Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography
Receive the tools necessary to be the rock star of your field. Our 12-month program teaches you the evolving world of multi-channel marketing as well as the complex issues and opportunities found in the industry.

ASP Free and Iron Speed Designer are giving away $5,500+ in FREE licenses. Iron Speed's RAD CASE toolset can save up to 80% of your coding time. One free license per week, one perpetual license per month!
Download and Activate to enter!

Web development can be a daunting task, even for specialists. There is a lot of information to absorb and a lot of technologies to learn in order to manage a superior website. When trying to learn the ropes, developers need a reliable source to introduce new ideas that can be easily implemented. When working on large projects, even web veterans may run into a technology or an aspect of a technology that they are unfamiliar with.

Learn More!


Download to Enter
| Contest Rules

Tutorials | Forums

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old February 18th, 2006, 06:34 PM
Cork Skate Cork Skate is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 263 Cork Skate User rank is Corporal (100 - 500 Reputation Level)Cork Skate User rank is Corporal (100 - 500 Reputation Level)Cork Skate User rank is Corporal (100 - 500 Reputation Level)Cork Skate User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 10 h 58 m 40 sec
Reputation Power: 9
Question Security Toolkits / Handbooks

Hi there,

Does anyone of some examples of Security Toolkits / Handbooks for small to medium businesses? I am looking for toolkits that focus on strength and depth. It is for some benchmarking of the various ones that are available on the market.

Any help is more than welcome.

Reply With Quote
  #2  
Old February 18th, 2006, 10:06 PM
drRAVALOT drRAVALOT is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2006
Posts: 29 drRAVALOT User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 48 m 24 sec
Reputation Power: 0
Quote:
Originally Posted by Cork Skate
Hi there,

Does anyone of some examples of Security Toolkits / Handbooks for small to medium businesses? I am looking for toolkits that focus on strength and depth. It is for some benchmarking of the various ones that are available on the market.

Any help is more than welcome.


Hey, im glad to see this post up, well there is a linux based LIVE CD called whax that has benchmarking tools and pennitration testing tools on it. This cd is very powerfull. everything from wirehacks to exploits , port scanners, it carrys the large frameworks and such. I use it at the company i work at now and it is a small med. company AND THE BEST PART ABOUT Whax is that it is FREE!!!! this is good for network security proffs. and such but we in the network security field are tired of script kiddies abusing it, if you are are a script kiddie which u dont sound like it then please dont use any software till you learn what is actually hapening and learn how to write your own exploits and learn what a payload is.

i know this is kind of a long answer for WHAX but i have to stress that script kiddies arent welcome because u still must know how to use the exploits so happy hunting and good luck !

Reply With Quote
  #3  
Old February 19th, 2006, 01:21 AM
kuza55's Avatar
kuza55 kuza55 is offline
It's only wrong if you're caught....
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Dec 2003
Location: Sydney, Australia
Posts: 1,286 kuza55 User rank is First Lieutenant (10000 - 20000 Reputation Level)kuza55 User rank is First Lieutenant (10000 - 20000 Reputation Level)kuza55 User rank is First Lieutenant (10000 - 20000 Reputation Level)kuza55 User rank is First Lieutenant (10000 - 20000 Reputation Level)kuza55 User rank is First Lieutenant (10000 - 20000 Reputation Level)kuza55 User rank is First Lieutenant (10000 - 20000 Reputation Level)kuza55 User rank is First Lieutenant (10000 - 20000 Reputation Level)kuza55 User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 3 Days 6 h 10 m 16 sec
Reputation Power: 172
I just wanted to mention that Whax has merged with Auditor (for a while now), and its called Backtrack now, its downloadable at remote-exploit.org in case you're wondering.

But what kind of toolkit/handbook are you looking for? There are many different ones out there, most geared at some specific niche....
__________________
- Alex
Web Security Research (my blog)
Handbook of Applied Cryptography (Free!)

Reply With Quote
  #4  
Old February 19th, 2006, 07:02 AM
drRAVALOT drRAVALOT is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2006
Posts: 29 drRAVALOT User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 48 m 24 sec
Reputation Power: 0
yes back track is in beta. its great i actually have it on a dual boot now, but anyway since it is beta there are some drivers that they are working on, so i would recomend sticking with wax or auditor till its out of beta unless you know what your doing ... and please again NO SCRIPT KIDDIES ALOUD!

