HNS Newsletter Issue 232 - 27.09.2004

Total Page:16

File Type:pdf, Size:1020Kb

HNS Newsletter Issue 232 - 27.09.2004 HNS Newsletter Issue 232 - 27.09.2004. http://net-security.org This is a newsletter delivered to you by Help Net Security. It covers weekly roundups of security events that were in the news the past week. --------------------------------------------------------------------------------------------- IBMSecure World Technical University - November 23-26 - Berlin Do you know how effectively you can protect your IT infrastructure? --------------------------------------------------------------------------------------------- Security has become a very important concern in today’s wireless and network computing business. This conference offers 70 sesions organised around 5 main topics: Security Risk Management, Physical & Logical Security Integration and Recovery, Security Architectures & Solutions, Security Management and Control. In addition, you will also have the possibility to take part to a Technology Solutions Forum, during which IBM and its Partners will demonstrate their latest security solutions. Find out more on http://www.ibm.com/services/learning/conf/europe/securew --------------------------------------------------------------------------------------------- Table of contents: 1) Security news 2) Vulnerabilities 3) Advisories 4) Reviews 5) Software 6) Webcasts 7) Conferences 8) Security World [ Security news ] ---------------------------------------------------------------- A VISUAL HISTORY OF SPAM AND VIRUS EMAILS Raymond chen, a Microsoft employee has kept every single piece of spam since mid-1997. The results were then put into a graph to show a visual representation of spam and viruses received for the last 6 years. http://www.net-security.org/news.php?id=6101 NET SECURITY THREATS GROWING FAST More than 30,000 PCs per day are being recruited into secret networks that spread spam and viruses, a study shows. http://www.net-security.org/news.php?id=6102 A FEAST OF ANTI-SPAM The proliferation of anti-spam offerings has left many businesses bewildered. Which products should they choose? http://www.net-security.org/news.php?id=6103 ARREST MADE IN CISCO SOURCE CODE THEFT Police in the UK have arrested a man in connection with the theft of source code from networking equipment maker Cisco Systems in May, a Scotland Yard spokeswoman confirmed on Friday. http://www.net-security.org/news.php?id=6104 MICROSOFT TRIALS PIRACY LOCK ON DOWNLOAD CENTER New feature locks out pirated copies of Windows. http://www.net-security.org/news.php?id=6105 VMWARE - SECURE ACCESS GOES VIRTUAL VMware offers a new option for controlling access to corporate systems. http://www.net-security.org/news.php?id=6106 4 TIPS FOR A STRONG DEFENSE Agency efforts to tighten system security have evolved in recent months from documenting weaknesses to deploying security safeguards, said experts familiar with federal programs. http://www.net-security.org/news.php?id=6107 FTC BACKS SPAMMER BOUNTIES (FALSE) A program to encourage members of the public to become "bounty hunters" tracking down email spammers received the luke warm backing of the US Federal Trade Commission (FTC). http://www.net-security.org/news.php?id=6108 HACKERS DEPLOYING 'BOTS' ON A MASSIVE SCALE Symantec reports up to 75,000 PCs being compromised daily. http://www.net-security.org/news.php?id=6109 GARTNER: INFORMATION SECURITY IS STILL KEY Despite claims from some quarters that security will cease to be a key issue over the next few years, Gartner stressed today that information security will remain a major executive concern for the foreseeable future. http://www.net-security.org/news.php?id=6112 ORACLE SECURITY PATCHES CAUSING HEADACHES Oracle Corp. released a batch of security patches earlier this month, addressing dozens of vulnerabilities discovered this year. With limited information on each patch, DBAs are being forced to take entire systems out of production. http://www.net-security.org/news.php?id=6113 MICROSOFT-CISCO SECURITY FIGHT HURTS US ALL Microsoft and Cisco pachyderms are fighting over network security standards, and the losers, once again, are the folks on the ground. http://www.net-security.org/news.php?id=6114 SASSER AUTHOR GETS IT SECURITY JOB Securepoint technical director Lutz Hausmann says the teenager deserved a second chance. http://www.net-security.org/news.php?id=6115 AVOID SECURITY TOOLS YOU DON'T NEED Many technologies may be a waste of time and money, researcher says. http://www.net-security.org/news.php?id=6116 CAN ALL-IN-ONE SECURITY APPLIANCES SECURE THE NETWORK? Some might do the job, but consultants recommend a layered security approach. http://www.net-security.org/news.php?id=6117 HACKERS COSTING ENTERPRISES BILLIONS Hackers continued adding billions to the cost of doing business on the Internet in the first half of 2004, despite security executives' efforts to prevent malicious attacks. http://www.net-security.org/news.php?id=6118 NMAP EXAMINATION OF VARIOUS OPERATING SYSTEMS The