Softpedia
 


LINUX CATEGORIES:



GLOBAL PAGES >>
NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
WEEK'S BEST
  • Linux Kernel 3.9.6 / 3....
  • Linux Kernel 3.0.82 LTS...
  • KDE Software Compilatio...
  • PulseAudio 4.0
  • Wireshark 1.10.0
  • NetworkManager 0.9.8.2
  • LibreOffice 3.6.6 / 4.0...
  • SystemRescueCd 3.7.0
  • Linux Kernel 3.10 RC6
  • Ubuntu Tweak 0.8.5
  • Home > Linux > System > Networking

    fl0p 0.0.1

    Download button

    No screenshots available
    Downloads: 421  View global page NEW!  Tell us about an update
    User Rating:
    Rated by:
    NOT RATED
    0 user(s)
    Developer:

    License / Price:

    Last Updated:

    Category:
    Michal Zalewski | More programs
    GPL / FREE
    December 6th, 2006, 15:05 GMT
    ROOT / System / Networking

     Read user reviews (0)  Refer to a friend  Subscribe

    fl0p description

    fl0p is a passive L7 flow fingerprinter that examines TCP/UDP/ICMP packet sequences.

    fl0p is a passive L7 flow fingerprinter that examines TCP/UDP/ICMP packet sequences.

    It can also can peek into cryptographic tunnels, can tell human beings and robots apart, and performs a couple of other infosec-related tricks.

    This approach differs from the techniques used by most other passive sniffers and mappers, and is advantageous in several interesting ways:

    - General flow behavior remains largely unchanged regardless of whether cryptographic tunnels or other obfuscation techniques are used. As such, backdoors or firewall evasion techniques that for example use SSL on port 443, can be told apart from browser traffic, and further investigated.

    - General insight into legitimate encrypted sessions can be gained; for example, it is possible to remotely tell successful and failed SSH authentication attempts apart, and react accordingly.

    - Human actions can be told apart from automated efforts: it is possible to ignore SMTP client programs, but single out humans manually interacting with the server on port 25; similarly, automated SSH login attempts can be told apart from human actions.

    Product's homepage

      


    TAGS:

    flow fingerprinter | examines TCP | ICMP packet sequences | fl0p | flow | fingerprinter

    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM