Linux Security
| Linux Network Security Very Sketchy, by Dave Regan, http://www.ao.com/~regan/security.html | |||||||
| Linux Network Security Introduction: http://www.linuxplanet.com/linuxplanet/tutorials/211/1 | |||||||
| Linux Network Security Links: http://nextofkin.penguinpowered.com/linux/security.html | |||||||
Books (from http://www.amazon.com/ ):
|
Basic Solutions:
| Access Control by Domain (Clients IP Address) | |
| Basic UID/Password scheme | |
| Secure Socket Layer (SSL) | |
| UID/Password over SSL | |
| Personal Certificates | |
| Kerberos for authentication (Kerberos may not be supported by the most popular browsers.) | |
| plugin technology and Java Applets |
Projects:
| "Columbia University" Kerberos (or CUkerb) | |||
| Project Mandarin at Cornell | |||
| S/IDENT (Stanford) | |||
| Shelob (CMU) | |||
Project
Minotaur (Carnegie Mellon University) : http://andrew2.andrew.cmu.edu/minotaur/
|
| NetScape Enterprise Server | |
| NCSA Security Tutorial | |
| OSF's WAND work http://www.opengroup.org/tech/dce/mall/dceweb.htm |
| Cookies ; (See http://www.research.digital.com/nsl/formtest/stats-by-test/NetscapeCookie.html http://www.research.digital.com/nsl/formtest/home.html to see which Browsers support cookies.) | |||
| IntelliSoft 's SNARE, | |||
| Gradient (Now; http://www.entegrity.com/) | |||
KLP ( Official
and UnOfficial home pages)
|
| KHTTP http://www.net.tsinghua.edu.cn/~ye/khttp-protocol.html http://www.net.tsinghua.edu.cn/~ye/khttpd-design.html |
| Nmap : http://www.insecure.org/nmap/index.html | |||||
| Nessus: http://www.nessus.org/ | |||||
| Saint: http://www.wwdsi.com/saint/ | |||||
| Nettest (Perl) : http://zorro.pangea.ca/~renec/nettest.php3 | |||||
| Tripwire | |||||
| Abacus Sentry/Logcheck | |||||
| SATAN | |||||
| small, fast "half-open" port scanners, etc | |||||
| IP Security (IPSec): | |||||
IPsec :
IPSec is a suite of RFC proposed standards that define a protocol
for packet-layer encryption.
|
| Sniffit : http://reptile.rug.ac.be/~coder/sniffit/sniffit.html | |||||
| CFS (Cryptographic File System) | |||||
| Kerberos :The Kerberos Network Authentication Service -- http://nii.isi.edu/gost-group/products/kerberos/ | |||||
Spoofing
|
Secure Linux-Based Servers
| Bastille Linux | |
| khaOS Linux: This Linux distribution is designed for the paranoid in the Linux user base, incorporating state-of-the art cryptographic tools (CFS--Cryptographic File System--Kerberos, IPsec, IPv6 and VPN technologies) and the integration of network security tools (Tripwire, Abacus, Sentry/Logcheck, SATAN, SAINT and more). | |
| Slinux: Slinux is a secure, specialized, server distribution. Development is still in very early stages. | |
| Spiro Linux |
IP Masquerade
| Linux IP Masquerade HOWTO : http://www.linuxdoc.org/HOWTO/IP-Masquerade-HOWTO.html (Local copy PDF) | |
| IP Masq ICQ : http://members.tripod.com/~djsf/masq-icq/ | |
| IP Masquerade Application Collection : http://members.home.net/ipmasq/ | |
| TkMasqdialer : Control PPP connections on a Masq server: http://www.midcoast.com.au/~mvoase/tkmasq.html |
Useful Web Sites:
| Linux.Security.Com: http://www.linuxsecurity.com/ | |
| Linux Kernel Auditing Project (Article): http://www.linuxsecurity.com/articles/projects_article-844.html | |
| The Soothingly Seamless Setup of Apache, SSL, MySQL, and PHP http://www.linuxsecurity.com/articles/server_security_article-850.html (Main article: http://www.devshed.com/Server_Side/PHP/SoothinglySeamless/) |
Some Stories:
| Hackers Breed Digital 'Zombies' : http://cbsnews.cbs.com/now/story/0,1597,204098-412,00.shtml (See also http://www.linuxsecurity.com/articles/general_article-846.html) |