Showing posts with label Network Security. Show all posts
Showing posts with label Network Security. Show all posts

Thursday, March 31, 2011

Linux Network Security (Administrator's Advantage Series)



Linux Network Security (Administrator's Advantage Series)
| 2005-03-30 00:00:00 | | 0 | Network Security


PROTECT YOUR NETWORK FROM HACKERS!

Linux networks are becoming more and more common, but security is often an overlooked issue. Unfortunately, in today?s environment all networks are potential hacker targets, from top-secret military research networks to small home LANs. Linux Network Security focuses on securing Linux in a networked environment, where the security of the entire network needs to be considered rather than just isolated machines. It uses a mix of theory and practical techniques to teach administrators how to install and use security applications, as well as how the applications work and why they are necessary. Starting with the need for security and understanding the problem, the book teaches administrators about packet filtering (firewalling) with iptables, hardening services such as Apache, BIND, Sendmail, FTP, and MySQL to prevent attacks, network analysis, encryption, local security, DoS attacks, and rootkits. Auditing networks for potential vulnerabilities and creating secure passwords is also explored. This is the one book that really details how to secure a Linux network.

KEY FEATURES * Provides a complete guide to finding, fixing, and preventing holes in a Linux network * Teaches all the main aspects of securing a small LAN, from routing and topology to configuring UNIX services, with particular emphasis on securing against remote attack * Teaches how a Linux firewall can be used to protect desktop systems inside the LAN from viruses, spam, and hackers * Includes a CD-ROM with various open source software that will allow administrators to implement the techniques from the book and begin securing their networks immediately

On the CD! (see Appendix F for more details) * SOFTWARE Includes John The Ripper password cracker, Ettercap, Nmap port scanner, Nessus vulnerability scanner, Nikto vulnerability scanner, LibSafe stack protection library, TripWire IDS, and Snort 2.2.0 IDS and packet sniffer * LINKS Hyperlinks to all the URLs mentioned in the book * FIGURES All the images used in the book

SYSTEM REQUIREMENTS UNIX/Linux: Linux operating system with a 2.4 or 2.6 (recommended) kernel; Pentium I processor, or equivalent; 64MB RAM (128MB or more recommended); CDROM drive; X Windows, optional; 80MB available hard disk space; Perl interpreter; GCC 2.96 or greater; WINDOWS: Windows 98, NT, or greater; Pentium I processor, or equivalent; 128MB RAM; CD-ROM drive; 80MB free hard disk space; Perl interpreter; C compiler

User review
A linux system is secure if you can depend on it and its software to behave as you expect
The focus of this book is not on formal definitions and theoricals models so much as it is on practical form. But in this book as many other books, does not address these topics in sufficient detail.


Instead, this book emphasizes the use of the security applications, as well as how the applications work and why they are necessary and many other interesting topics.


Yes, this is not the best book about security in linux servers, but yes is a good book for beginners and intermediate users using small LANs.



User review
One of the better books on this subject
If you are a network administrator who needs to get a quick handle on Linux security this would be a very good choice. It covers the basics of security in general (weak passwords, key logging, Trojans, network topology, etc.) as well as security issues that are specific to Linux.


It does a good job of explaining how Iptables are used in a firewall and how to tune the network. Linux Network Security does appear to thoroughly cover all the basic system security considerations including the passwd file, shadowing, enforcing security, using PAM, and SUDO security. The best part of the book is when the author gets to how to choose an appropriate distribution, use a chroot jail, and protect memory.


In addition to the basic Linux security common to all distributions the author discusses role based access control, the Linux Intrusion Detection System, and the secure Linux distribution SeLinux. The book ends with sections on securing the most common services for Linux - Apache, SSH, NFS, NIS, DNS, BIND, and FTP. It also includes a section on keeping your system secure using Tripwire.


