Shield is an aggressive, modular firewall script for iptables which features easy configuration through a BSD-style configuration file, optional NAT support, TCP-wrapper-like functionality for service access, port forwarding, routable protection, DMZ support, and more.
6d4a00b5e40e1eb59e715669495cadfbb7e6c628667039d2b0c2913871df7bca
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
15e3fb1236a3da077eeebe487b3c5b667cc492ca1f43a5ac6385fe054184a451
The Secure-Linux patch adds a few security features to the kernel which, while not a complete method of protection, will stop most of the 'cookbook' buffer overflow exploits cold. It also adds the option of restricting the use of symlinks and named pipes in +t (temp) directories which fixes most tmp-race exploits as well. It can also add a little bit more privacy to the system by restricting access to parts of /proc to root so that users may not see who else is logged on or what they're doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction, and privileged IP aliases for kernel 2.0.
77027624534ebb3c6a25766a6aaef4b4529d268b3b22e0718bd21a731722355b
Iplayer (pronounced ip-layer) is a libpcap sniffer based on ipgrab. It is useful for building custom TCP/IP packets that will be injected by NASL scripts or by other raw socket-building tools such as sendip.
f190e0fc6ab2574044b9dd29d025392924de0f615bf3453f89c769a29d7ec503
Riley is a file integrity checker written in Perl, somewhat similar to Tripwire.
0003d72c1eadfdc96f434b6d85ce289d6f291acc228f773f009cdfecb5b6b4cc