Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010 CFP

Linux Magazine is offering free booths for the CeBIT 2010 computer fair to selected open source projects. Apply Now!

  linux-magazine.com » Online » News » Scalp: Log Analyzer Finds Web Attacks  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Scalp: Log Analyzer Finds Web Attacks

Romain Gaucher, a specialist in web security, offers his Scalp tool in version 0.4. The log analyzer searches for attacks on Apache web applications.

Scalp’s Python script uses regular expressions of the PHP Intrusion Detection System (PHPIDS) project that monitors attacks on PHP applications. Methods used include cross-site scripting (XSS), cross-site request forgery (CSRF) and SQL injection. Because the Apache web server in its standard form does not employ POST request variables, it can detect only GET request attacks.

The tool outputs its results as a report in text, XML or HTML format (here an example).

Scalp sorting search results

Scalp can sort its search results by type of attack, as a formatted HTML page.

In its standard form, the script can handle Apache logs of more than 100 megabytes without a problem, according to Gaucher. Limiting the analysis to a timeframe and a particular type of attack can further reduce the search time for large data sets. The program also allows spot checks in large log files.

The tool consists of a single Python script. Users will also need to download a default filter file. Both are available on the project home page.

Romain Gaucher is currently working on a C++ version of his program.

(Mathias Huber)

Comments


Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
Improved Multi-Threading Performance: Google's Perf Tools Version 1.0
Apache Closes Down Vulnerabilities
Google Sets Jaiku Free
Apache Loses Market Shares to Microsofts IIS
Ivy 2.0 Manages Dependencies in Java Projects
Klone 2.0.0: Web Applications in C/C++
Live Streaming from ApacheCon Europe 2009

All about Apache in 19 talks

Watch 3 days full of Apache talks live from Amsterdam on March 25-27 in the convenience of your home or office. Topics are: Apache Hadoop, Tomcat for Developers and Administrators, HTTP Server Administration and much more.

Find out more

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]