purpose of this short comparison is to perform some sort of evaluation of the quality of the TCP/IP stack which is implemented differently in various Operating Systems. http://www.net-security.org/news.php?id=6119 SECURE ID TAGS AT AOL Internet provider introduces new service to put a 'dead bolt' on accounts. http://www.net-security.org/news.php?id=6120 THE BUILDING BLOCKS OF A CUSTOMIZED SECURITY SERVICE New IP VPN services can be customized to fit specific user needs, speeding time-to-market without investing in dedicated hardware or applications. http://www.net-security.org/news.php?id=6121 I/O DEVICES ARE TRUSTED WITH PC SECURITY Two new SafeKeeper Trusted Input/Output (I/O) devices are designed to embed security into desktop and notebook computer motherboards. http://www.net-security.org/news.php?id=6122 OFFSHORE SECURITY CAN BE COMPROMISED BY CULTURAL DIFFERENCES Gartner has warned companies that outsource to countries like India and China not to overlook the impact of cultural differences on security. http://www.net-security.org/news.php?id=6123 SECURITY FEARS STILL BLOCKING WLAN ADOPTION Despite the best efforts of the Wi-Fi industry to assure companies wireless networking is safe in the workplace, a new survey of executives finds security remains the leading barrier to WLAN adoption. http://www.net-security.org/news.php?id=6124 BACKING UP YOUR LINUX DESKTOP WITH RSYNC This article explain how to use rsync to backup your computer to a drive attached to your system. http://www.net-security.org/news.php?id=6125 UNCLE SAM DEMANDS ALL AIR TRAVEL RECORDS The US Transportation Security Administration (TSA) has demanded the passenger records of all domestic flights during the month of June, 2004, so that it can test its new "CAPPS Lite" data mining operation before putting it into production, the Associated Press reports. http://www.net-security.org/news.php?id=6126 ACTIVISTS FIND MORE E-VOTE FLAWS More weaknesses appear in the Diebold electronic voting system that activists say could be used to rig the November election. The company says auditing procedures would catch any vote fraud. http://www.net-security.org/news.php?id=6127 THERE'S 100,000 OF THEM... AND THEY'RE AFTER YOU As a new study reveals that the number of malicious computer programs has reached the 100,000 mark for the first time, Adrian Mather looks at the dangers facing us in our own homes and what we can do to ward off an attack. http://www.net-security.org/news.php?id=6128 THE SPY THREAT FROM THE INTERNET Browsing the web can let unwanted visitors into your system - and simple anti-virus software can't catch them. http://www.net-security.org/news.php?id=6129 INFORMATION SECURITY FAILS TO REACH THE BOARDROOM Global security survey shows need for greater awareness still an issue. http://www.net-security.org/news.php?id=6130 DHS EXPANDS BIOMETRIC USE Biometric programs should be expanded to fight terrorism and crime, a Homeland Security Department official said. http://www.net-security.org/news.php?id=6131 EXPLOIT POSTED FOR MICROSOFT JPEG FLAW Customers are urged to install software updates. http://www.net-security.org/news.php?id=6132 HACKERS HIT CREDIT CARD COMPANY DDoS attack on e-commerce service provider is preceded by an extortion note. http://www.net-security.org/news.php?id=6133 BILL WOULD NARROW INTRUDER SURVEILLANCE Senate proposal would scale back a provision of the USA Patriot Act that lets the FBI monitor alleged computer trespassers without a warrant http://www.net-security.org/news.php?id=6134 4 MUST-HAVE SECURITY SOLUTIONS Vulnerability and automated patch management top the list. http://www.net-security.org/news.php?id=6135 IRELAND CRACKS DOWN ON NET SCAMS Calls to 13 other countries will be blocked to thwart auto-dialer software. http://www.net-security.org/news.php?id=6136 P-CUBE GOES HUNTING FOR ZOMBIE PCS P-Cube, the traffic management firm Cisco agreed to buy for $200m last month, is aiming to tackle the problem of spam at source by detecting and quarantining spam zombie machines. http://www.net-security.org/news.php?id=6137 FIRM JUSTIFIES JOB FOR VIRUS WRITER A German computer security firm has defended its decision to hire the self-confessed teenage author of the Sasser and Netsky worms. http://www.net-security.org/news.php?id=6138 NOKIA BREAKS INTO HOME SECURITY MARKET Wireless home monitoring device controlled by text message. http://www.net-security.org/news.php?id=6139 ARE FIREWALLS USEFUL? AND ANOTHER THING... Address spoofing depends crucially on being able to hide the real source address, so why not make that impossible? One way to do it would be to have all the ISPs and network carriers whose connections constitute the Internet certify where packets entering the network come from. http://www.net-security.org/news.php?id=6140 FRENCH DEFENSE MINISTRY COMMISSIONS HIGH-SECURITY LINUX The French Ministry of Defense has awarded an $8.6 million, three-year contract to a consortium of companies, including Linux vendor Mandrakesoft, to develop a highly secure Linux operating system.
