|
May 17 10:02:40 PDT 2012
Your IP: 38.107.179.212
|
|
Campin dot Net
|
What in the heck is this page for?
|
|
I put this page together because I was having
trouble bookmarking my favorite web sites.
I decided that I needed to save them all on a web
page for easy reference... and here they are.
That's all this is, and I hope that some of you
find some use in it as well.
|
|
|
|
|
-
Introduction to Network Security by
Matt Curtin
-
RFCs about "Security"
-
The Australian CERT Unix Security Checklist
-
Introduction To Intrusion Detection Systems
-
NCSA is the National Computer Security Association. You'll find plenty of papers, reports and tools here.
-
Unix Guru Universe The Official Home Page for Unix System Administrators
-
The Information Systems Security Association (ISSA) is a not-for-profit international organization of information security professionals and practitioners
-
Murphy's Law and computer security by Wietse Venema.
-
Playing Hide and Seek, Unix style
By Phreak Accident
-
Wietse Venema's ftp site has tools and papers. Wietse wrote TCP Wrappers, co-wrote SATAN and is generally seen as a god in internet circles.
-
Improving the Security of Your Site by Breaking Into it by Dan Farmer
-
Cert's UNIX "Steps for Recovering from a Root Compromise" paper
-
An Evening with Berferd, In which a Cracker is Lured, Endured, and Studied by
Bill Cheswick (the firewall guru)
-
IF you're a Linux user, visit the
Linux Documentation Project
-
Lance Spitzner's page has a number of his white papers on
"Armoring Linux", "Armoring Solaris", the methods of the "Script Kiddie", and
much more.
-
At the
Laboratory for Information Technology (LIT), there are a number of interesting
security papers.
-
Shall We Dust Moscow?
(Security Survey of Key Internet Hosts & Various Semi-Relevant Reflections) by Dan Farmer
-
A white paper:
The Inevitability of Failure:
The Flawed Assumption of
Security in Modern
Computing Environments
-
Read the
Linux Administrator's Security Guide
-
Read
Steve Sutton's NSA white paper on NT security guidelines.
-
Secure Windows NT Installation and Configuration Guide is step by step guide.
I don't have a link right now - search the web for it.
-
Check out the white paper
"Building an NT Bastion Host in Practice"
-
Ten tips to lock Linux
-
Linux "newbie" page has basic security info.
-
According to his web page
"Fred Cohen is one of the most recognized, respected,
and requested names in information protection today."
His page is a good resource for articles and information.
-
See the technical library at
www.netsys.com
-
Securing X Windows John Fisher, CIAC, 1995 (pdf format)
-
Dan Famer's security paper collection
-
Have you been wanting a copy of the "Orange" or "Red" book?
Here's the whole rainbow series:
http://csrc.ncsl.nist.gov/secpubs/rainbow/
A second link to the series is:
http://nsi.org/Computer/govt.html
-
A listing of Microsoft white papers on security is at
www.microsoft.com/security/Resources/whitepapers.asp
-
The SANS Institite
(System Administration, Networking, and Security) Institute is a cooperative
research and education organization through which more than 62,000 system
administrators, security professionals, and network administrators share the
lessons they are learning and find solutions for challenges they face.
-
FIRST is the Forum of Incident Response and Security Teams.
-
The best books on computers and computer security are
published by O'Reilly and Associates.
www.oreilly.com
-
Computer Security Information
This page features general information about computer security.
-
Read the
DOS Rules for a good laugh.
|
|
|
Free Operating Sytems
|
Linux
Berkeley Software Distribution
The BSD's are great for
firewalling and Intrusion Detection
due to powerful packet
capture code and a fast TCP/IP stack, and all are descendants of 4.4 BSD Lite
-
FreeBSD is the most popular of the BSD's. The goal of it's developers is to make the fastest, most advanced OS possible.
-
OpenBSD is an effort to develop a secure
operating system "out of the box."
Their motto: "Sending Kiddies to /dev/null since 1995" :)
-
Don't forget NetBSD.
This OS is possibly the most widely ported OS in history.
-
What is Darwin?
"Darwin is a complete operating system based
on the foundation technologies in Mac OS X
Server. It is an advanced BSD Unix system
which offers advanced networking, services
such as the Apache web server, and support
for both Macintosh and Unix filesystems.
Darwin runs on Power Macintosh and Intel
PC-compatible computers."