If you need additional help on specific issues there are six appendixes which cover recompiling the kernel, kernel configuration for networking, firewall scripts, and cryptography. This book is obviously intended for the Linux network administrator, but the level of knowledge assumed is somewhat confusing. For some pieces it seems to assume no prior knowledge (like Chapters 1 and 2) and for other areas it seems to assume some basic prior understanding of Linux (although admittedly minimal). Keep in mind that there are whole books on some of these items (like securing Apache) so there is obviously much more detailed information available if you have a specific need. Linux Network Security is highly recommended to network administrators who are dealing with a basic file and print sharing network or who need a solid overview of Linux security and some of the security problems with common services.

User review
lots of info
despite its smallish size (550 pages) this book is packed full of useful info. the first couple of chapters are a whistle stop tour of the all the ways a linux box can be hacked, and the rest of the book describes how to fix these problems. most of the book is intermediate level, but a couple of the later chapters are more advanced. but i think this is a good thing because it means the book goes into much more detail than most others.

User review
Includes a Great Deal of Useful Software
Security is one of those things that everyone knows they should do but typically doesn't until too late. In spite of all the warnings most companies ignore the pleadings of the assigned security specialist until all of a sudden they are hit in the face with a penetration. And this is the theme of the introductory chapter, except that he explains it a lot better.


The second chapter starts with an explanation of John The Ripper. This is a program that attempts to automatically crack your system's password file. (The John The Ripper program is included on the books CD so you can use it to test your own system.)


By this point he had my attention. It was clear that if he wished he could get into my system and do whatever he wished. I interrupted my reading at this point and changed several system passwords to make them a lot more difficult.


After that I went on to read the rest of the book on finding, fixing and preventing holes in a Linux network. I never realized it was so easy.


The book is a combined explanation of what's happening and a wealth of software on the CD. This software, described in the text part of the book, is a selection of software off of the net. The net has a huge amount of software available. Here the author has selected a dozen or so packages that he discusses enough for you to use and to have some faith that the results you are getting are worthwhile.


Perhaps the best book on Linux security ever.


Download this book!

Free Ebooks Download

Saturday, February 19, 2011

Network Infrastructure Security



Network Infrastructure Security
| 2009-05-20 00:00:00 | | 0 | Network Security


Research on Internet security over the past few decades has focused mainly on information assurance, issues of data confidentiality and integrity as explored through cryptograph algorithms, digital signature, authentication code, etc. Unlike other books on network information security, Network Infrastructure Security by Angus Wong and Alan Yeung addresses the emerging concern with better detecting and preventing routers and other network devices from being attacked or compromised.

Attacks to network infrastructure affect large portions of the Internet at a time and create large amounts of service disruption, due to breaches such as IP spoofing, routing table poisoning and routing loops. Daily operations around the world highly depend on the availability and reliability of the Internet, which makes the security of this infrastructure a top priority issue in the field.

Network Infrastructure Security is a book that bridges the gap between the study of the traffic flow of networks and the study of the actual network configuration. This book makes effective use of examples and figures to illustrate network infrastructure attacks from a theoretical point of view. The book includes conceptual examples that show how network attacks can be run, along with appropriate countermeasures and solutions.

About the authors

Angus Kin-Yeung Wong obtained his BSc and PhD degrees from City University of Hong Kong and is currently an associate professor at Macao Polytechnic Institute. Alan Kai-Hau Yeung obtained his BSc and PhD degrees from the Chinese University of Hong Kong and is currently an associate professor at City University of Hong Kong. Wong and Yeung have been collaborating in network-related research for over 10 years.




Download this book!

Free Ebooks Download

Tuesday, January 25, 2011

Testing Web Security: Assessing the Security of Web Sites and Applications



Testing Web Security: Assessing the Security of Web Sites and Applications
| 2001-02-01 00:00:00 | | 0 | Network Security


* Covers security basics and guides reader through the process of testing a Web site.
* Explains how to analyze results and design specialized follow-up tests that focus on potential security gaps.
* Teaches the process of discovery, scanning, analyzing, verifying results of specialized tests, and fixing vulnerabilities.