Recommended publications
  • Instalación Y Configuración De Cortafuegos
    Tema 4. Seguridad y alta disponibilidad Instalación y configuración de cortafuegos Raquel Castellanos Crespo Instalación y configuración de cortafuegos Seguridad y alta disponibilidad Raquel Castellanos Crespo INDICE Cortafuegos - Concepto. Utilización de cortafuegos - Historia de los cortafuegos - Funciones principales de un cortafuegos: Filtrado de paquetes de datos, filtrado por aplicación, reglas de filtrado y registros de sucesos de un cortafuegos - Listas de control de acceso (ACL) - Ventajas y limitaciones de los cortafuegos - Políticas de cortafuegos - Tipos de cortafuegos: Clasificación por ubicación y por tecnología - Arquitecturas de cortafuegos - Pruebas de funcionamiento. Sondeos Cortafuegos software y hardware - Cortafuegos software integrados en los sistemas operativos - Cortafuegos software libres y propietarios - Distribuciones libres para implementar cortafuegos en maquinas dedicadas - Cortafuegos hardware. Gestión unificada de amenazas “Firewall UTM” (Unified Threat Management) 2 Tema 4. Seguridad y alta disponibilidad | Raquel Castellanos Crespo Instalación y configuración de cortafuegos Seguridad y alta disponibilidad Raquel Castellanos Crespo Concepto y utilización de cortafuegos Un cortafuegos (firewall en inglés) es una parte de un sistema o una red que está diseñada para bloquear el acceso no autorizado, permitiendo al mismo tiempo comunicaciones autorizadas. Se trata de un dispositivo o conjunto de dispositivos configurados para permitir, limitar, cifrar, descifrar, el tráfico entre los diferentes ámbitos sobre la base de un conjunto de normas y otros criterios. Los cortafuegos pueden ser implementados en hardware o software, o una combinación de ambos. Los cortafuegos se utilizan con frecuencia para evitar que los usuarios de Internet no autorizados tengan acceso a redes privadas conectadas a Internet, especialmente intranets. Todos los mensajes que entren o salgan de la intranet pasan a través del cortafuegos, que examina cada mensaje y bloquea aquellos que no cumplen los criterios de seguridad especificados.
    [Show full text]
  • SEGURIDAD Y ALTA DISPONIBILIDAD En Este Libro Se Abarcara La Asignatura De Servicios De Red E Internet Del Grado Superior De Informática
    SEGURIDAD Y ALTA DISPONIBILIDAD En este libro se abarcara la asignatura de servicios de red e internet del grado superior de informática. Escrito por: Nicolás Madrid Gallego Nicolás Madrid Gallego IES GREGORIO PRIETO CORTAFUEGOS SEGURIDAD Y ALTA DISPONIBILIDAD CORTAFUEGOS 2 SEGURIDAD Y ALTA DISPONIBILIDAD CORTAFUEGOS Contenido 1.- Concepto . Utilización de cortafuegos. ........................................................................... 3 2.-Historia de los cortafuegos ............................................................................................... 4 Primera generación – cortafuegos de red: filtrado de paquetes ................................ 5 Segunda generación – cortafuegos de estado ............................................................ 5 Tercera generación - cortafuegos de aplicación.......................................................... 6 Acontecimientos posteriores ......................................................................................... 6 1.3.-Funciones principales de un cortafuegos: Filtrado de paquetes de datos, filtrado por aplicación, Reglas de filtrado y registros de sucesos de un cortafuegos ................... 7 Filtrado de paquetes .............................................................................................................. 7 1.4.-Listas de control de acceso (ACL) .............................................................................. 10 1.5.-Ventajas y Limitaciones de los cortafuegos ..............................................................
