	Martin Matuska <martin@matuska.org>
Approved by:	erwin (mentor)
2007-02-02 13:57:29 +00:00
Rong-En Fan
af1d88f66a Add p5-Authen-Bitcard 0.86, bitcard authentication verification.
PR:		ports/107968
Submitted by:	chinsan
2007-01-16 13:09:32 +00:00
Alex Dupre
7c7317bc09 pkcs11-helper is a library that simplifies the interaction
with PKCS#11 providers for end-user applications.

pkcs11-helper allows using multiple PKCS#11 providers at
the same time, enumerating available token certificates, or
selecting a certificate directly by serialized id, handling
card removal and card insert events, handling card re-insert
to a different slot, supporting session expiration and much
more all using a simple API.

pkcs11-helper is not designed to manage card content, since
object attributes are usually vendor specific, and 99% of
application need to access existing objects in order to
perform signature and decryption.

WWW:	http://www.opensc-project.org/pkcs11-helper/
2007-01-08 09:12:58 +00:00
Martin Wilke
89fc8fbeff 2007-01-01 graphics/teddy: No new releases in the past 4 years
2007-01-01 net/arla: "does not compile"
2007-01-02 sysutils/lsmlib: distfile and homepage disappeared
2007-01-02 security/ifd-gpr400: distfile and homepage disappeared
2007-01-04 science/mmtk: distfile and homepage disappeared
2007-01-04 print/xtem: distfile and homepage disappeared
2007-01-04 net/mrt: distfile and homepage disappeared
2007-01-05 18:42:55 +00:00
Martin Wilke
2782bcfe89 2006-12-01 net-p2p/gnome-btdownload: does not run with BitTorrent 4.x yet
2006-12-01 print/ec-fonts-mftraced: Installs files before 'make install'
2006-12-01 print/yatex-xemacs-mule: hangs during build
2006-12-01 security/gnu-crypto: Does not compile
2006-12-01 www/linux-beonex: Security issues. From http://www.beonex.com/ 'The currently available Beonex Communicator 0.8 builds have several known security bugs'
2007-01-05 16:54:27 +00:00
Cheng-Lung Sung
004b4683a8 Text::Password::Pronounceable - Generate pronounceable passwords
This module generates pronuceable passwords, based the the
English digraphs by D Edwards.

WWW: http://search.cpan.org/dist/Text-Password-Pronounceable/
2006-12-29 07:31:47 +00:00
Ion-Mihai Tetcu
4ae48f023a Vinetto extracts the thumbnails and associated metadata from the Thumbs.db
files.

The Windows systems (98, ME, 2000, XP and 2003 Server) can store thumbnails
and metadata of the picture files contained in the directories of its FAT32
or NTFS filesystems.

The thumbnails and associated metadata are stored in Thumbs.db files.
The Thumbs.db files are undocumented OLE structured files.

Once a picture file has been deleted from the filesystem, the related thumbnail
and associated metada remain stored in the Thumbs.db file. So, the data
contained in those Thumbs.db files are an helpful source of information
for the forensics investigator.

WWW:	http://vinetto.sourceforge.net/

PR:		ports/107235
Submitted by:	Aleksander Fafula <alex at BSDGuru.org>
2006-12-27 12:41:18 +00:00
Gabor Kovesdan
7a1cf5082f Overview:
Pantera uses an improved version of SpikeProxy to provide a powerful web
application analysis engine.

Goals:
The primary goal of Pantera is to combine automated capabilities with complete
manual testing to get the best penetration testing results.

WWW: http://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project

PR:		ports/105291
Submitted by:	Yonatan <onatan at gmail.com>
2006-12-25 20:08:15 +00:00
Ade Lovett
bf3c459d42 Fix Makefile now that gnupg-devel has disappeared, and gnupg1 has been
repocopied.  Takes care of current INDEX breakage.

Submitted by:	various scripts
2006-12-22 00:54:02 +00:00
Cheng-Lung Sung
c91912f708 OpenID is a decentralized identity system, but one that's actually
decentralized and doesn't entirely crumble if one company turns evil
or goes out of business.

An OpenID identity is just a URL. You can have multiple identities in
the same way you can have multiple URLs. All OpenID does is provide a
way to prove that you own a URL (identity).

Anybody can run their own site using OpenID, and anybody can be an
OpenID server, and they all work with each other without having to
register with or pay anybody to "get started". An owner of a URL can
pick which OpenID server to use.

WWW: http://www.openidenabled.com/openid/libraries/perl/
2006-12-20 11:41:27 +00:00
Cheng-Lung Sung
3dcdcceee8 Python OpenID library implements recent changes to the OpenID
specification as well as making API changes that should make
integration with applications easier.

This library allows the use of XRI as OpenID identifiers, allowing users
to log in with their i-names.  For full XRI compatibility,
relying parties integrating this library should take note of the user's
CanonicalID, as described in the "Identifying the End User" section of
the OpenID 2.0 specification.

WWW: http://www.openidenabled.com/openid/libraries/python/
2006-12-20 09:53:45 +00:00
Cheng-Lung Sung
885b99197b Add phpmyid 0.3, a single user Identity Provider for the OpenID
framework.

PR:		ports/106874
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-12-20 05:47:34 +00:00
Alejandro Pulver
c22052f6b7 MyPasswordSafe is a straight-forward, easy-to-use password manager that
maintains compatibility with Password Safe files. MyPasswordSafe has the
following features:

* Safes are encrypted when they are stored to disk.
* Passwords never have to be seen, because they are copied to the clipboard.
* Random passwords can be generated.
* Window size, position, and column widths are remembered.
* Passwords remain encrypted until they need to be decrypted at the dialog and
  file levels.
* A safe can be made active so it will always be opened when MyPasswordSafe
  starts.
* Supports Unicode in the safes.
* Languages supported: English and French.

WWW: http://www.semanticgap.com/myps/
2006-12-17 20:29:05 +00:00
Alexander Botero-Lowry
ce54679244 - Add hashlib-20060408a
Python secure hash and message digest module MD5, SHA1, SHA224, SHA256,
 SHA384 and SHA512 (backported from Python 2.5 for use on 2.3 and 2.4)

 WWW: http://code.krypto.org/python/hashlib/
2006-12-13 03:19:17 +00:00
Martin Wilke
fc454f85a8 The tool is a simple flow-analyzing passive L7 fingerprinter. It
examines the sequence of client-server exchanges, their relative
layer 7 payload sizes, and transmission intervals (as opposed to
inspecting the contents, which is what most passive fingerprinters
and "smart" sniffers would do to analyze transmissions). This is
then matched against a database of traffic pattern signatures to
infer some interesting facts about the traffic.

PR:		ports/106351
Submitted by:	trasz <trasz at pin.if.uz.zgora.pl>
2006-12-04 22:33:37 +00:00
Anders Nordby
4162850462 Add sshblock, a tool to block abusive SSH login attempts. 2006-12-03 22:25:18 +00:00
Martin Wilke
40786d825e A library for connecting to and sending commands to a local
ClamAV clamd service - an anti-virus daemon process.

You can find more information about clam anti-virus at
WWW: http://www.clamav.net/

File::Scan::ClamAV was originally based on the Clamd module

Submitted by:	Jan-Peter Koopmann <Jan-Peter.Koopmann at seceidos.de>
2006-11-23 23:08:30 +00:00
Martin Wilke
e56c8c72e0 Sguil (pronounced "sgweel") is a graphical interface to snort,
an open source intrusion detection system.
The actual interface and GUI server are written in tcl/tk.
Sguil also relies on other open source software
in order to function properly.

The client requires gpg, iwidgets and other tcl packages and may
also use wireshark, festival and tls depending on your selection
of options.  Run "make config" in the port to see what options
are available.

Sguil currently functions as an analysis interface and has
no snort sensor or rule management capabilities.

WWW: http://sguil.sourceforge.net/index.php
pauls@utdallas.edu

PR:		ports/105496
Submitted by:	Paul Schmehl <pauls at utdallas.edu>
2006-11-15 21:33:51 +00:00
Frank J. Laszlo
6ebfbc8583 New Port: security/osslsigncode
Platform-independent tool for Authenticode signing of EXE/CAB files - uses
OpenSSL and libcurl. It also supports timestamping.

PR:	ports/105353
Submitted By:	Nick Barkas <snb@threerings.net>
Approved By:	flz (mentor)
2006-11-11 13:55:05 +00:00
Alejandro Pulver
b529c1e197 Sguil is an open source tool to implement Network
Security Monitoring (NSM).  NSM is the collection,
analysis, and escalation of indications and warnings
to detect and respond to intrusions.  NSM tools are
used more for network audit and specialized
applications than traditional alert-centric "intrusion
detection" systems.

Want to learn more about Network Security Monitoring
(NSM)? Then check out Richard Bejtlich's recently
released book, The Tao of Network Security Monitoring:
Beyond Intrusion Detection. An excerpt reads:

"Network security monitoring (NSM) equips security
staff to deal with the inevitable consequences of too
few resources and too many responsibilities. NSM collects
the data needed to generate better assessment, detection,
and response processes--resulting in decreased impact from
unauthorized activities."

WWW: http://sguil.sourceforge.net/index.php
pauls@utdallas.edu

PR:		ports/104227
Submitted by:	Paul Schmehl <pauls at utdallas.edu>
2006-10-31 02:43:25 +00:00
Jeremy Messenger
70cd04b258 Simple commandline wrapper around gpg that makes it store its passphrase
in gnome-keyring.  It is a direct competitor to (the unmaintained)
quintuple-agent.

