
Top : Computers : Software : Operating Systems : Unix : Security :
FAQs, Help, and Tutorials
Websites
Recipes to secure network services on AIX. Download of scripts available.
site exerpt
AIX Network Hardening Oops! Your browser doesn't support frames. Try starting at the Table of Contents....Editorial from Dr. Dobb's Journal about Randal Schwartz's felony convictions for running Crack on unauthorized machines.
http://www.lightlink.com/fors/press/ddj9603.html
Thamer Al-Herbish's Raw IP Networking FAQ about networking below TCP/UDP and sniffing networks. Includes raw socket source code.
site exerpt
Raw IP Networking FAQ This faq is very old and most likely out dated. There has been an effort by Lukas Ruf to resurrect the faq and maintain it here Please know that the mailing list associated with the FAQ is also present there....The Computer Security Evaluation Frequently Asked Questions (V2.1)
site exerpt
Frequently Asked Questions Q is designed to answer common questions about the evaluation of trusted products. We have attempted to be as clear, precise and accurate as possible. Some answers are undoubtedly closer to this ideal than others. Comments on the FAQ may...Understanding file attribute bits and modes
site exerpt
ITworld.com Security basics, Part 1 Take control of your network perimeter using FreeMap, a free web service from Qualys.Qualys Better Security: A Practical GuideWatchGuard Layered Security Practices for Incorporating Wireless LANs into IntranetsWatchGuard IT in the small business Analyst briefing Wireless and mobile technology Analyst...Definitions of security holes, security principles, how to access files safely, and untainting input.
http://www.whitefang.com/sup
Collects and disseminates computer security information and resources to help users, systems administrators, managers, and security professionals better protect their data and systems.
site exerpt
NIST Computer Security Division's CSRC Home page Federal employees and contractors National Vulnerability Database (NVD) Computer Security Division Focus Areas: Cryptographic Standards and Application Security Testing Security Research/Emerging Technologies Security Management and Guidance A more complete listing of research areas is given here. CSD News: November 17,...A primer from prevention through recovery by Russell L. Brand.
ftp://ftp.cerias.purdue.edu/pub/doc/guidelines/primer.txt
Paper by Rajib K. Mitra about file permissions, daemons, stack overflows and scripts.
site exerpt
Unix Security Due to a lack of software and time, I was unable to produce The Guide in any form but Rich Text Format. Since then kind readers have helped me convert it to HTML and PDF (Adobe Acrobat but I have...Protecting Debian during installation and securing network services.
site exerpt
Securing Debian Manual This document describes security in the Debian project and in the Debian operating system. Starting with the process of securing and hardening the default Debian GNU/Linux distribution installation. It also covers some of the common tasks to set up a...To get to "ROOT" you have to have somewhere to start. For the purposes of this file, that somewhere is with the 'passwd' file.
site exerpt
G A C T Unix Passwords X system has as part of it's Operating system. The ROOT is a Trusted User account, THE most powerful account on a UNIX. If you can hack a ROOT you can utilize or exploit every function a UNIX is capable...Solaris system administration FAQs, articles and tips.
site exerpt
Securing Solaris A solaris security document Solaris security broadly falls under two groups one is where the system is accessible using local area network/vlan and it has to be secured against unauthorized access. Second is system is accessible over the Internet to a number of persons...Details some of the focus areas for security and provides suggestions to make it strong.
site exerpt
Securing Solaris A solaris security document A quick reference to commonly used unix commands Solaris Network Configuartion Simplified Quick reference to setting up network in Solaris system Performance Monitoring iostat vmstat netstat Introduction to performance monitoring tools with example and command syntax. crontab in Unix A...Collection of papers on writing safe setuid programs by Matt Bishop.
site exerpt
Writing Safe Setuid Programs Writing safe privileged programs (defined as programs that run with extra privileges but do not compromise security) is difficult. Here are some of the papers and talks I've given about this. Talks and Tutorials Adapting Formal Methods for Informal Use,...This report, written as a case study, presents results of a detailed information security audit of UNIX systems that belong to a fictitious company. It illustrates an approach to performing such an examination.
site exerpt
Lenny Zeltser Auditing UNIX Systems: A Case Study My team can help address your data protection and IT risk management concerns. I'll be teaching the Reverse-Engineering Malware course in September and November. Try a more effective way to research information security issues. Other versions of this article: Adobe...Online book on software security tips.
site exerpt
Secure Programming for Linux and Unix HOWTO This book provides a set of design and implementation guidelines for writing secure programs for Linux and Unix systems. Such programs include application programs used as viewers of remote data, web applications (including CGI scripts network servers, and setuid/setgid programs....Securing FreeBSD
site exerpt
Securing FreeBSD Protocols will use a normal font. This typographical distinction is useful for instances such as ssh, since it is a protocol as well as command. The sections that follow will cover the methods of securing your FreeBSD system that were...