    [Show full text]
  • Catalogueformationspythagorefd 2017.Pdf
    p.1 Pythagore F.D. : Apprendre à Apprendre Nouveautés 2017 : Pour plonger au coeur des technologies BigData, comprendre les concepts de NoSQL, d'indexation, de sharding, etc ... savoir concevoir les architecture ad-hoc et intégrer, déployer les solutions, nous proposons une gamme complète de formations, ateliers, classes virtuelles qui vont de l'introduction avec des stages comme « BigData, architecture et technologies », jusqu'à l'expertise sur des sujets comme la « Programmation R pour hadoop », ou le stage « Machine Learning : technologies et bonnes pratiques ». Nos domaines d'expertise : • Unix et Linux, et les applicatifs Apache, Openldap, Squid, Nagios, Zabbix, OCS/GLPI, puppet , chef... • la virtualisation et l'orchestration avec xen, kvm, lxc, Docker, et le cloud : cloudstack et openstack, openNebula, Cloudify, cobbler, etc ... • TCP/IP (IPv6, snmp, Architecture, Sécurité, Administration de réseaux IP, VoIP, ...) • Développement (langage C, Java, Jee, technologies Jee, JBoss, WebServices, PHP, Perl, Python , ...) et le développement sur mobiles android • les bases de données et le BigData avec NoSQL, Cassandra, MongoDB, Hadoop, ... Sur chacun de ces domaines, notre équipe possède un excellent niveau d'expertise couvrant l'ensemble du domaine, des fondamentaux aux outils les plus complexes : nos formations vont de l'introduction à Linux, à la Sécurité, la Haute Disponibilité, des concepts NoSQL à la programmation MapReduce Tous nos stages sont l'occasion de nombreuses mises en pratique et exercices de manière à permettre aux participants de bien assimiler les nouveaux concepts. Nos méthodes pédagogiques : Apprendre, concevoir, intégrer ... nous pensons que le meilleur moyen de comprendre les nouveaux concepts et les technologies est la mise en pratique. Nous organisons des ateliers, expériences, démonstrations, ..
    [Show full text]
  • Architecture of a Identity Based Firewall System
    ARCHITECTURE OF A IDENTITY BASED FIREWALL SYSTEM Nenad Stojanovski1 and Marjan Gušev2 1 Makedonski Telekom AD, Orce Nikolov BB, 1000 Skopje, Macedonia [email protected] 2 Faculty of Natural Sciences and Mathematics, Ss. Cyril and Methodius University, Arhimedova b.b., PO Box 162, 1000 Skopje, Macedonia [email protected] ABSTRACT Classic firewall systems are built to filter traffic based on IP addresses, source and destination ports and protocol types. The modern networks have grown to a level where the possibility for users’ mobility is a must. In such networks, modern firewalls may introduce such complexity where administration can become very frustrating since it needs the intervention of a firewall administrator. The solution for this problem is an identity based firewall system. In this paper we will present a new design of a firewall system that uses the user’s identity to filter the traffic. In the design phase we will define key points which have to be satisfied as a crucial milestone for the functioning of the whole Identity based firewall system. KEYWORDS Identity based firewalls, user identity, firewalls, network security, computer networks, firewall systems design 1. INTRODUCTION Classic firewall systems are built to filter traffic based on source and destination IP addresses, source and destination ports and protocol types[11]. As Information technology moves forward and advances, classic firewalls start to become very robust and unusable when it comes to the transparent user experience. The main problem that arises from using classic firewalls in a modern dynamic environment is that users have to be mobile and have access to their resources.