User review
Adds the auditing dimension to web testing
This book is unique in that it focuses more on auditing than on actual web testing techniques, which is an area that is too often overlooked by QA. Because of this niche area, this book can be used in conjunction with any of the more testing-centric books, giving QA a solid security-in-depth approach. This approach also makes this book a solid reference for complying with parts of the Sarbanes-Oxley Act.

Splaine thoroughly covers the test/audit process by addressing all layers and threat vectors. He takes a systematic vulnerability assessment and risk management approach, and extensively uses checklists throughout this book to help you to develop a security auditing process that will close most of the vulnerability gaps, as well as to augment other testing approaches.

I particularly like the completeness of topic coverage - he goes into network, protocol, client- and server-side application, and attack modes in great detail. For each area he provides advice, checklists and a strategy for dealing with the risks and vulnerabilities represented. I also like the way he addresses configuration management, quality and test case design. These reflect best practices and can be quickly integrated into a web security QA function.

Splaine's earlier book, `The Web Testing Handbook` (ISBN 0970436300) nicely augments this one, as does Nguyen's highly regarded `Testing Applications on the Web: Test Planning for Internet-Based Systems` (ISBN 047139470X), both of which are more focused on web testing.

If you work in QA or web security this book will be an invaluable resource, and is one that I highly recommend because it spans both disciplines.

User review
An Excellent Read & Reference for Testers and Test Managers
Before I read Steve's book, I thought that testing the security of a Web site required huge amounts of technical knowledge including how certain operating systems, web servers, etc., actually worked. Having read the book, I realise that someone needs to know - but it needn't be me. As a tester, my job is to see if the security measures that have been put into place actually do what they are supposed to and in this context the book exceeds my requirements and expectations.

In addition, one of the problems in testing security is trying to ensure that the site does not open itself up to any unauthorised activity - accidental or not. How do you ensure `complete coverage' of the virtually infinite number of event combinations and therefore test cases? This problem is addressed in the Test Planning and Risk Analysis sections and placed properly and pragmatically into context.

Then we get into the meat of test design. I like the way we start with scoping. What are we trying to secure and from what or whom? To answer the latter part of the question, the book delves into types of attacks - which then helps us to think about what and how to test. I particularly like the checklists (OK, I'm a checklist fan) and the lists of software tools which are available to carry out things like IP address sweeps, port scans, etc.

This part of the book has separate chapters for networks, system software, client and server-side application software. Each chapter is virtually stand-alone which makes it a good reference as well as a good read. I also like the fact that Steve has not left out the social engineering aspect of security. Finally, Test Implementation addresses the usual practical problems associated with test execution but with all the emphasis on security.

Steve Splaine has distilled into one book enough information to give testers and test managers confidence in the planning, design and execution of Web security testing. An excellent read and reference.

User review
A Great General Overview of Testing Web Security
The author's goal is to make managers responsible for Web site security aware that having a super-duper firewall doesn't excuse the organization from conducting tests or exploring additional avenues to supplement the firewall.

The book also supports security testers with flexible descriptions and checklists for creating test cases and conducting tests. Each chapter ends with a checklist covering the various aspects of the test process from planning to intrusion detection. Organizations with a process model in place such as CMM (Capability Maturity Model), RUP (Rational Unified Process), and Six Sigma will find the material supportive of such efforts and maybe even making it easier because of the lists of example tools and software products for managing reporting and schedules.

The book isn't a read front-to-back book as each chapter is understandable with or without previous chapters. The first two chapters address vocabulary, test plans and planning, and general project management activities. The meat of the book is in Part 3, Test Design, beginning with chapter 3, which addresses scoping and conducting a network assessment. Chapter 4 focuses on system software and related tools.

