| :: | Security Cheat-Sheet Collection from zeltser.org
The following documents are security-related cheat-sheets, taken from
zeltster.com, a very good resource for
security-informations, both before an incident and after. This section covers actions to be taken
bevore an incident; our DONT PANIC emergency-kit covers what to do AFTER
a secruity-related incident. This compilation also covers webbased cheat-sheets for SQL/XSS-prevention.
Kategorien: [ security it rootserver technic ]
| :: | INTERNET PIZZO
Another very interesting suggestion from the Team @ snortattack.org on how to manage secure webservices through IPS (snort) and a proxy (NGINX).
Intro From the paper:
With the expression "Internet Pizzo" we may reference a system which is able to protect
Internet services remotely; the Italian term "pizzo" (as "protection") is hereby used in
an ironic and mocking form, far distant from its literal meaning, which refers to the fee
that mobsters require to assure "protection". "Remote protection" is the peculiar and
innovative feature of this system, i.e. the ability to protect services that are not
physically close to the security infrastructure.
We will show that, thanks to a "NGINX" proxy and featuring proper IPS/firewall
protection, it’s feasible to extend a security perimeter beyond geographical boundaries.
Kategorien: [ security rootserver technic ]
|
| :: | IPS FLEXIBLE RESPONSE
The Team from SnortAttack.org comes up with some interesting whitepapers on how to use snort as an active Intrusion Prevention System (IPS).
The Whitepaper IPS FLEXIBLE RESPONSE describes the following: (from the Document):
The IPS acronym references an Intrusion Prevention System, i.e. a network security
device. It monitors the network traffic flow in order to feature real-time malicious traffic
blocking.
An IPS can be implemented using a server wherein Snort software works as an IPS,
while Iptables handles the more specific firewall tasks and, leveraging specific
packages, creates packet queues to be analyzed by the system.
Kategorien: [ security it rootserver ]
|
| :: | Security / Incident / Sysadmin Cheat Sheets and References
We compiled a list of security and incident-based cheat-sheets, questionaires, online.resources and response information as well as some (mostly *nix) systemadministration pocket reference cards for quick resonses in case of emergency.
For more information you might consult your literature or ask the mighty brother
Kategorien: [ security mare rootserver ]
|
| :: | The Twelve Networking Truths
RFC1925 - The Twelve Networking Truths
Network Working Group R. Callon, Editor
Request for Comments: 1925 IOOF
Category: Informational 1 April 1996
The Twelve Networking Truths
Status of this Memo
This memo provides information for the Internet community. This memo
does not specify an Internet standard of any kind. Distribution of
this memo is unlimited.
Abstract
This memo documents the fundamental truths of networking for the
Internet community. This memo does not specify a standard, except in
the sense that all standards must implicitly follow the fundamental
truths.
Acknowledgements
The truths described in this memo result from extensive study over an
extended period of time by many people, some of whom did not intend
to contribute to this work. The editor merely has collected these
truths, and would like to thank the networking community for
originally illuminating these truths.
Kategorien: [ security it ]
|
| :: | Z0F5 - Security Research Zine
Grossartige Artikelserie über die Sicherheit in der Security-Industrie selbst, einige ihrer **STARS** wie Kevin Mitnick, Dan Kaminsky, Robert Lemos und gierige Hacker/Skiddie - Gruppen wie Anti-Sec, Blackhat-forum et.al.
Wir spiegeln diesen Text, um uns immer wieder daran zu erinnern, die eigene Sicherheit hochzuhalten.
|
The security scene is fucked. You have Dan Kaminsky lecturing you on how DNS
poisoning will destroy life as we know it. You have Matasano harvesting talent
and critiquing everyone, and then Ptacek can only announce the release of....a
graphical firewall management client. There's kingcope killing bugs and
dropping weaponized exploits while making no other contribution except putting
a smile on the face of kiddies. There's iDefense and their competitors selling
exploits and only doing research in how to make more exploits. There's Jeff
Moss running a conference under the hideous misnomer "Blackhat Briefings" where
the same researchers search for glory and present the same shit year after
year. There are people who just live press release by press release. And on top
of it all, somehow you STILL have not got rid of Kevin Mitnick. The industry
cares about virtualization one year and iPhones the next, every year forgetting
the lessons it should have picked up in the last.
| |
Kategorien: [ security ]
|
| :: | NIST Technical Guide to Information Security Testing and Assessment
Security-Testing-Guide des National Institute of Standards and Technology (NIST); sehr umfangreiche Sammlung von Techniken und Standards, zur Planung, Durchführung und Auswertung von Security-Tests.