Submitted by:	ahze
Approved by:	portmgr (kris and marcus)
2006-10-14 09:10:57 +00:00
Boris Samorodov
800e4e5443 Sguil (pronounced "sgweel") is a graphical interface to snort
(www.snort.org), an open source intrusion detection system.
The actual interface and GUI server are written in tcl/tk
(www.tcl.tk). Sguil also relies on other open source software
in order to function properly.

The sensor list includes security/barnyard, security/snort,
security/sancp, tcpdump (a part of the OS) and devel/tcltls as
well as lang/tcl84 and lang/tclX.  Care has been taken to ensure
that everything you need to build a working sguil operation is
in the FreeBSD ports system or part of the OS already.

Sguil currently functions as an analysis interface and has
no snort sensor or rule management capabilities.

WWW: http://sguil.sourceforge.net/index.php
pauls@utdallas.edu

PR:		ports/95018
Submitted by:	Paul Schmehl <pauls at utdallas.edu>
2006-10-09 19:04:38 +00:00
Rong-En Fan
243c063a6a Add p5-openxpki-deployment 0.9.543, perl based enterprise class
trustcenter software for PKI.

PR:		ports/103949
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:32:19 +00:00
Rong-En Fan
0ffdd411b1 Add p5-openxpki-i18n 0.9.538, perl based trustcenter software for PKI:
i18n tools.

PR:		ports/103948
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:31:50 +00:00
Rong-En Fan
ab27869dd7 Add p5-openxpki-client-soap-lite 0.9.421, SOAP-Lite toolkit for
openxpki.

PR:		ports/103947
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:31:24 +00:00
Rong-En Fan
e240e8975b Add p5-openxpki-client-scep 0.9.421, client for SCEP requests to
openxpki server.

PR:		ports/103946
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:30:55 +00:00
Rong-En Fan
2259b7c0e8 Add p5-openxpki-client-html-mason 0.9.546, web interface for local
openxpki daemon.

PR:		ports/103945
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:30:21 +00:00
Rong-En Fan
9f6ee59f79 Add p5-openxpki-client-cli 0.9.459, command line interface for local
openxpki daemon.

PR:		ports/103944
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:29:54 +00:00
Rong-En Fan
84542c0a32 Add p5-openxpki-client 0.9.450, perl based trustcenter software for PKI:
base class for actual clients.

PR:		ports/103943
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:29:03 +00:00
Cheng-Lung Sung
281c4c0d24 Add p5-Crypt-GCrypt 1.15, perl interface to the GNU Cryptographic
library.

PR:		ports/103767
Submitted by:	TAKAHASHI Kaoru <kaoru at kaisei.org>
2006-10-06 04:58:39 +00:00
Alejandro Pulver
a37457ae0e The Metasploit Project
This is the Metasploit Project. The goal is to provide useful
information to people who perform penetration testing, IDS signature
development, and exploit research. This site was created to fill the
gaps in the information publicly available on various exploitation
techniques and to create a useful resource for exploit developers. The
tools and information on this site are provided for legal penetration
testing and research purposes only.

This port is an in-development version of the upcoming Metasploit Framework.
It is based on Ruby instead of perl, and has a different license.

WWW: http://www.metasploit.org

PR:		ports/101280
Submitted by:	Yonatan <onatan at gmail.com>
2006-10-05 00:05:52 +00:00
Andrew Pantyukhin
13656ce767 - Separate sinfp into library (p5-Net-SinFP) and binary+db (sinfp)
- Use latest db snapshot
2006-09-30 15:36:00 +00:00
Martin Wilke
acfcbd1c4c PBNJ is a network suite to monitor changes that occur on a network
over time. It does this by checking for changes on the target
machine(s), which includes the details about the services running on
them as well as the service state. PBNJ parses the data from a scan
and stores it in a database. PBNJ uses Nmap to perform scans.

WWW: http://www.sf.net/projects/pbnj

PR:		ports/100904
Submitted by:	Joshua D. Abraham <jabra(at)ccs.neu.edu>
2006-09-30 07:30:18 +00:00
Cheng-Lung Sung
eede56113d Add blocksshd 0.8, protects computers from SSH brute force attacks.
PR:		ports/102367
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-09-26 10:26:06 +00:00
Martin Wilke
141f8510d6 Fwipe is a secure file erasing program. fwipe0, which actually erases
your files, is immune to filenames containing spaces, carriage returns,
dashes, or any other special characters. You can use it in place of rm
in cron jobs, together with "find ... -print0". The output of fwipe0 is
specially designed to be parsed easily by machine, so it can be embedded
in other applications which need secure file erasure.

WWW: http://jeenyus.net/~budney/linux/software/fwipe.html

PR:		ports/103488
Submitted by:	David Thiel <lx(at)redundancy.redundancy.org>
2006-09-24 21:19:48 +00:00
Andrew Pantyukhin
35da930207 Add port security/shttpscanner:
Simple HTTP Scanner is a creation made for web site pen testing. You can
check for directories and files on the remote web server and get some
server information like the webserver running.

WWW: http://sourceforge.net/projects/shttpscanner/
Author: Paisterist <paisterist@users.sourceforge.net>
2006-09-24 20:18:15 +00:00
Jose Alonso Cardenas Marquez
bfc8d463f6 - Remove security/fpc-md5. It was renamed to security/fpc-hash
Approved by:	garga (mentor, implicit)
2006-09-07 21:40:37 +00:00
Jose Alonso Cardenas Marquez
13c8628fb5 - New port: 2006-09-07 21:09:28 +00:00
Roman Bogorodskiy
bb0e84c435 TLS Lite is a free python library that implements SSL 3.0, TLS 1.0, and TLS
1.1. TLS Lite supports non-traditional authentication methods such as SRP,
shared keys, and cryptoIDs in addition to X.509 certificates. TLS Lite is pure
Python, however it can access OpenSSL, cryptlib, pycrypto, and GMPY for faster
crypto operations. TLS Lite integrates with httplib, xmlrpclib, poplib,
imaplib, smtplib, SocketServer, asyncore, and Twisted.

WWW: http://trevp.net/tlslite/

PR:		ports/102923
Submitted by:	Alexander Botero-Lowry <alex at foxybanana.com>
2006-09-07 05:23:30 +00:00
Alex Dupre
bcfcdf474c Suhosin is an advanced protection system for PHP installations.
It was designed to protect servers and users from known and
unknown flaws in PHP applications and the PHP core.
Suhosin comes in two independent parts, that can be used
separately or in combination. The first part is a small patch
against the PHP core, that implements a few low-level
protections against bufferoverflows or format string
vulnerabilities and the second part is a powerful PHP extension
that implements all the other protections.

Suhosin is binary compatible to normal PHP installation,
which means it is compatible to 3rd party binary extension
like ZendOptimizer.

WWW: http://www.suhosin.org/
2006-09-04 08:02:04 +00:00
Kris Kennaway
0a6f04e280 Remove expired ports 2006-09-02 23:31:26 +00:00
Pav Lucistnik
bf663cc26b The pam_abl provides auto blacklisting of hosts and users
responsible for repeated failed authentication attempts.

WWW: http://www.hexten.net/pam_abl/

PR:		ports/100635
Submitted by:	Petr Rehor <prehor@gmail.com>
2006-09-01 18:34:03 +00:00
Roman Bogorodskiy
070fdc9acb GnuTLS is a portable ANSI C based library which implements the TLS 1.0 and
SSL 3.0 protocols. The library does not include any patented algorithms and
is available under the GNU Lesser GPL license.

Important features of the GnuTLS library include:
- Thread safety
- Support for both TLS 1.0 and SSL 3.0 protocols
- Support for both X.509 and OpenPGP certificates
- Support for basic parsing and verification of certificates
- Support for SRP for TLS authentication
- Support for TLS Extension mechanism
- Support for TLS Compression Methods

Additionaly GnuTLS provides an emulation API for the widely used
OpenSSL library, to ease integration with existing applications.

WWW:	http://www.gnutls.org/
2006-08-27 19:47:30 +00:00
Rong-En Fan
29ae2adb2a Add mosref 2.0.b3, a secure remote execution framework using a compact
Scheme-influenced VM.

PR:		ports/102238
Submitted by:	Piet Delport
2006-08-23 13:13:57 +00:00
Andrew Pantyukhin
c295728bd5 Add port security/sinfp:
SinFP is a new approach to OS fingerprinting, which bypasses
limitations that nmap has.

Nmap approaches to fingerprinting as shown to be efficient for years.
Nowadays, with the omni-presence of stateful filtering devices,
PAT/NAT configurations and emerging packet normalization technologies,
its approach to OS fingerprinting is becoming to be obsolete.

SinFP uses the aforementioned limitations as a basis for tests to be
obsolutely avoided in used frames to identify accurately the remote
operating system. That is, it only requires one open TCP port, sends
only fully standard TCP packets, and limits the number of tests to 2
or 3 (with only 1 test giving the OS reliably in most cases).

WWW: http://www.gomor.org/sinfp
2006-08-21 07:46:31 +00:00
Ion-Mihai Tetcu
cf787a73eb VNCcrack is a fast offline password cracker for VNC passwords.
By sniffing a VNC challenge-response sequence off the network
(typically when VNC is used without a decent cryptographic
wrapper like SSH or SSL), you can recover the password fairly
easily and quickly by letting VNCcrack pound on it.