    [Show full text]
  • Cortafuegos Y Seguridad En El Internet”
    INSTITUTO POLITÉCNICO NACIONAL ESCUELA SUPERIOR DE INGENIERÍA MECÁNICA Y ELÉCTRICA UNIDADAD CULHUACAN TESIS “CORTAFUEGOS Y SEGURIDAD EN EL INTERNET” Que como prueba escrita de su examen profesional para obtener el Título de: Ingeniero en Comunicaciones y Electrónica Presenta: EDGAR VICENTE JIMÉNEZ ÁVILA Asesores Ing. Gustavo Mendoza Campeche Lic. Martha Guadalupe Hernández Cuellar México D.F FEBRERO 2014. A mi padre Que gracias a su apoyo moral y económico me ha apoyado para la culminación de mis estudios y al mismo tiempo a la realización de esta obra, y que gracias a sus consejos me han ayudado a ser una mejor persona. Gracias papá TE AMO. A mi madre Gracias al amor y cariño que me has brindado, a los consejos para superarme día a día, al apoyo económico y moral para concluir mis estudios y de esta manera ser un profesionista y servir a la sociedad. A mis hermanas Gracias madrecita. TE AMO. Que gracias al apoyo moral, ánimos, cariño y consejos brindados que me han servido para poder concluir satisfactoriamente mis estudios. Gracias Fabiola, Cindy, Miriam. A toda mi familia Especialmente a mi abuelita Teresa, mi tío Fredy Macario, mi abuelito Macario, mi abuelita Costa, mi tía Marlene, mi tío Alberto, que me han enseñado que la A Yanel dedicación es sinónimo de triunfó. Gracias Gracias a tus consejos, a tus ánimos para no darme por vencido tan fácilmente y todo el cariño que me has brindado, que día con día me hacen ser una persona de bien para la sociedad, gracias por estar a mi lado en los momentos de alegría y de tristeza.
    [Show full text]
  • Pipenightdreams Osgcal-Doc Mumudvb Mpg123-Alsa Tbb
    pipenightdreams osgcal-doc mumudvb mpg123-alsa tbb-examples libgammu4-dbg gcc-4.1-doc snort-rules-default davical cutmp3 libevolution5.0-cil aspell-am python-gobject-doc openoffice.org-l10n-mn libc6-xen xserver-xorg trophy-data t38modem pioneers-console libnb-platform10-java libgtkglext1-ruby libboost-wave1.39-dev drgenius bfbtester libchromexvmcpro1 isdnutils-xtools ubuntuone-client openoffice.org2-math openoffice.org-l10n-lt lsb-cxx-ia32 kdeartwork-emoticons-kde4 wmpuzzle trafshow python-plplot lx-gdb link-monitor-applet libscm-dev liblog-agent-logger-perl libccrtp-doc libclass-throwable-perl kde-i18n-csb jack-jconv hamradio-menus coinor-libvol-doc msx-emulator bitbake nabi language-pack-gnome-zh libpaperg popularity-contest xracer-tools xfont-nexus opendrim-lmp-baseserver libvorbisfile-ruby liblinebreak-doc libgfcui-2.0-0c2a-dbg libblacs-mpi-dev dict-freedict-spa-eng blender-ogrexml aspell-da x11-apps openoffice.org-l10n-lv openoffice.org-l10n-nl pnmtopng libodbcinstq1 libhsqldb-java-doc libmono-addins-gui0.2-cil sg3-utils linux-backports-modules-alsa-2.6.31-19-generic yorick-yeti-gsl python-pymssql plasma-widget-cpuload mcpp gpsim-lcd cl-csv libhtml-clean-perl asterisk-dbg apt-dater-dbg libgnome-mag1-dev language-pack-gnome-yo python-crypto svn-autoreleasedeb sugar-terminal-activity mii-diag maria-doc libplexus-component-api-java-doc libhugs-hgl-bundled libchipcard-libgwenhywfar47-plugins libghc6-random-dev freefem3d ezmlm cakephp-scripts aspell-ar ara-byte not+sparc openoffice.org-l10n-nn linux-backports-modules-karmic-generic-pae
    [Show full text]
  • Index Images Download 2006 News Crack Serial Warez Full 12 Contact
    index images download 2006 news crack serial warez full 12 contact about search spacer privacy 11 logo blog new 10 cgi-bin faq rss home img default 2005 products sitemap archives 1 09 links 01 08 06 2 07 login articles support 05 keygen article 04 03 help events archive 02 register en forum software downloads 3 security 13 category 4 content 14 main 15 press media templates services icons resources info profile 16 2004 18 docs contactus files features html 20 21 5 22 page 6 misc 19 partners 24 terms 2007 23 17 i 27 top 26 9 legal 30 banners xml 29 28 7 tools projects 25 0 user feed themes linux forums jobs business 8 video email books banner reviews view graphics research feedback pdf print ads modules 2003 company blank pub games copyright common site comments people aboutus product sports logos buttons english story image uploads 31 subscribe blogs atom gallery newsletter stats careers music pages publications technology calendar stories photos papers community data history arrow submit www s web library wiki header education go internet b in advertise spam a nav mail users Images members topics disclaimer store clear feeds c awards 2002 Default general pics dir signup solutions map News public doc de weblog index2 shop contacts fr homepage travel button pixel list viewtopic documents overview tips adclick contact_us movies wp-content catalog us p staff hardware wireless global screenshots apps online version directory mobile other advertising tech welcome admin t policy faqs link 2001 training releases space member static join health