Aus dem Intro:
|
This document is a guide to the basic technical aspects of conducting information security assessments. It presents technical testing and examination methods and techniques that an organization might use as part of an assessment, and offers insights to assessors on their execution and the potential impact they may
have on systems and networks. For an assessment to be successful and have a positive impact on the
security posture of a system (and ultimately the entire organization), elements beyond the execution of
testing and examination must support the technical process. Suggestions for these activities—including a
robust planning process, root cause analysis, and tailored reporting—are also presented in this guide.
|
Kategorien: [ security technic ]
|
| :: | Securing Wordpress Whitepaper
Technisches Whitepaper, in dem Schritt für Schritt erklärt wird, wie eine Wordpress-Installationen abgesichert werden kann (en, 15 Seiten)
Aus dem Intro:
This paper provides you with all necessary information to improve the security for your blog. We try
to describe the steps in an easy, understandable way without to much tech talk, so that you can
easily follow them and you don’t run into problems with applying these changes to secure your blog.
All information can be found on BlogSecurity.net; this paper serves as a compact guide to secure
your blog. We will strive to keep this document updated, so check back regularly.
If you have questions, problems, ideas or something else related to this paper, feel free to contact us.
|
Links
Kategorien: [ security ]
|
| :: | OWASP Testing Guide V3
OWASP Testing Guide: Umfangreiche Anleitung, um Webapplikationen und zugrundeliegende Server (Web/Datenbank-Server) umfangreich auf Schwachstellen zu testen und die Ergebnisse zu analysieren.
Kategorien: [ security technic ]
|
| :: | Software Assurance Maturity Model (SAMM)
OWASP veröffentlicht ein umfangreiches Framework, um Entwickler und Software-Verantwortliche dabei zu unterstützen, Software im Ansatz sicher zu entwickeln. Das Framework (SAMM) steht unter einer Open License und kann frei verwendet werden.
Aus dem Intro:
The Software Assurance Maturity Model (SAMM) is an open framework to help organizations for-
mulate and implement a strategy for software security that is tailored to the specific risks facing the
organization. The resources provided by SAMM will aid in:
- Evaluating an organization’s existing software security practices
- Building a balanced software security assurance program in well-defined iterations
- Demonstrating concrete improvements to a security assurance program
- Defining and measuring security-related activities throughout an organization
Kategorien: [ security technic ]
|
| :: | SSL Server Rating Guide
Umfangreiches Handbuch von SSL Labs, um SSL-Serverkonfigurationen abzusichern und das Public-SSL-Server-Ranking zu verbessern.
Kategorien: [ security technic ]
|
| :: | Webserver-Security / linux-magazin.de
Webapplikationen sind meist beinahe schutzlos den Widrigkeiten des WWW ausgesetzt. Enthalten sie Fehler, hat das fatale Folgen. Das Apache-Modul Modsecurity schafft eine zusätzliche Knautschzone.
Kategorien: [ security rootserver technic ]
|
| :: | AWS Security Whitepaper (engl.)
Amazon Web Services (AWS) delivers a highly scalable cloud computing platform with high availability and dependability, and the flexibility to enable customers to build a wide range of applications. This document is intended to answer customer questions such as "How does AWS help me ensure my data is secure?" Specifically, AWS physical and operational security processes are described for network and infrastructure under AWS' management, as well as service-specific security implementations.
Kategorien: [ security technic ]
|
| :: | Firewall / Astaro - Fallstudien
Mehr als 100.000 Kunden vertrauen Astaro beim Schutz ihrer Unternehmensnetzwerke. Ausführlichere Informationen und Fallbeispiele dazu finden Sie auf der Astaro-Webseite.
Kategorien: [ security it ]
|
(c) copyright 2003 - 2010 MARE system Kiel
| PublicKey
| Datenschutz
| Impressum
| AGB
| Warum GNU/Linux?
|
excuse: We already sent around a notice about that.
|