WWW: http://www.randombit.net/projects/vnccrack/

PR:		ports/102279
Submitted by:	Pankov Pavel <pankov_p at mail.ru>
2006-08-20 12:09:31 +00:00
Shaun Amott
7b94055d70 Finish adding security/openvpn-devel after repocopy. 2006-08-19 15:15:27 +00:00
Rong-En Fan
93af334482 Add bruteblock 0.0.4, software for blocking bruteforce attacks with
ipfw.

PR:		ports/101254
Submitted by:	Dmitry Marakasov <amdmi3 at mail.ru>
2006-08-17 08:27:13 +00:00
Jose Alonso Cardenas Marquez
e00dd18649 - Remove security/linux-krb5-libs, it was integrated to linux_base-fc4.
Approved by:	garga (mentor)
2006-08-14 02:57:11 +00:00
Cheng-Lung Sung
a9fbcd3d1d - ruby-crypt is a pure-ruby implementation of a number of popular
encryption algorithms.
2006-08-10 15:47:15 +00:00
Cheng-Lung Sung
12079d2d9a Add p5-PerlCryptLib 1.03, perl interface to Peter Guttman cryptlib API.
PR:		ports/101658
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-08-09 03:51:27 +00:00
Ion-Mihai Tetcu
5a28389014 This library implements Blowfish, DES, and Triple-DES.
Author:	Gerd Stolpmann
WWW:	http://www.ocaml-programming.de/packages/

PR:		ports/101213
Submitted by:	Stanislav Sedov <ssedov at mbsd.msk.ru>
2006-08-04 16:25:22 +00:00
Jose Alonso Cardenas Marquez
dcac88c148 - New port: security/linux-krb5-libs
Kerberos V5 is an authentication system developed at MIT.

(Linux version)

WWW: http://web.mit.edu/kerberos/

- New port: security/linux-openssl

The OpenSSL Project is a collaborative effort to develop a robust,
commercial-grade, full-featured, and Open Source toolkit implementing
the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security
(TLS v1) protocols with full-strength cryptography world-wide. The
project is managed by a worldwide community of volunteers that use
the Internet to communicate, plan, and develop the OpenSSL tookit
and its related documentation.

OpenSSL is based on the excellent SSLeay library developed by Eric
A. Young and Tim J. Hudson. The OpenSSL toolkit is licensed under
an Apache-style licence, which basically means that you are free
to get and use it for commercial and non-commercial purposes subject
to some simple license conditions.

(Linux version)

WWW: http://www.openssl.org/

Approved by:	garga (mentor)
2006-08-04 15:03:55 +00:00
Rong-En Fan
92cdbfdf92 Add p5-Crypt-OICQ, cryptographic algorithm used by OICQ protocol.
This is for chinese/oicq.
2006-08-02 17:22:08 +00:00
Cheng-Lung Sung
b790572c0f Add pecl-tcpwrap 1.0, a PECL extension which provides tcpwrappers
binding.

PR:		ports/101136
Submitted by:	chinsan <chinsan.tw at gmail.com>
2006-08-01 13:42:17 +00:00
Rong-En Fan
e7ddca584f Add httprint 301, web server fingerprinting tool.
PR:		ports/101004
Submitted by:	Yonatan <onatan at gmail.com>
2006-08-01 13:06:55 +00:00
Jose Alonso Cardenas Marquez
b9c2bea73d New port: security/gpass
The GNOME Password Manager - GPass for short - is a simple
application, written for the GNOME 2 desktop, that lets you manage a
collection of passwords.  The password collection is stored in an
encrypted file, protected by a master-password.

GPass is released under the GNU GPL2 licence.

Features:

    * Clean and easy-to-use user interface.
    * Quick-search facility.
    * Username and password may easily be copied to the clipboard.
    * Encryption is done using the OpenSSL cryptographics library.
    * The built-in password generator helps you generate secure passwords.
    * You can launch a website and the associated username/passwords
      direct from GPass

Author: Kouji TAKAO <kouji -at- netlab.jp>
WWW:    http://projects.netlab.jp/gpass/

PR:		ports/100845
Submitted by:	ports_at_c0decafe.net <ports at c0decafe.net>
Approved by:	garga (mentor)
2006-08-01 11:12:26 +00:00
Rong-En Fan
21f7b02baa Add isnprober 1.02, penTest tool for TCP Initial Sequence Numbers
research.

PR:		ports/101005
Submitted by:	Yonatan <onatan at gmail.com>
2006-07-30 18:15:59 +00:00
Cheng-Lung Sung
c9c4d0a1c6 Add courieruserinfo 1.1.2, user account information retrieval utility.
PR:		ports/100900
Submitted by:	Andrew St. Jean <andrew at arda.homeunix.net>
2006-07-27 08:07:23 +00:00
Martin Wilke
3a02664880 Add trans-proxy-tor, transparent proxy used to redirect TCP
connections into Tor.

trans-proxy-tor is a transparent proxy
that uses PF to redirect TCP connections
through Tor (http://tor.eff.org/).

Programs that aren't aware of Tor
will use it without their knowledge,
and their traffic no longer leaves the
system unencrypted.

PR:		ports/99034
Submitted by:	Fabian Keil <fk at fabiankeil.de>
2006-07-22 09:56:26 +00:00
Martin Wilke
4fb2a83de5 Add dns-proxy-tor, resolves DNS requests through Tor.
dns-proxy-tor is a DNS server that stops
DNS leaks with applications that don't support
or aren't configured to use socks4a or Tor's DNS
resolution.

WWW: http://http://p56soo2ibjkx23xo.onion/

PR:		ports/99033
Submitted by:	Fabian Keil <fk at fabiankeil.de>
2006-07-22 09:47:54 +00:00
Cheng-Lung Sung
20937d1b03 Add p5-Data-Entropy 0.000, entropy (randomness) management.
PR:		ports/100547
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-07-20 01:21:50 +00:00
Erwin Lansing
63b87c5058 This is a pure perl implementation of the new AES Rijndael. You want
to use Crypt::Rijndael where available. This implementation is really
slow, but I am working on it.

WWW:	http://search.cpan.org/dist/Crypt-Rijndael_PP/

PR:		ports/100262
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-07-14 15:45:24 +00:00
Shaun Amott
a2aab3122c Add a port of "knock" - a flexible port-knocking server and client.
PR:		ports/94626
Submitted by:	shaun (me)
Approved by:	ahze (mentor, implicit)
2006-07-12 18:03:24 +00:00
Renato Botelho
d9bcb23339 This package provides an interface to the cracklib (libcrack) libraries that
come standard on most unix-like distributions. This allows you to check
passwords against dictionaries of words to ensure some minimal level of
password security.

From the cracklib README
CrackLib makes literally hundreds of tests to determine whether you've
chosen a bad password.

* It tries to generate words from your username and gecos entry to tries
to match them against what you've chosen.

* It checks for simplistic patterns.

* It then tries to reverse-engineer your password into a dictionary
word, and searches for it in your dictionary.

- after all that, it's PROBABLY a safe(-ish) password. 8-)

WWW: http://pecl.php.net/package/crack

PR:		ports/94244
Submitted by:	Bill Moran <wmoran at collaborativefusion.com>
2006-07-11 15:41:19 +00:00
Roman Bogorodskiy
053732df0e Remove gnutls-devel since the development version of gnutls is not
active yet.
2006-07-06 19:21:00 +00:00
Vasil Dimov
f4212e1cd8 Remove expired leaf ports:
2006-07-01 emulators/linux_base-fc3
2006-06-15 misc/linux-opengroupware
2006-07-01 net/opengk
2006-07-01 security/p5-Crypt-OpenPGP
2006-07-01 textproc/sed_inplace
2006-07-01 textproc/xml4j
2006-07-01 x11-wm/aewm++
2006-07-04 14:04:31 +00:00
Ion-Mihai Tetcu
76dc862617 Kovpn is a really simple OpenVPN GUI for everyday use. It is a client only GUI,
meaning that you cannot administrate an OpenVPN server with it (Look for kvpnc
if you want such a program). You can use it to connect and disconnect without
needing to open a console. You can also input username and/or password that
might be needed.
In Short: It can do everything an end-user want's for his everyday work with
OpenVPN.

WWW: http://www.enlighter.de/

--Anderson S. Ferreira <anderson@cnpm.embrapa.br>

PR:		ports/95709
Submitted by:	anderson@cnpm.embrapa.br
2006-07-03 21:08:02 +00:00
Erwin Lansing
d3de307fe3 Add p5-openxpki 0.9.342, perl based enterprise class trastcenter
software for PKI.

PR:		ports/99317
Submitted by:	Sergei Vyshenski <svysh@cryptocom.ru>
2006-06-28 12:52:48 +00:00
Aaron Dalton
2b2737e54b Adding port security/p5-Authen-PAAS, Perl Authentication & Authorization
Service

Approved by:	tobez (implicit)
2006-06-23 05:00:05 +00:00
Florent Thoumie
6ee2e58e9d Add OpenBSM 1.0a6, the Open Source Basic Security Module (BSM) Audit
Implementation.
2006-06-14 11:51:09 +00:00
Alex Dupre
6050f3251d Engine_pkcs11 is an implementation of an engine for OpenSSL.
It can be loaded using code, config file or command line and
will pass any function call by openssl to a PKCS#11 module.
Engine_pkcs11 is meant to be used with smart cards and software
for using smart cards in PKCS#11 format, such as OpenSC.