    [Show full text]
  • Dynamic and Application-Aware Provisioning of Chained Virtual Security Network Functions
    This is the author’s version of an article that has been published in IEEE Transactions on Network and Service Management. Changes were made to this version by the publisher prior to publication. The final version of record is available at https://doi.org/10.1109/TNSM.2019.2941128. The source code associated with this project is available at https://github.com/doriguzzi/pess-security. Dynamic and Application-Aware Provisioning of Chained Virtual Security Network Functions Roberto Doriguzzi-Corinα, Sandra Scott-Haywardβ, Domenico Siracusaα, Marco Saviα, Elio Salvadoriα αCREATE-NET, Fondazione Bruno Kessler - Italy β CSIT, Queen’s University Belfast - Northern Ireland Abstract—A promising area of application for Network Func- connected to the network through an automated and logically tion Virtualization is in network security, where chains of Virtual centralized management system. Security Network Functions (VSNFs), i.e., security-specific virtual functions such as firewalls or Intrusion Prevention Systems, The centralized management system, called NFV Manage- can be dynamically created and configured to inspect, filter ment and Orchestration (NFV MANO), controls the whole or monitor the network traffic. However, the traffic handled life-cycle of each VNF. In addition, the NFV MANO can by VSNFs could be sensitive to specific network requirements, dynamically provision complex network services in the form such as minimum bandwidth or maximum end-to-end latency. of sequences (often called chains) of VNFs. Indeed, Network Therefore, the decision on which VSNFs should apply for a given application, where to place them and how to connect them, Service Chaining (NSC) is a technique for selecting subsets should take such requirements into consideration.
    [Show full text]
  • Suricata 2.0, Netfilter and The
    Suricata 2.0, Netfilter and the PRC Éric Leblond Stamus Networks April 26, 2014 Éric Leblond (Stamus Networks) Suricata 2.0, Netfilter and the PRC April 26, 2014 1 / 52 Eric Leblond a.k.a Regit French Network security expert Free Software enthousiast NuFW project creator (Now ufwi), EdenWall co-founder Netfilter developer: Maintainer of ulogd2: Netfilter logging daemon Misc contributions: NFQUEUE library and associates Port of some features iptables to nftables Currently: co-founder of Stamus Networks, a company providing Suricata based network probe appliances. Suricata IDS/IPS funded developer Éric Leblond (Stamus Networks) Suricata 2.0, Netfilter and the PRC April 26, 2014 2 / 52 What is Suricata IDS and IPS engine Get it here: http://www.suricata-ids.org Open Source (GPLv2) Funded by US government and consortium members Run by Open Information Security Foundation (OISF) More information about OISF at http://www. openinfosecfoundation.org/ Éric Leblond (Stamus Networks) Suricata 2.0, Netfilter and the PRC April 26, 2014 5 / 52 Suricata Features High performance, scalable through multi threading Protocol identification File identification, extraction, on the fly MD5 calculation TLS handshake analysis, detect/prevent things like Diginotar Hardware acceleration support: Endace Napatech, CUDA PF_RING Éric Leblond (Stamus Networks) Suricata 2.0, Netfilter and the PRC April 26, 2014 6 / 52 Suricata Features Rules and outputs compatible to Snort syntax useful logging like HTTP request log, TLS certificate log, DNS logging Lua scripting for detection Éric Leblond (Stamus Networks) Suricata 2.0, Netfilter and the PRC April 26, 2014 7 / 52 Suricata capture modes IDS pcap: multi OS capture pf_ring: Linux high performance af_packet: Linux high performance on vanilla kernel ..