The next two chapters look at client-side and server-side applications to ensure the system is designed to function correctly for its users while guarding its castle to prevent the evil ones from breaking in. Mother Nature might pay a visit or another big blackout could happen and those guards need to be prepared to react, hence Chapter 7 prepares a team for such events as well as various ways the bad guys might do a sneak attack.

Mysterious intruders and audit trails sounds like a case for Sherlock Holmes as Chapter 8 directions on detecting unauthorized intruders, responding to an attack, and assessing the damage.

Those who haven't formed a team might want to leap into Chapter 9, which provides staffing options for in-house and outsourcing. It also discusses the process of selecting tools. In the last chapter, get the lowdown on doing a risk analysis to be prepared in for the likelihood of changed plans (which we know happens often). Doing such an analysis is a step toward to having a well-planned test schedule ensure the areas that pose the greatest risks are done early in the process while the lesser important items are done near the end of the test period.

The appendices provide an overview of network protocols, addresses, and devices; a list of the most critical Internet security vulnerabilities; and example templates for testing documentation. Those who need more in-depth information can reference the resources for further reading via books and Web sites.

If the thought of security is daunting, this book is a good introduction to the topic. It's appropriate for organizations creating a new testing team; teams responsible for conducting testing assessments; and testing managers, project managers, and test teams that are new to testing security. Directors, executives, and other top level managers who are responsible for Web site security will also benefit.

Any technical terms that pop up are clearly defined without the dull writing that makes eyes glaze over when reading a technical book. The use of sidebars, checklists, headers, examples, and figures provide a nice balance in presenting the material without losing the reader. The book is practical for anyone who needs a general reference on Web security and wants to know how it works.

As for the programming issue another reviewer mention, it's true there isn't reference to programming languages. However, that's not the point of this particular book.

User review
Simply the worst security book I have ever read
This book proposes to teach us about testing web application security. OK, there *is* one entire sentence devoted to PHP, and somewhere in this mess I think that I remember seeing several lines regarding jsp. On the plus side -- there is an Appendix devoted to a cursory review of the SANS top 20 security vulnerabilities. Thank goodness -- googling for this list or finding it online at the SANS portal must be outside the abilities of the reviewers who gave this book positive reviews.

Testing w/ client-side proxies, as far as I can tell, is not covered; nor is any mention made of SQL insertion techniques, basic authentication mechanism testing, Nikto usage, etc.

I purchased this book based upon the initial reviews on this site. Obviously, the earlier reviewers were not reading the same book as the one I received.

User review
Smart and Resourceful
Interestingly, this is one of the very few commercial guides on testing anything out there that actually provides a test plan and specific tests to perform. It smartly provides straight facts on web security without trying to oversell anything which is why I particularly recommend it.

Another point of the book I found helpful and intelligent is the layout which did more than just take one through a step-by-step assessment.

Although not overly technical, for instance you won't find specific programming tips on PHP or JSP, its broad coverage of the web presence from physical to Internet is more than enough to provide any organization with a proper risk assessment.

I have written the author about a few improvements I would like to see but there is nothing that would detract from the knowledge transfer this book currently offers. It is an excellent complement to the OSSTMM (Open Source Security Testing Methodology Manual) at [email address]and will assist you in making an OSSTMM certified test as well meeting BS7799 best practice requirements. If you worry about privacy legislation in your region then this may just be the help you are looking for in your web presence.


Download this book!

Free Ebooks Download

Monday, January 10, 2011

Wireless Security Essentials: Defending Mobile Systems from Data Piracy



Wireless Security Essentials: Defending Mobile Systems from Data Piracy
| 2002-07-15 00:00:00 | | 0 | Network Security


As wireless device usage increases worldwide, so does the potential for malicious code attacks. In this timely book, a leading national authority on wireless security describes security risks inherent in current wireless technologies and standards, and schools readers in proven security measures they can take to minimize the chance of attacks to their systems. Russell Dean Vines is the coauthor of the bestselling security certification title, The CISSP Prep Guide (0-471-41356-9) Book focuses on identifying and minimizing vulnerabilities by implementing proven security methodologies, and provides readers with a solid working knowledge of wireless technology and Internet-connected mobile devices

User review
Useful when it counted.
The title may lead you to believe that only wireless security is addressed but this book is a complete source of security information and reference material that is useful for any computer user.