WWW:	http://www.opensc-project.org/engine_pkcs11/

Note: the port requires the OpenSSL installed from ports,
since dynamic engine loading is disabled in base system.
See PR bin/79570 for details.
2006-06-12 17:04:13 +00:00
Alex Dupre
acf7714db0 Pam_p11 is a plugable authentication module (pam) package
for using crpytographic tokens such as smart cards and
usb crypto tokens for authentication.

Pam_p11 uses libp11 to access any PKCS#11 module.
It should be compatible with any implementation, but it
is primarely developed using OpenSC.

Pam_p11 implements two authentication modules:
 * pam_p11_openssh authenticates the user using his
   openssh ~/.ssh/authorized_keys file.
 * pam_p11_opensc authenticates the user using
   certificates found in ~/.eid/authorized_certificates.

Pam_p11 is very simple, it has no config file, no options
other than the PKCS#11 module file, does not know about
certificate chains, certificate authorities, revocation
lists or OCSP. Perfect for the small installation with no
frills.

WWW:	http://www.opensc-project.org/pam_p11/
2006-06-12 17:00:25 +00:00
Alex Dupre
a8e121cb3c Libp11 is a library implementing a small layer
on top of PKCS#11 API to make using PKCS#11
implementations easier.

WWW:	http://www.opensc-project.org/libp11/
2006-06-12 16:58:38 +00:00
Erwin Lansing
9bf2eb4547 The NTLM (Windows NT LAN Manager) authentication scheme is the
authentication algorithm used by Microsoft.

NTLM authentication scheme is used in DCOM and HTTP environment. It is
used to authenticate DCE RPC packets in DCOM. It is also used to
authenticate HTTP packets to MS Web Proxy or MS Web Server.

Currently, it is the authentication scheme Internet Explorer chooses to
authenticate itself to proxies/web servers that supports NTLM.

WWW: http://search.cpan.org/dist/Authen-NTLM/

PR:		ports/98684
Submitted by:	James Thomason <james@divide.org>
2006-06-08 09:44:48 +00:00
Cheng-Lung Sung
6aa8cb1880 Add p5-Nmap-Parser 1.05, parse nmap scan data with perl.
PR:		ports/98576
Submitted by:	Joshua D. Abraham <jabra@ccs.neu.edu>
2006-06-06 08:49:36 +00:00
Renato Botelho
6721ecefac PAM module for TIS authsrv authentication
The pam_authsrv module provides TIS authsrv authentication to PAM-aware
applications. It has been tested under AIX 4.3.3 (using the Linux-PAM for
AIX patch) and 5.1, Solaris 8 and 9, RedHat Linux 7.2, and HP-UX 11.00.

The pam_authsrv source code is available from:

    ftp://ftp.feep.net/pub/software/PAM/pam_authsrv/pam_authsrv-1.0.2.tar.gz

Binaries of pam_authsrv are available as Encap packages for a variety of
platforms.

For further information, please see the enclosed README file.

WWW: http://www.feep.net/PAM/pam_authsrv/

PR:		ports/97157
Submitted by:	Jim Pirzyk <pirzyk@FreeBSD.org>
2006-06-05 13:00:31 +00:00
Ion-Mihai Tetcu
e7686467d4 Translated manual pages for security/nmap. Current list of
translations includes Spanish, French, Croatian, Japanese,
Polish, Portuguese, Romanian, Slovak and Chinese.

WWW: http://www.insecure.org/nmap/

PR:		ports/93598
Submitted by:	Daniel Roethlisberger <daniel@roe.ch>
Approved by:	lawrance (mentor, implicit)
2006-06-05 10:09:41 +00:00
Jean Milanez Melo
1d4970bb44 - Remove this port, the version was included in base system.
Approved by:	mnag (mentor)
2006-05-31 21:33:20 +00:00
Pav Lucistnik
5580b13f7d - Rename ports
security/gnomekeyring -> security/gnome-keyring
  security/gnomekeyringmanager -> security/gnome-keyring-manager
2006-05-28 15:22:13 +00:00
Johan van Selst
b5bd0897dd Let's not forget to update Makefile when adding new port (reminded by flz)
Approved by:	flz (mentor)
2006-05-26 14:26:36 +00:00
Aaron Dalton
e82e60987a Adding port security/p5-Crypt-Dining, The Dining Cryptographers' ProtocoAdding port security/p5-Crypt-Dining, The Dining Cryptographers' Protocoll
Approved by:	tobez (implicit)
2006-05-25 20:05:50 +00:00
Sergey Matveychuk
6bbfcfd62b A PAM module that allows you to require a special group or
user to access a service.

WWW: http://www.splitbrain.org/projects/pam_require/

PR:		ports/95187
Submitted by:	Chris Cowart <ccowart@rescomp.berkeley.edu>
2006-05-24 18:04:24 +00:00
Aaron Dalton
c8f0bc74a4 Adding port security/p5-Tree-Authz, a library implementing a Role-Based Access Control authorization scheme.
Approved by:	tobez (implicit)
2006-05-22 18:20:22 +00:00
Aaron Dalton
ed9a86da78 Adding port security/p5-Authen-Simple-RADIUS, RADIUS extension for security/p5-Authen-Simple.
Approved by:	tobez (implicit)
2006-05-22 17:30:35 +00:00
Aaron Dalton
378ea9059c Adding port security/p5-Authen-Simple-PAM, PAM extension for security/p5-Authen-Simple.
Approved by:	tobez (implicit)
2006-05-22 17:24:15 +00:00
Aaron Dalton
5d74ca5e78 Adding port security/p5-Authen-Simple-DBM, DBM extension for security/p5-Authen-Simple.
Approved by:	tobez (implicit)
2006-05-22 17:20:26 +00:00
Aaron Dalton
b21bd2820b Adding port security/p5-Authen-Simple-SMB, SMB extension for security/p5-Authen-Simple.
Approved by:	tobez (implicit)
2006-05-22 17:15:34 +00:00
Aaron Dalton
1760501dfa Adding port security/p5-Authen-Simple-SSH, SSH protocol extension for security/p5-Authen-Simple.
Approved by:	tobez (implicit)
2006-05-22 17:09:14 +00:00
Renato Botelho
895bfd837a PAM module for pseudouser authentication
PR:		ports/97159
Submitted by:	Jim Pirzyk <pirzyk@FreeBSD.org>
2006-05-22 11:50:04 +00:00
Aaron Dalton
ae50b32032 Adding port security/p5-Authen-Simple-Passwd, Passwd extension for security/p5-Authen-Simple.
Approved by:	tobez (implicit)
2006-05-22 05:37:30 +00:00
Aaron Dalton
87cb63c95e Adding port security/p5-Authen-Simple-HTTP, HTTP extension for security/p5-Authen-Simple.
Approved by:	tobez (implicit)
2006-05-22 05:27:24 +00:00
Aaron Dalton
dff0afe74c Adding port security/p5-Authen-Simple-Net, extension for security/p5-Authen-Simple allowing authentication via FTP, POP3, or SMTP.
Approved by:	tobez (implicit)
2006-05-22 05:19:07 +00:00
Aaron Dalton
cbd52b8357 Adding port security/p5-Authen-Simple-DBI, DBI extension for security/p5-Authen-
Simple.

Approved by:	tobez (implicit)
2006-05-22 05:07:49 +00:00
Aaron Dalton
b521fbe031 Adding port security/p5-Authen-Simple-LDAP, LDAP and ActiveDirectory extension to security/p5-Authen-Simple.
Approved by:	tobez (implicit)
2006-05-22 01:10:14 +00:00
Aaron Dalton
c3c2cd4d14 Adding port security/p5-Authen-Simple, a consistent and simple framework for authentication.
Approved by:	tobez (implicit)
2006-05-22 00:52:28 +00:00
Andrew Pantyukhin
0852e66295 Add py-cerealizer: Secure pickle-like module
PR:		ports/96944
Submitted by:	Jose Alonso Cardenas Marquez <acardenas@bsd.org.pe>
Approved by:	krion (mentor)
2006-05-17 10:44:48 +00:00
Renato Botelho
52ba1c313f PAM module for per-user authentication
PR:		ports/97158
Submitted by:	Jim Pirzyk <pirzyk@freebsd.org>
2006-05-16 15:34:08 +00:00
Aaron Dalton
f339ced151 Add ipfwcount 0.2.1, summarise ipfw logs by counting and sorting the
fields.

PR:		ports/92454
Submitted by:	Robert Archer <freebsd@deathbeforedecaf.net>
Approved by:	tobez
2006-05-13 16:33:50 +00:00
James E. Housley
e4054d3289 Since the DAT files are so short lived on the server, have this port
automatically fetch the current DAT file.  The uvscan-dat port will
be removed shortly.
2006-05-09 12:08:51 +00:00
Ion-Mihai Tetcu
bdcd0201a6 TrustedPickle is a Python module that can save most any arbitrary Python object
in a signed pickle file. There are two big differences between this module and
the standard pickle module. First, TrustedPickle can pickle a module, but the
standard pickle module cannot. Second, TrustedPickle includes a signature that
can verify the data's origin before the data is unpickled.

WWW: http://trustedpickle.sourceforge.net/index.html

PR:		ports/96691
Submitted by:	Alexander Botero-Lowry <alex@foxybanana.com>
Approved by:	lawrance (mentor)
2006-05-09 11:46:02 +00:00
Andrew Pantyukhin
0922dea7a2 Add parano: A Gnome program to deal with hashfiles
PR:		ports/96710
Submitted by:	sat
Approved by:	krion (mentor)
2006-05-08 14:06:14 +00:00
Emanuel Haupt
c24ab61dd2 Add rainbowcrack 1.2, a hash cracker that precomputes plaintext -
ciphertext pairs in advance.

