http://www.Linux-Sec.net




  • Hardening-Tightening

    Security_Policy

  • Hardening-HOWTO

    Linux Distros

    Distro Patches

    Kernel-Patches

    Dedicated Servers
  • Firewalls
  • DNS Servers
  • Mail Servers
  • Web Servers

    Turn-Off Daemons

    Tighten Inetd Services


  • Top-10 Vulnerabilities

    Top-7 Security Mistakes

    Top-10 Vulnerabilities

    Top-20 Most Critical Vulnerability


    Top-10 Virus


  • Scans/Attacks Stats

    Top-10 Attacks

    Hacked Servers


  • One Minute Audits
  • OpenPorts Audit


    AntiVirus - AntiSpam
  • Anti-Spam
  • Anti-Virus

  • spam.wav


    Wireless [In]Security
  • Sniffers


  • Security Tools

    SSH_SSL

    Firewalls

    MailServer

    FileSystem

    VPN

    Port Scan Detectors

    IDS Tools

    LogFile Analysis

    Ethernet Monitoring

    Server Monitoring

    Tracking & Forensics


  • Hackers Tools

    Audit Tools

    Port Scanners

    Hacking Tools

    DDOS Tools

    Sniffer Tools

    Spoof Tools

    Exploits & Vulnerbilities


  • Wireless

    Wireless [In]Security


  • Misc

    Statistics

    Linux/BSD Distros

    Links,Articles,WatchDogs

    Security Mailing Lists/FAQs

    Liability Insurance



  • 1U Rackmount Chassis

    Custom-Chassis.com

    Linux-1U.net

    1U-ITX.net


    ITX-Blades.net


    Small PC cases

    Mini-Box.net

    Wrap-Box.net

    Wrap-OS.net


    Wan-Sim.net



    Linux-Consulting.com

    Linux-CAE.net

    Linux-Sec.net

    Linux-Boot.net

    Linux-Backup.net

    Linux-Wireless.org

    Linux-Office.net

    Linux-Video.net

    Linux-VOIP.net

    Linux-Jobs.net

    Linux-Diff.net

    1U-Raid5.net

    Linux-Howto.net


    Spam Reporting



    Free Linux CDs

    ISO9660.org

    Distro-CD.org

    Patch-CD.org




    Contact



    Linux is a registered trademark of
    Linus Torvalds

    More Linux Legalese


    Linux-Sec.net/Vulnerability


    Top-10 Common Security Mistakes

    Our Definition and Differences
    ( Exploits, Audits, PenTest, Vulnerabilities )


    Mailing Lists


    Exploits

    Vulnerabilities
    Physical-Vulnerability Network-Vulnerability Server-Vulnerability Proceedural-Vulnerability Software-Vulnerability

    Audit

    Hacking Tools

    PenetrationTest


    RootKits




    Vulnerability : Someone/Attacker reviews your Network, Server and Security Policies and determine your "weakpoints"


    Minimum Vulnerability Prevention
    • Dont Make the 7 or 10 Common Mistakes

    • ( 80% to 90% ) of your security breaches will be internal
      • By accident and ooopss
      • Default installations
      • Untested releases of patches, extra binaries
      • Employees want to get around established Corp Security Policy

    • Watch out for Un-happy (fired) ex-employees
    • Why do outside hackers/script kiddies hack away

    • Subscribe to the various Security Mailing Lists
    • Subscribe to the various CERT Advisories

    Common Vulnerabilities

    Physical Vulnerability
    • UnLocked Computer rooms and Un-Locked Spare parts
    • UnLocked power panels
    • UnLocked doors or locks without entry Logs

    • UnLocked Laptop and PCs and Tapes
      • What is on the disks ( PCs, Laptops ) and tapes ??
      • UnLocked cars

    • Pull/TripOver the power cord !!
    • Pull/TripOver the network cable !!

    • Passwd on pieces of paper, under the keyboard

    Network Vulnerability
    • A construction worker with a backhoe tearing up the road outside your building

    • Pull the power cord
    • Pull the network uplink cable

    • Live network connection but NOT monitored
      • ( conference room, wireless, dhcp, etc )

    • Install a Sniffer and see what is visible to the hacker/attacker
      • Park outside the building with a wireless Sniffer

    Server Vulnerability
    • Pull the network cable
    • Pull the power cord

    • Default Installation ... need patches and upgrades

      Harden the server

    Proceedural Vulnerability
    • Convenience vs Security vs Productivity Tradeoff
    • Easy to guess Passwds
      • Root passwd should be different on each server
    • Same userID or same passwd for various "secure/insecure" apps
      • ssh, email, pop3, vpn, ppp, wireless, ...
    • usually beyond the scope of the corp admin to go to employee's homes

    Software Vulnerability

    Copyright © 2000
    Linux-Consulting
    All Rights Reserved.
    Updated: Mon Sep 26 13:21:13 2005 PDT