It provides detailed information on security standards and policies. Both for the wireless and connected environments. There is also specific information for the products of major vendors.

The true test of whether or not a technical book is useful is whether or not you can apply the information provided to the real world. After finding an unknown machine attached to my wireless network one day I was glad I had this book handy. It proved an invaluable asset in locking down our system and accessing any damage.

highly recommended for anyone interested in security. Wireless or not.

User review
Another Winner
If you think the only thing you need to do to ensure wireless security is not leaving your cell phone lying around, you should check this book out. I went right to this book, mostly because of the author, and it did not disappoint. His CISSP Prep Guide is also an amazing book.

User review
Good book, but doesn?t have much about wireless security
Writing a book on wireless security is like writing a book on safe skydiving - if you want the safety and security, just don't do it. Hard-wired (cabled) networks have been around for decades and they are still for the most part insecure. Wireless networking (focusing on 802.11), which has been around for only a few years, is clearly an insecure technology. With that, there is currently not a lot to write about when it comes to effective wireless security.

Wireless Security Essentials: Defending Mobile Systems from Data Piracy confirms that there is little to say on this topic because although it is 345 pages in length, only about 75 pages deal with wireless security. Of those 75 pages (pages 135 - 207), about 15 pages discuss vendor products.

The first 135 pages and 4 chapters of the book are an introduction to computer technology, networking, wireless security, and basic security issues. In addition to the 75 pages on wireless security, pages 209 - 345 are composed of a comprehensive glossary and 4 appendixes.

Only in chapter 5 does the book get into ` wireless security`. For the most part, people equate wireless with 802.11. Within 802.11, the security functionality is provided by WEP (Wired Equivalent Privacy), which provides the underlying security of 802.11. But an insurmountable problem is that WEP has been proven (see Breaking 802.11 Security at [URL]) to be seriously flawed, and is therefore insecure. Since the security foundation of 802.11 is basically nil, 802.11 networks as of this writing simply can't be adequately secured.

So why do companies deploy wireless networks given their inherent security risks? For the same reason they deploy Windows -- functionality. While Windows is for the most part an insecure operating system, its functionality is huge, and history has shown that functionality wins over security.

The functionality of wireless has even given birth to a new pastime of war chalking. War chalking is when an area of public access has been determined to have a wireless access point available, it is marked with chalk to let everyone know. For more information on war chalking, see [URL]

While the book does have valuable information, the fact that only 75 pages of it are specific to wireless security may not warrant its [price] purchase price. There are numerous free articles on the Internet that provide roughly the same amount of information and may be more cost effective to most readers. One place to start is The Unofficial 802.11 Security Web Page at [URL]/ and also 802.11 Security Beyond WEP at [URL].

User review
Good for professionals and the home user
I found that this book was informative in explaining the different wireless protocols out there. It also explained some of the weaknesses, which helped me not only to set up my own wireless lan at home, but make recommendations in my office towards a more private network!

I recommend this book for anyone who needs to know about security with today's devices.

User review
Two Thumbs Up!
Two thumbs up! In depth coverage, but easy to read. The fifteen pages of references gives an indication of the extent of research backing this book, not to mention the author's extensive background in computer security. I like the fact that each chapter stands on it's own - You can dive in wherever you like and sink your teeth into it. The well thought-out formatting and illustrations make it a breeze to navigate. Whether you're looking for a guide to wireless security, or for a reference book on the alphabet soup of protocols and standards, this book is the answer!


Download this book!

Free Ebooks Download