PR:		96664
Submitted by:	bryan@freshdns.net
2006-05-08 00:52:28 +00:00
Cheng-Lung Sung
54b2e35f60 Add medusa 1.0, a speedy, massively parallel, modular, login
brute-forcer.

PR:		ports/96641
Submitted by:	David Thiel <lx@redundancy.redundancy.org>
2006-05-02 07:36:47 +00:00
Pav Lucistnik
6a26ebefa7 courierpasswd is an authentication and password changing utility
that uses the courier-authlib authentication library to find user credentials.

Its interface follows that of Daniel J. Bernstein's checkpassword program.

WWW: http://www.arda.homeunix.net/store/

PR:		ports/96572
Submitted by:	Andrew St. Jean <andrew@arda.homeunix.net>
2006-05-01 20:46:26 +00:00
Ying-Chieh Liao
a8137202c2 add p5-Authen-TypeKey 0.05
TypeKey authentication verification

PR:		94679
Submitted by:	Gea-Suan Lin <gslin@gslin.org>
2006-05-01 04:04:11 +00:00
Pav Lucistnik
6fa6a66529 Tcl SASL provides a Tcl interface to the Cyrus SASLv2 library.
WWW: http://beepcore-tcl.sourceforge.net/tclsasl.html

PR:		ports/96359
Submitted by:	Denis Shaposhnikov <dsh@vlink.ru>
2006-04-29 15:55:15 +00:00
Pav Lucistnik
185fa8dd77 Password Manager helps to manage large numbers of passwords and related
information and simplifies the tasks of searching and entering password data.

KedPM is written as an extensible framework, which allows users to plug in
custom password database back-ends and custom user interface front-ends.
Currently, only the Figaro PM back-end supported. To control KedPM user can
choose between CLI and GTK2 based GUI front-ends.

WWW: http://kedpm.sourceforge.net

PR:		ports/96321
Submitted by:	Tim Welch <twelch@thepentagon.org>
2006-04-29 15:44:46 +00:00
Jean Milanez Melo
22e951ba0f - New port:
fswatch is a utility to guard changes in a file system. fswatch is composed
of three simple programs: fswbuild, fswcmp, fswshow. fswbuild builds file
system information database. fswcmp compairs two database files and returns
what changes a in file system have been introduced. fswshow shows contents of
database file. a file information database is platform independend.

fswatch can collect the following information about files (and directories):
inode, links, uid, gid, mode, size, flags, ctime, checksum (sha1) ; and can
show which files were added, deleted or changed.

PR:		ports/95973
Submitted by:	dominik karczmarski <dominik@karczmarski.com> (maintainer)
Reworked by:	jmelo
Approved by:	mnag (mentor)
2006-04-25 01:55:02 +00:00
Vasil Dimov
9f11fc7d66 Remove expired ports:
2006-04-17 security/nessus-devel
2006-04-17 security/nessus-libnasl-devel
2006-04-17 security/nessus-libraries-devel
2006-04-17 security/nessus-plugins-devel
2006-04-17 07:19:40 +00:00
Archie Cobbs
e64e4b6ab5 Remove the skip port. Created before there was an IPSec implementation on
FreeBSD, it is now extremely obsolete. In any case it doesn't compile. Earlier
version of this port can still be used on older versions of FreeBSD of course.
2006-04-06 13:54:46 +00:00
Sergey Matveychuk
a0c8969618 UPEK TouchChip TFM/ESS Fingerprint BSP is a (binary only) BioAPI BSP which
provides support for UPEKs fingerprint sensors.

PR:		ports/93035
Submitted by:	Fredrik Lindberg <fli@shapeshifter.se>
2006-03-28 17:07:38 +00:00
Anton Berezin
c4ee7c086c Add security/p5-GSSAPI 0.20, a Perl extension providing access to the
GSSAPIv2 library.
2006-03-28 09:57:33 +00:00
Sergey Matveychuk
d053138b06 Anti-bruteforce PAM module for authentification services. It can be used to
prevent brute-force attacks on services like SSH or Telnet. It's highly
configurable and very fast.

WWW: http://mbsd.msk.ru/pam_af.html

PR:		ports/94113
Submitted by:	Stanislav Sedov <ssedov@mbsd.msk.ru>
2006-03-26 12:32:16 +00:00
Pav Lucistnik
078531c569 Password Gorilla is cross-platform Password Manager.
It uses TCL/Tk and runs on most platforms supported by Tcl/Tk.

WWW:	http://www.fpx.de/fp/Software/Gorilla

PR:		ports/93179
Submitted by:	Kay Lehmann <kay_lehmann@web.de>
2006-03-20 19:20:10 +00:00
Jean-Yves Lefort
d5fcf1d08f Add silktools.
SiLK, the System for Internet-Level Knowledge, is a collection of
netflow tools developed by the CERT/NetSA (Network Situational
Awareness) Team to facilitate security analysis in large networks.

SiLK consists of a suite of tools which collect and examine netflow
data, allowing analysts to rapidly query large sets of data.

WWW: http://silktools.sourceforge.net

PR:		ports/94623
Submitted by:	David Thiel <lx@redundancy.redundancy.org>
2006-03-19 23:11:14 +00:00
Tilman Keskinoz
b5dc8972d2 Add matrixssl, a small GPL'd SSL implementation. 2006-03-17 15:54:09 +00:00
Marcus Alves Grando
701e124a49 - Add port security/pecl-gnupg
This extension provides methods to PHP interact with gnupg.

WWW:	http://pecl.php.net/package/gnupg
2006-03-16 21:40:45 +00:00
Mark Linimon
eb39429955 Remove hpn-ssh; the functionality is now an option when building the
openssh-portable port.

Pointy hat to:	brooks
2006-03-15 20:00:08 +00:00
Renato Botelho
c0184bdf7d The Authen::Libwrap module allows you to access the hosts_ctl()
function from the popular TCP Wrappers security package.  This
allows validation of network access from perl programs against
the system-wide hosts.allow file.

WWW: http://search.cpan.org/dist/Authen-Libwrap

PR:		ports/92855
Submitted by:	Zach Thompson <hideo@lastamericanempire.com>
2006-02-06 11:37:06 +00:00
Pav Lucistnik
587c8499aa New slave port to security/barnyard - adds patches for sguil6
PR:		ports/92241
Submitted by:	Paul Schmehl <pauls@utdallas.edu>
2006-01-26 10:56:46 +00:00
Renato Botelho
774d0244c1 We all know that you should always check input variables, but PHP does not
offer really good functionality for doing this in a safe way.
The Input Filter extension is meant to address this issue by implementing
a set of filters and mechanisms that users can use to safely access their
input data.

WWW: http://pecl.php.net/package/filter

PR:		ports/92198
Submitted by:	Alexander Zhuravlev <zaa@zaa.pp.ru>
2006-01-24 17:09:46 +00:00
Pav Lucistnik
0fd18fb816 Net::SFTP is a pure Ruby implementation of the SFTP client protocol
(versions 1 through 5).

PR:		ports/91829
Submitted by:	Roderick van Domburg <r.s.a.vandomburg@student.utwente.nl>
2006-01-18 07:27:09 +00:00
Pav Lucistnik
e1638b45c7 Net::SSH is a pure-Ruby implementation of the SSH2 client protocol. It
supports the following features:

 - User authentication via explicit username/password, or using a
public-key/private-key pair.
 - Port forwarding, both from the local host to a remote computer via
the remote host, and from the remote host to the local host.
 - Execute processes on the remote machine, both interactively and
non-interactively ("batch").

PR:		ports/91828
Submitted by:	Roderick van Domburg <r.s.a.vandomburg@student.utwente.nl>
2006-01-18 07:20:26 +00:00
Brooks Davis
b9d80214a0 Add drupal-ldap_integration.
The ldap_integration Drupal module allows users to authenticate against
a LDAP directory.  Additionally, users can read and modify their data in
the LDAP directory subject to administrative restrictions.
2006-01-17 23:19:55 +00:00
Pav Lucistnik
9669e20176 ClamCour is a filter for courier MTA using ClamAV for scanning mails for
viruses.

PR:		ports/91740
Submitted by:	Milan Obuch <bsd@dino.sk>
2006-01-15 15:24:16 +00:00
Pav Lucistnik
f55d4d1c11 The (BSD) BioAPI service module for PAM provides authentication management
through BioAPI BSPs.

PR:		ports/91750
Submitted by:	Fredrik Lindberg <fli@shapeshifter.se>
2006-01-15 10:12:34 +00:00
Pav Lucistnik
7f980746a6 bioapitool is a small BioAPI management utility which allows enrollment and
verification of BIR entries.  It only implements a subset of the BioAPI
specification but should provide enough functionallity for basic account
management.

PR:		ports/91749
Submitted by:	Fredrik Lindberg <fli@shapeshifter.se>
2006-01-15 10:11:40 +00:00
Pav Lucistnik
15284a2fe6 BioAPI (Biometric Application Programming Interface) brings platform and device
independence to application programmers and biometric service providers.

PR:		ports/91734
Submitted by:	Fredrik Lindberg <fli@shapeshifter.se>
2006-01-15 09:29:14 +00:00
Pav Lucistnik
e1a049eeef - Move databases/pecl-hash to security/pecl-hash
PR:		ports/91680
Submitted by:	Alexander Zhuravlev <zaa@zaa.pp.ru> (maintainer)
Repocopies by:	marcus
2006-01-13 08:31:43 +00:00
Edwin Groothuis
0f76ae3ac3 New port: security/expiretable Utility used to remove entries from the pf(4) table based on their age
Expiretable is a utility used to remove entries from the pf(4) table
	based on their age.