Open Source Projects at Apple
|
|
|
Scan Detection
|
-
Portsentry
takes action when it detects scans - usually that action is
to "blackhole" the attacker (risky, but some people find it useful, myself included).
-
Available for Unix and Windows, is Marcus Ranum's
"Back Officer Friendly."
It will tell you when you are scanned for Back Orifice,
and can be made to listen on other commonly scanned ports.
|
|
|
NT/Microsoft Security
|
-
NT Objectives
-
Diamond Computer Systems Pty. Ltd have released a BO2K scanner as freeware to the global public domain.
-
CIAC NT
-
Microsoft maintains a security page at
www.microsoft.com/security
-
Windows NT Magazine usually has NT Security articles to read.
They are at
www.winntmag.com/
-
Carvdawg's Perl Page has a couple good NT security items like a scanner and a Tripwire wannabe perl script.
-
NTBugtraq.com is the web page for the
NTBugtraq mailing list. Check out the
faq section and the
fixes section.
-
If you manage even one NT machine you should check this page regularly.
www.ntsecurity.net/
-
NT admins should check out Jim Buyens' Windows NT System Administration page
-
ADDING NEW SERVICES TO THE WINDOWS NT KERNEL ( NATIVE API ) ON INTEL 80X86 PROCESSORS
-
Netcat for NT is the indispensable tool you never knew
you needed. Read about (and download) it at:
www.l0pht.com/~weld/netcat/
-
Open Service Ports for WindowsNT, Terminal Server, & ExchangeServer
-
Every NT box needs tools for performance tuning and security monitoring from
www.sysinternals.com. If you've never been
there, go NOW!
-
I'm sorry but I just had to include this:
The "Boycott Microsoft Page" at
www.vcnet.com/bms/
-
BHS 32 Bit Download Center! The best 32-bit Shareware,Freeware,Trialware and Drivers on the Internet for NT!
This site is good for security tools, you can get the NT Objectives tools, Sysinternals tools, and more.
-
Ever wonder if the $ you spent on NT Server could
have been spent a little more wisely? Well then this article on the (small) differences between
NT Workstation and NT Server won't help a bit :)
-
NT Freeware and Shareware
Internet Resources for Windows NT®. is provided as a pointer to Internet applications, documents and resources that are available for Microsoft® Windows NT®. It's got everything from BOOTP, DHCP, DNS Servers to Document Management to Web Servers
-
Make your NT box more like UNIX:
-
cygwin
Recommended - these are the real GNU programs!
|
|
|
Information Warfare
|
-
The Critical Infrastructure Assurance Office (CIAO), announced by President Clinton in May 1998, will facilitate the creation of a national plan to protect the services that we depend on daily: telecommunications, banking and finance, electric power, transportation, gas and oil, emergency services and government services.
www.ciao.gov is their site.
-
Information Warfare and Information Security on the Web
www.fas.org/irp/wwwinfo.html
|
|
|
Other Infosec Sites
|
-
COAST-Computer Operations, Audit, and Security Technology.
COAST is a multiple-project, multiple-investigator laboratory in computer security research in the Computer Science Department at Purdue University. It is intended to function with close ties to researchers and engineers in major companies and government agencies. It focuses its research on real-world needs and limitations, with a special focus on security for legacy computing systems. With its recent increase in support and student and faculty participation, COAST is now the largest dedicated, academic computer security research group in the world.
|
|
|
Security-minded Mail Servers
|
-
"What is
Postfix?
It is Wietse Venema's attempt to provide an alternative to the widely-used
Sendmail program.
Sendmail is responsible for an estimated 70% of all e-mail
delivered on the Internet. With an estimated 100 million users, that's billions
of messages daily. A stunning number.
Postfix attempts to be fast, easy to administer, and secure,
while at the same time being sendmail compatible enough to not
upset existing users."
-
qmail has a
security guarantee
with an unclaimed reward.
|
|
|
Open Source Software
|
-
The unofficial spokesman for Open Source Software
(besides Richard Stallman, Linus Torvalds and Tim O'Reilly) is Eric Raymond.
His paper
"The Cathedral and the Bazaar" is considered the definitive paper on the subject.
Visit his home page.
-
How can we mention Open Source without providing a link to
www.gnu.org
Richard Stallman is the man who brought the issues to everyone's attention.
-
The developerWorks open source zone hosts a variety of projects for the open-source community. All projects on this zone are licensed under the same IBM Public License, which has been approved by the Open Source Initiative.
|
|
|
|