Reply With Quote
  #5  
Old February 19th, 2006, 04:48 PM
Cork Skate Cork Skate is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 263 Cork Skate User rank is Corporal (100 - 500 Reputation Level)Cork Skate User rank is Corporal (100 - 500 Reputation Level)Cork Skate User rank is Corporal (100 - 500 Reputation Level)Cork Skate User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 10 h 58 m 40 sec
Reputation Power: 9
Cheers for that guys !!

Quote:
Originally Posted by kuza55
I just wanted to mention that Whax has merged with Auditor (for a while now), and its called Backtrack now, its downloadable at remote-exploit.org in case you're wondering.

But what kind of toolkit/handbook are you looking for? There are many different ones out there, most geared at some specific niche....


I am doing a project on security and i want to basically enable a company (small to medium, not much resources) to carry out a security and information audit and setup a security policy for heir needs. I want to be able to provide a handbook that will allow them to do that, and clear up any problems they may have while doing it.

I'm going review the toolkits / handbooks available and basically have a look at what is good and bad (bad, areas not covered enough) ..... in a nutshell, i suppose i want people to know that sticking in a firewall and anti-virus software is not enough (small business) and there are other measures to take.

Strength and Depth

Now i know this is extensive, but i want to look at as many toolkits as possible, i want to give them as much info as possible ... where something is covered very well, then i'll direct them there,.

Anyway .... thats the bones of what i am at.

Reply With Quote
  #6  
Old February 25th, 2006, 03:31 PM
drRAVALOT drRAVALOT is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2006
Posts: 29 drRAVALOT User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 48 m 24 sec
Reputation Power: 0
Quote:
Originally Posted by Cork Skate
Cheers for that guys !!



I am doing a project on security and i want to basically enable a company (small to medium, not much resources) to carry out a security and information audit and setup a security policy for heir needs. I want to be able to provide a handbook that will allow them to do that, and clear up any problems they may have while doing it.

I'm going review the toolkits / handbooks available and basically have a look at what is good and bad (bad, areas not covered enough) ..... in a nutshell, i suppose i want people to know that sticking in a firewall and anti-virus software is not enough (small business) and there are other measures to take.

Strength and Depth

Now i know this is extensive, but i want to look at as many toolkits as possible, i want to give them as much info as possible ... where something is covered very well, then i'll direct them there,.

Anyway .... thats the bones of what i am at.



well, for one implement physical security, such as " is there server room locked" and they should only have VERY FEW people only the Network admins in the server room, is there a LAB for testing, Only give access to people who need it ,, lock every one else out, theres guides online, and such about all theise general rules, As for Auditing ,,,, it matters what you wnat to audit and how much u want to spend,
some great aim auditing program/solution's are facetime, akonix but agian these cost $$$ , as for auditing exchange , emails and such there are programas out there ,, i cnat think of any of the top of my head, but we use one where i work, Another policy as for physical that i put in our security policy is employees are not aloud to touch the firewall settings on there computers, every onece in a while some guy will disable it, you also want to make sure that you add in Tape Back up systems, what if a hacker was to pennitrate your system and you lost everything, you NEED to back it up , via tape back up system or a remote back up offsite place , and also making your users use at least 8 character passwords with at least 1 cappital 1 lower case and a character and number. As much as it kills people to try and remember them it needs to be done, and your network admins could get blammed for a users ignorance of putting there dogs name as there password. if you have OutLook web access, implement https,

also lock computer for 15 min , after 4 or so false attempts of password logins, auto lock after 5 min of not using your pc.

you get the picture well i wish i could give u more but i actually have to run so sorry i couldnt go more in depth, i will maby later on
Hope this helps a little,

-- drRAVALOT

Reply With Quote
  #7  
Old February 25th, 2006, 03:33 PM
drRAVALOT drRAVALOT is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2006
Posts: 29 drRAVALOT User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 48 m 24 sec
Reputation Power: 0
real quick before i go ,,, if a employee is going to get laid off, suggestr that the network admin knows about it right before the employee is told there getting laid off, this allows the network admin to lock the user out of there computer so they cant create any back doors or steal data and such, and make sure the employee is escorted by some one out the building ,,, that part is almost 100 percent commen now a days.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Security Toolkits / Handbooks


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.

© 2003-2012 by Developer Shed. All rights reserved. DS Cluster 3 - Follow our Sitemap