	The age in question being the amount of time that has passed since
	the statistics for each entry in the target table was last cleared.

	WWW: http://expiretable.fnord.se/

PR:		ports/91481
Submitted by:	cris <cris@gufi.org>
2006-01-08 12:33:41 +00:00
Edwin Groothuis
dde12a2e74 Update: security/samhain 2.0.10 -> 2.1.0
Updating the Samhain integrity checking system to 2.1.0, a
        bugfix release.

        It's been requested by several people to break Samhain out
        into separate client and server ports. This PR does that,
        with a samhain-client and samhain-server port, as slave
        ports off of samhain. I'm not sure the best way to submit
        a PR to do this kind of action, but here is a shar of all
        three ports. If another format is desired, please let me
        know.  I'm also interested in feedback on the approach used
        for splitting these out.

PR:             ports/90305
Submitted by:   David Thiel <lx@redundancy.redundancy.org>
2006-01-07 07:57:51 +00:00
Edwin Groothuis
3b0c1b16dd Update: security/samhain 2.0.10 -> 2.1.0
Updating the Samhain integrity checking system to 2.1.0, a
        bugfix release.

        It's been requested by several people to break Samhain out
        into separate client and server ports. This PR does that,
        with a samhain-client and samhain-server port, as slave
        ports off of samhain. I'm not sure the best way to submit
        a PR to do this kind of action, but here is a shar of all
        three ports. If another format is desired, please let me
        know.  I'm also interested in feedback on the approach used
        for splitting these out.

PR:             ports/90305
Submitted by:   David Thiel <lx@redundancy.redundancy.org>
2006-01-07 07:56:46 +00:00
Edwin Groothuis
1146e3e7e9 [NEW PORT]: security/cutlass
The attached shar is for security/cutlass - an encrypted
	peer-to-peer voice, text, and file transmission protocol
	entended to bring encrypted Internet use to the masses.
	Also included is a sample application using the protocol.

Please note that the patch ommited from the PR will have to be added
when ports/91035 : [UPDATE]: security/botan is commited.

PR:		ports/91072
Submitted by:	Wesley Shields <wxs@csh.rit.edu>
2005-12-30 04:38:56 +00:00
Foxfair Hu
dbf9464889 Add ipfcount 0.1, summarise ipf logs by counting and sorting the fields.
PR:		ports/90811
Submitted by:	Robert Archer <freebsd@deathbeforedecaf.net>
2005-12-22 15:52:43 +00:00
Renato Botelho
7ae09659e8 Add openvpn-admin 1.9.2, GUI frontend to openvpn.
PR:		ports/90176
Submitted by:	Remington Lang <MrL0Lz@gmail.com>
2005-12-22 09:58:44 +00:00
Erwin Lansing
b063cb837c This is not C-code interface (like `Digest::MD5') but a Perl-only
implementation of MD4 (like `Digest::Perl::MD5'). Because of this, it is
slow but avoids platform specific complications. For efficiency you
should use `Digest::MD4' instead of this module if it is available.

WWW: http://search.cpan.org/dist/Digest-Perl-MD4

PR:		ports/90771
Submitted by:	Gabor Kovesdan
2005-12-22 09:27:37 +00:00
Erwin Lansing
22d628b6be Digest::SHA::PurePerl is a complete implementation of the NIST
Secure Hash Standard.  It gives Perl programmers a convenient way
to calculate SHA-1, SHA-224, SHA-256, SHA-384, and SHA-512 message
digests.  The module can handle all types of input, including
partial-byte data.
Digest::SHA::PurePerl is written entirely in Perl.  If your platform
has a C compiler, you should install the functionally-equivalent
(but much faster) Digest::SHA module.

WWW: http://search.cpan.org/dist/Digest-SHA-PurePerl

PR:		ports/90773
Submitted by:	Gabor Kovesdan
2005-12-22 09:25:34 +00:00
Erwin Lansing
b4c79d2622 This is not an interface (like "Digest::MD5") but a Perl implementation
of MD5. It is written in perl only and because of this it is slow but it
works without C-Code. You should use "Digest::MD5" instead of this
module if it is available. This module is only usefull for
computers where you cannot install "Digest::MD5" (e.g. lack of a
C-Compiler).

WWW: http://search.cpan.org/dist/Digest-Perl-MD5

PR:		ports/90772
Submitted by:	Gabor Kovesdan
2005-12-22 09:24:33 +00:00
Erwin Lansing
9d15acf68c Digest::Pearson::PurePerl is an implementation of Peter K. Pearson's hash
algorithm presented in "Fast Hashing of Variable Length Text Strings"
- ACM 1990. This hashing technique yields good distribution of hashed results
for variable length input strings on the range 0-255, and thus, it is well
suited for data load balancing.
If you prefer a fast implementation, you might want to
consider Digest::Pearson instead.

WWW: http://search.cpan.org/dist/Digest-Pearson-PurePerl

PR:		ports/90770
Submitted by:	Gabor Kovesdan
2005-12-22 09:19:54 +00:00
Erwin Lansing
71120f4bb8 TEA is a 64-bit symmetric block cipher with a 128-bit key and a variable number
of rounds (32 is recommended). It has a low setup time, and depends on a
large number of rounds for security, rather than a complex algorithm. It was
developed by David J. Wheeler and Roger M. Needham, and is described at
http://www.ftp.cl.cam.ac.uk/ftp/papers/djw-rmn/djw-rmn-tea.html .

WWW: http://search.cpan.org/dist/Crypt-TEA

PR:		ports/90717
Submitted by:	Gabor Kovesdan
2005-12-21 17:39:06 +00:00
Erwin Lansing
c7db2c962c Crypt::X509 parses X.509 certificates. Methods are provided for accessing most
certificate elements. It is based on the generic ASN.1 module by Graham Barr,
on the x509decode example by Norbert Klasen and contributions on the
perl-ldap-dev-Mailinglist by Chriss Ridd.

WWW: http://search.cpan.org/dist/Crypt-X509

PR:		ports/90716
Submitted by:	Gabor Kovesdan
2005-12-21 17:38:15 +00:00
Erwin Lansing
e9e4afbce5 The Crypt::SaltedHash module provides an object oriented interface to create
salted (or seeded) hashes of clear text data. The original formalization of
this concept comes from RFC-3112 and is extended by the use of different
digital agorithms.

WWW: http://search.cpan.org/dist/Crypt-SaltedHash

PR:		ports/90698
Submitted by:	Gabor Kovesdan
2005-12-21 16:37:19 +00:00
Erwin Lansing
e67874664b Shark is 64-bit block cipher that accepts a 128-bit key. It was
designed by Vincent Rijmen, Joan Daemen, Bart Preneel, Antoon
Bosselaers, and Erik De Win.

WWW: http://search.cpan.org/dist/Crypt-Shark

PR:		ports/90699
Submitted by:	Gabor Kovesdan
2005-12-21 16:35:33 +00:00
Erwin Lansing
01308ef90f The single exported subroutine in this module is for generating a salt
suitable for being fed to crypt() and other similar functions.

WWW: http://search.cpan.org/dist/Crypt-Salt

PR:		ports/90696
Submitted by:	Gabor Kovesdan
2005-12-21 16:31:51 +00:00
Erwin Lansing
89a50ab638 This module contains a simple S/Key calculator (as described in RFC
1760) implemented in Perl. It exports the function `key' by default, and
may optionally export the function `compute'.
`compute_md4', `compute_md5', `key_md4', and `key_md5' are provided as
convenience functions for selecting either MD4 or MD5 hashes. The
default is MD4; this may be changed with with the `$Crypt::SKey::HASH'
variable, assigning it the value of `MD4' or `MD5'. You can access any
of these functions by exporting them in the same manner as `compute' in
the above example.
Most S/Key systems use MD4 hashing, but a few (notably OPIE) use MD5.

WWW: http://search.cpan.org/dist/Crypt-SKey

PR:		ports/90695
Submitted by:	Gabor Kovesdan
2005-12-21 15:40:50 +00:00
Erwin Lansing
a0ef1b0ad6 Loki97 is 128-bit block cipher that accepts a variable-length key. It was
designed by Lawrie Brown, Josef Pieprzyk, and Jennifer Seberry. The default
key length in this implementation is 128 bits. Loki97 was one of the 15
candidates for the AES.

WWW: http://search.cpan.org/dist/Crypt-Loki97

PR:		ports/90694
Submitted by:	Gabor Kovesdan
2005-12-21 15:39:47 +00:00
Erwin Lansing
656ce31219 Crypt::License decodes an encrypted file and attempts to decrypt it by first,
looking for a hash pointer in the caller program called $ptr2_License. The
hash contains the path to the License file and an optional 'private' key list
of modules which will decrypt only with the 'private' key. OR, a hash key of
'next' with no particular value that indicates to look to the next caller on
the stack for the License pointer. If the pointer is not present or the
License file is not found successfully, then no further action is taken. If the
License file is successfully opened, and the contents validated then the
attached encrypted module is loaded and the seconds remaining until License
expiration are returned or now() in the case of no expiration. Undef is
returned for an expired license (module fails to load).

