etherscan --------- Etherscan is a "semi-intelligent" network monitoring tool. It monitors certain TCP/IP services for activity that indicates possible intruder presence. It is intended not only as a generic intrusion scanner, but also as a complement to the drawbridge filter package, covering areas of weakness inherent in bridging filter arrangements. It probably won't pick up the pro's, but it is pretty good at detecting the rest. The distribution of etherscan has been hotly debated within our group. One argument is that etherscan should be freely released, as the crackers already have equivalent knowledge and tools (they do), and restrictions would only hurt valid administrators. The counter argument is that free availability of the intrusion signatures would enable the crackers to design better intrusions, and the availability of sources would provide novice crackers a significant help. Our resultant compromise will be to provide copies to NIC registered site contacts, given an official request on respective letterhead. Requests should be sent to: Dr. Dave Safford Director, Supercomputer Center Texas A&M University MS 3363 College Station, TX 77843-3363