WWW: http://search.cpan.org/dist/Crypt-License

PR:		ports/90693
Submitted by:	Gabor Kovesdan
2005-12-21 15:37:30 +00:00
Erwin Lansing
a814e62c20 Khazad is a 128-bit key, 64-bit block cipher. Designed by Vincent Rijmen and
Paulo S. L. M. Barreto, Khazad is a NESSIE finalist for legacy-level block
ciphers. Khazad has many similarities with Rijndael, and has an extremely
high rate of diffusion.

WWW: http://search.cpan.org/dist/Crypt-Khazad

PR:		ports/90692
Submitted by:	Gabor Kovesdan
2005-12-21 15:30:06 +00:00
Erwin Lansing
420de3189a This module is a complete working Perl implementation of the Enigma Machine
used during World War II. The cipher calculations are based on actual Enigma
values and the resulting ciphered values are as would be expected from an
Enigma Machine.
The implementation allows for all of the Rotors and Reflectors available to the
real world Enigma to be used. A Steckerboard has also been implemented,
allowing letter substitutions to be made.

WWW: http://search.cpan.org/dist/Crypt-Enigma

PR:		ports/90683
Submitted by:	Gabor Kovesdan
2005-12-21 08:35:13 +00:00
Edwin Groothuis
459b8d16e6 [new port] security/chroot_safe
chroot_safe, a tool to chroot any application in a sane
	manner without requring binaries, shared libraries etc
	within the chroot or any support from the application. Works
	with any dynamically linked application.

	WWW: http://sourceforge.net/projects/chrootsafe

PR:		ports/90341
Submitted by:	Gabor Kovesdan <gabor.kovesdan@t-hosting.hu>
2005-12-20 20:47:45 +00:00
Erwin Lansing
c458b72e33 This package is used to encrypt and decrypt passwords generated by IMail.
See: http://www.ipswitch.com/products/imail_server/

WWW: http://search.cpan.org/dist/Crypt-Imail

PR:		ports/90686
Submitted by:	Gabor Kovesdan
2005-12-20 15:51:51 +00:00
Erwin Lansing
6e9eb278e0 Crypt::GOST_PP is a pure perl implementation of GOST, a 64-bit
symmetrical block cipher with a 256-bit key from the former Soviet
Union. Please read the Pod documentation contained in the module
itself for additional information, including the rationale behind
the writing of this module.

WWW: http://search.cpan.org/dist/Crypt-GOST_PP

PR:		ports/90685
Submitted by:	Gabor Kovesdan
2005-12-20 15:51:00 +00:00
Erwin Lansing
7a9dfa805e GOST 28147-89 is a 64-bit symmetric block cipher with a 256-bit
key developed in the former Soviet Union. Some information on it
is available at http://vipul.net/gost/ .
This module implements GOST encryption. It supports the Crypt::CBC
interface, with the functions described below. It also provides
an interface that is backwards- compatible with Crypt::GOST 0.41,
but its use in new code is discouraged.

WWW: http://search.cpan.org/dist/Crypt-GOST

PR:		ports/90684
Submitted by:	Gabor Kovesdan
2005-12-20 15:50:08 +00:00
Erwin Lansing
90136fe774 The Data Encryption Standard (DES), also known as Data
Encryption Algorithm (DEA) is a semi-strong encryption and
decryption algorithm.
The module is 100 % compatible to Crypt::DES but is implemented
entirely in Perl. That means that you do not need a C compiler
to build and install this extension.

WWW: http://search.cpan.org/dist/Crypt-DES_PP

PR:		ports/90682
Submitted by:	Gabor Kovesdan
2005-12-20 14:49:19 +00:00
Erwin Lansing
f394b93f7b The Chimera key exchange protocol generates a shared key between two parties.
The protocol was shown to be INSECURE. This module is therefore released for
purely academic curiosity.

WWW: http://search.cpan.org/dist/Crypt-Chimera

PR:		ports/90681
Submitted by:	Gabor Kovesdan
2005-12-20 14:42:58 +00:00
Andrey Slusar
ffea7eb5e0 Added p5-Crypto-MySQL, perl extension to compare MySQL passwords without libmysqlclient.
PR:		ports/90590
Submitted by:	Gabor Kovesdan <gkovesdan@t-hosting.hu>
Approved by:	sem(mentor)
2005-12-19 09:51:04 +00:00
Andrey Slusar
49f1cb6139 Added p5-Crypt-HCE_MD5, perl extension implementing one way hash chaining encryption using MD5.
PR:             ports/90589
Submitted by:   Gabor Kovesdan <gkovesdan@t-hosting.hu>
Approved by:    sem(mentor)
2005-12-19 09:35:13 +00:00
Andrey Slusar
ecdd1f15e2 Added p5-Crypt-HCE_MD5, perl extension implementing one way hash chaining encryption using MD5.
PR:		ports/90589
Submitted by:	Gabor Kovesdan <gkovesdan@t-hosting.hu>
Approved by:	sem(mentor)
2005-12-19 09:16:46 +00:00
Erwin Lansing
f17e6a49e1 Rabbit is a new stream cipher based on the properties of counter assisted
stream ciphers, invented by Martin Boesgaard, Mette Vesterager,
Thomas Pedersen, Jesper Christiansen, and Ove Scavenius of Cryptico A/S.

WWW: http://search.cpan.org/dist/Crypt-Rabbit

PR:		ports/90615
Submitted by:	Gabor Kovesdan
2005-12-18 22:13:44 +00:00
Erwin Lansing
4d58b3abc6 Sometimes it's necessary to protect some certain data against plain reading
or you intend to send information through the Internet. Another reason might
be to assure users cannot modify their previously entered data in a follow-up
step of a long Web transaction where you don't want to deal with server-side
session data. The goal of Crypt::Lite was to have a pretty simple way to
encrypt and decrypt data without the need to install and compile huge
packages with lots of dependencies.
Crypt::Lite generates every time a different encrypted hash when you
re-encrypt the same data with the same secret string. Nevertheless you
are able to make double or tripple-encryption with any data to increase
the security. Decryption works also on hashes that have been encrypted
on a foreign host (try this with an unpatched IDEA installation ;-).

WWW: http://search.cpan.org/dist/Crypt-Lite

PR:		ports/90614
Submitted by:	Gabor Kovesdan
2005-12-18 22:06:01 +00:00
Erwin Lansing
429feed8fc Generic Counter Mode implementation in pure Perl. The Counter Mode module
constructs a stream cipher from a block cipher or cryptographic hash funtion
and returns it as an object. Any block cipher in the Crypt:: class can be
used, as long as it supports the blocksize and keysize methods. Any hash
function in the Digest:: class can be used, as long as it supports
the add method.

WWW: http://search.cpan.org/dist/Crypt-Ctr

PR:		ports/90613
Submitted by:	Gabor Kovesdan
2005-12-18 21:59:47 +00:00
Erwin Lansing
23be9d08e9 Crypt::Caesar - Decrypt rot-N strings
WWW: http://search.cpan.org/dist/Caesar

PR:		ports/90612
Submitted by:	Gabor Kovesdan
2005-12-18 21:56:07 +00:00
Erwin Lansing
3a682b1c6d Generic CFB implementation in pure Perl. The Cipher Feedback Mode module
constructs a stream cipher from a block cipher or cryptographic hash funtion
and returns it as an object. Any block cipher in the Crypt:: class can be
used, as long as it supports the blocksize and keysize methods. Any hash
function in the Digest:: class can be used, as long as it supports the
add method.

WWW: http://search.cpan.org/dist/Crypt-CFB

PR:		ports/90611
Submitted by:	Gabor Kovesdan
2005-12-18 21:55:15 +00:00
Erwin Lansing
9c4705836e This code appears to have only cursory resemblance to Bruce Schneier's
blowfish and twofish algorithms in that it too has a table-based decoder.
Derivation from FairKeys code by Jon Lech Johanson at nanocrew.net.
If you don't know what that is, don't bother looking here further. This is
a Pure Perl implementation. I doubt there is any need for xs coding for
what would mainly be processing 16 bytes at a time. This code is part of an
ongoing effort to clone portions of the Apple iTMS in Perl for portability.
See www.hymn-project.org for prior efforts by others.

WWW: http://search.cpan.org/dist/Crypt-AppleTwoFish

PR:		ports/90610
Submitted by:	Gabor Kovesdan
2005-12-18 21:53:18 +00:00
Vanilla I. Shu
0a3fde80af Add sshit 0.5, checks for SSH/FTP bruteforce and blocks given IPs.
PR:		ports/90603
Submitted by:	Jui-Nan Lin <jnlin@csie.nctu.edu.tw>
2005-12-18 16:03:28 +00:00
Erwin Lansing
ca806cdbd7 Digest::Pearson is an implementation of Peter K. Pearson's hash algorithm
presented in "Fast Hashing of Variable Length Text Strings" - ACM 1990. This
hashing technique yields good distribution of hashed results for variable
length input strings on the range 0-255, and thus, it is well suited for
data load balancing.
The implementation is in C, so it is fast. If you prefer a pure Perl version
and can tolerate slower speed, you might want to consider
Digest::Pearson::PurePerl instead.

WWW: http://search.cpan.org/dist/Digest-MD5-Pearson

PR:		ports/90578
Submitted by:	Gabor Kovesdan
2005-12-17 21:50:56 +00:00
Erwin Lansing
7851a6d375 Digest::ManberHash - a Perl package to calculate Manber Hashes
WWW: http://search.cpan.org/dist/Digest-ManberHash

PR:		ports/90577
Submitted by:	Gabor Kovesdan
2005-12-17 21:46:44 +00:00
Erwin Lansing
0e5ac9c4a8 MD5 sums (see RFC 1321 - The MD5 Message-Digest Algorithm) are used as a
one-way hash of data. Due to the nature of the formula used, it is impossible
to reverse it.
This module provides functions to search several online MD5 hashes database and
return the results (or return undefined if no match found).

WWW: http://search.cpan.org/dist/Digest-MD5-Reverse

PR:		ports/90576
Submitted by:	Gabor Kovesdan
2005-12-17 21:45:20 +00:00
Erwin Lansing
b54f7fcc07 Get MD5 sums for files of a given path or content of a given url.
WWW: http://search.cpan.org/dist/Digest-MD5-File

PR:		ports/90567
Submitted by:	Gabor Kovesdan
2005-12-17 16:22:16 +00:00
Erwin Lansing
f42c6cee20 The Digest::JHash module allows you to use the fast JHash hashing algorithm
developed by Bob Jenkins from within Perl programs. The algorithm takes as
input a message of arbitrary length and produces as output a 32-bit
"message digest" of the input in the form of an unsigned long integer.
See http://burtleburtle.net/bob/hash/doobs.html for more information.

WWW: http://search.cpan.org/dist/Digest-JHash

PR:		ports/90564
Submitted by:	Gabor Kovesdan
2005-12-17 16:16:24 +00:00
Erwin Lansing
1c85e87a77 Digest::FNV is an implementation for the 32-bit version of Fowler/Noll/Vo
hashing algorithm which allows variable length input strings to be quickly
hashed into unsigned integer values. For more information about this hash,
please visit http://www.isthe.com/chongo/tech/comp/fnv/.

WWW: http://search.cpan.org/dist/Digest-FNV

PR:		ports/90563
Submitted by:	Gabor Kovesdan
2005-12-17 16:15:29 +00:00
Erwin Lansing
a1b6ae659b Digest::Elf provides an XS based implementation of the ElfHash algorithm.
ElfHash generates resonably 32 bit integer value from a string in a
reasonably short period of time.

WWW: http://search.cpan.org/dist/Digest-Elf

PR:		ports/90561
Submitted by:	Gabor Kovesdan
2005-12-17 16:02:09 +00:00
Erwin Lansing
a9fd566668 This is Encrypted MAC (EMAC), formerly known as Double MAC (DMAC).
Unlike HMAC, which reuses an existing one-way hash function, such as
MD5, SHA-1 or RIPEMD-160, EMAC reuses an existing block cipher to
produce a secure message authentication code (MAC).

WWW: http://search.cpan.org/dist/Digest-EMAC

PR:		ports/90560
Submitted by:	Gabor Kovesdan
2005-12-17 16:00:52 +00:00
Erwin Lansing
a1072b7f96 This is Encrypted MAC (EMAC), formerly known as Double MAC (DMAC).
Unlike HMAC, which reuses an existing one-way hash function, such as
MD5, SHA-1 or RIPEMD-160, EMAC reuses an existing block cipher to
produce a secure message authentication code (MAC).

WWW: http://search.cpan.org/dist/Digest-DMAC

PR:		ports/90550
Submitted by:	Gabor Kovesdan
2005-12-17 15:22:03 +00:00
Erwin Lansing
8f158d4ab3 Digest::DJB is an implementation of D. J. Bernstein's hash which returns a
32-bit unsigned value for any variable-length input string. An equivalent pure
Perl version is also available: Digest::DJB::PurePerl.

WWW: http://search.cpan.org/dist/Digest-DJB

PR:		ports/90549
Submitted by:	Gabor Kovesdan
2005-12-17 14:50:31 +00:00
Erwin Lansing
949a62cf04 This module implements the hashcash hash (or digest, although it's not
clearly a digest). For all your information needs please
visit http://www.hashcash.org.

WWW: http://search.cpan.org/dist/Digest-Hashcash

PR:		ports/90548
Submitted by:	Gabor Kovesdan
2005-12-17 14:44:25 +00:00
Erwin Lansing
6900e1d6f7 This module provides a perl implementation to generate 32 bits CRC digests for
buffers and files.

WWW: http://search.cpan.org/dist/Digest-Crc32

PR:		ports/90547
Submitted by:	Gabor Kovesdan
2005-12-17 14:16:08 +00:00
Erwin Lansing
3790a4a1ac The Digest::CRC module calculates CRC sums of all sorts. It contains wrapper
functions with the correct parameters for CRC-CCITT, CRC-16 and CRC-32.

WWW: http://search.cpan.org/dist/Digest-CRC

PR:		ports/90546
Submitted by:	Gabor Kovesdan
2005-12-17 14:06:58 +00:00
Erwin Lansing
d58838243c The Digest::Adler32 module implements the Adler-32 checksum as specified
in RFC 1950. The interface provided by this module is specified in Digest,
but no functional interface is provided.

WWW: http://search.cpan.org/dist/Digest-Adler32

PR:		ports/90545
Submitted by:	Gabor Kovesdan
2005-12-17 13:53:18 +00:00
Erwin Lansing
918a2b3ca2 Digest::SV1 - Cryptosleazically strong message digest format
WWW: http://search.cpan.org/dist/Digest-SV1

PR:		ports/90539
Submitted by:	Gabor Kovesdan
2005-12-17 12:09:13 +00:00
Erwin Lansing
94f64aa37c A perl module that implements the tiger hash, which is believed to be secure
and runs quickly on 64-bit processors.

WWW: http://search.cpan.org/dist/Digest-Tiger

PR:		ports/90537
Submitted by:	Gabor Kovesdan
2005-12-17 11:54:10 +00:00
Erwin Lansing
bf5342d0cb Digest::Whirlpool - A 512-bit, collision-resistant, one-way hash function
developed by Paulo S. L. M. Barreto and Vincent Rijmen.

WWW: http://search.cpan.org/dist/Digest-Whirlpool

PR:		ports/90536
Submitted by:	Gabor Kovesdan
2005-12-17 11:21:52 +00:00
Erwin Lansing
532ec61cb2 Haval is a variable-length, variable-round one-way hash function designed by
Yuliang Zheng, Josef Pieprzyk, and Jennifer Seberry. The number of rounds can
be 3, 4, or 5, while the hash length can be 128, 160, 192, 224, or 256 bits.
Thus, there are a total of 15 different outputs. For better security, however,
this module implements the 5-round, 256-bit output.

WWW: http://search.cpan.org/dist/Digest-Haval256

PR:		ports/90534
Submitted by:	Gabor Kovesdan
2005-12-17 10:30:12 +00:00
Emanuel Haupt
62ebcfd1d4 Add, security/fiked, a fake IKE PSK+XAUTH daemon based on VPNC.
This is a fake IKE daemon supporting just enough of the standards and Cisco
extensions to attack commonly found insecure Cisco PSK+XAUTH VPN setups.

If you know the pre-shared key, also known as shared secret or group password,
you can impersonate the VPN gateway in IKE phase 1, and learn XAUTH user
credentials in phase 2.

PR:		90372
Submitted by:	Daniel Roethlisberger <daniel@roe.ch>
2005-12-16 20:15:06 +00:00
Simon Barner
fd7e0f8f8e Add symbion-sslproxy 1.0.5, an SSL proxy for securing unsecure
connections.

PR:		ports/90216
Submitted by:	Gabor Kovesdan
2005-12-12 09:50:37 +00:00
Roman Bogorodskiy
4de7513dc0 Add gnutls-devel - development version of gnutls. 2005-11-28 10:07:51 +00:00
Edwin Groothuis
2d638f24b1 Add security/tor-devel 2005-11-26 01:04:38 +00:00
Edwin Groothuis
172444444e [NEW PORT] security/jailaudit: Generate portaudit reports for jails from the hostsystem
This port contains a script for generating portaudit reports
	for jails running on a FreeBSD system.

	Jailaudit runs in the Host-system and uses portaudit to
	create reports for every jail currently running.

	It can also be used to send specific report-mails to the
	owner of a jail by running it as a cronjob.

	/etc/crontab example:
	0   4   *   *   *   *   root   /usr/local/bin/jailaudit mail admin@foo.bar "foo.example.com bar.example.com"

	Sends reports-mails of the jails with the hostnames
	foo.example.com and bar.example.com to the mailaddr.
	admin@example.com.

	WWW: http://outpost.h3q.org/software/jailaudit/

PR:		ports/87581
Submitted by:	Philipp Wuensche <cryx-ports@h3q.com>
2005-11-25 02:31:06 +00:00
Edwin Groothuis
b164841180 New port: security/klamav
KlamAV - Clam Anti-Virus on the KDE Desktop

	KlamAV is a KDE 3 front-end to Clam Anti-Virus.  It includes
	the following features:

	- 'On Access' Scanning
	- Manual Scanning
	- Quarantine Management
	- Downloading Updates
	- Mail Scanning (KMail/Evolution)

PR:		ports/84342
Submitted by:	Anderson S. Ferreira <anderson@cnpm.embrapa.br>
2005-11-24 21:03:40 +00:00
Mario Sergio Fujikawa Ferreira
fe645fdf8c New port md4coll version 0.1: Fast MD4 collision generator 2005-11-23 05:16:42 +00:00
Mario Sergio Fujikawa Ferreira
e80ae8339a New port md5coll version 0.1: Fast MD5 collision generator 2005-11-23 05:15:03 +00:00
Sergei Kolobov
b612847503 - Disconnect security/prelude-nids from the parent Makefile
prior to deletion
2005-11-21 13:25:22 +00:00