    [Show full text]
  • Catalogue Des Formations 2011 Plans De Cours Et Calendrier
    Catalogue des formations 2011 Plans de cours et calendrier Pythagore F.D. 11, rue du Faubourg Poissonnière 75009 PARIS Tél : 01 55 33 52 10 – Télécopie : 01 55 33 52 11 – Site : www.pythagore-fd.fr (c) Pythagore F.D. 2011 p.1 Pythagore F.D. : Apprendre à Apprendre La nouveauté : nos classes virtuelles ! Vous connaissez déjà le principe des classes virtuelles : les participants et le formateur se retrouvent au travers d'internet pour une session de formation « synchrone ». A la différence des outils d'auto-formation en e-learning, les classes virtuelles permettent l'interactivité entre les participants et le formateur. L'innovation apportée par notre solution est la fourniture d'un environnement de travaux pratiques comme dans un véritable centre de formation : chaque participant dispose d'un poste distant sur lequel il peut réaliser les exercices et travaux pratiques. Le formateur peut également se connecter sur le poste, y effectuer des corrections, ou y déposer des fichiers, etc ... Qu'il s'agisse de programmation en java, d'administration de cluster JBoss, de serveurs linux, tous les travaux pratiques sont réalisés sur les postes distants, qui peuvent être reconfigurés, réinstallés à volonté, comme dans une vraie salle de formation. Cette solution, parfaitement adaptée aux formations techniques permet, par exemple, d'organiser des sessions multi-sites pour des entreprises ou organisations dont le personnel est réparti géographiquement sur plusieurs sites. Les participants à ces stages sont très heureux de pouvoir bénéficier des avantages des formations en centre, tout en évitant les déplacements. N'hésitez pas à nous contacter pour organiser vos propres sessions ! Nos domaines d'expertise technique : Nos grands classiques : • Java, serveurs d'applications J2EE (Jboss, Websphere, Jonas, ) • TCP/IP (Architecture, Sécurité, Administration de réseaux IP, VoIP, ...) • Unix (AIX, HP-UX, Solaris), • Linux, les aspects systèmes, la virtualisation (xen, kvm), les applicatifs Apache, Openldap, Squid, Nagios, glpi, OpenOffice, ..
    [Show full text]
  • 2013 Kernel Recipes Nftables
    nftables, far more than %s/ip/nf/g Éric Leblond Nefilter Coreteam September 24, 2013 Éric Leblond (Nefilter Coreteam) nftables, far more than %s/ip/nf/g September 24, 2013 1 / 48 1 Introduction 2 Netfilter in 2013 3 Iptables limitations 4 Nftables, an Iptables replacement 5 Advantages of the approach 6 An updated user experience 7 Conclusion Éric Leblond (Nefilter Coreteam) nftables, far more than %s/ip/nf/g September 24, 2013 2 / 48 Éric Leblond Hacker and contractor Independant Open Source and Security consultant Started and developped NuFW, the authenticating firewall Core developer of Suricata IDS/IPS Netfilter Coreteam member Work on kernel-userspace interaction Kernel hacking ulogd2 maintainer Port of Openoffice firewall to Libreoffice Éric Leblond (Nefilter Coreteam) nftables, far more than %s/ip/nf/g September 24, 2013 4 / 48 History ipchains (1997) Linux 2.2 firewalling stateless Developped by Paul ’Rusty’ Russel iptables (2000) Linux 2.4 firewalling Stateful tracking and full NAT support in-extremis IPv6 support Netfilter project ’Rusty’ Russel developed iptables and funded Netfilter project Netfilter coreteam was created to consolidate the community Éric Leblond (Nefilter Coreteam) nftables, far more than %s/ip/nf/g September 24, 2013 6 / 48 Features Filtering and logging Filtering on protocol fields on internal state Packet mangling Change TOS Change TTL Set mark Connection tracking Stateful filtering Helper to support protocol like FTP Network Address Translation Destination Network Address Translation Source Network Address Translation Éric
    [Show full text]
  • Technical Report TR2005-544 Department of Computer Science, Dartmouth College June 17, 2005 Abstract
    Managing Access Control in Virtual Private Networks A Thesis Submitted to the Faculty in partial fulfillment of the requirements for the degree of Bachelor of Arts in Computer Science by Twum Djin Dartmouth College Technical Report TR2005-544 Department of Computer Science, Dartmouth College June 17, 2005 Abstract Virtual Private Network technology allows remote network users to benefit from resources on a private network as if their host machines actually resided on the network. However, each resource on a network may also have its own access control policies, which may be completely unrelated to network access. Thus users’ access to a network (even by VPN technology) does not guarantee their access to the sought resources. With the introduction of more complicated access privileges, such as delegated access, it is conceivable for a scenario to arise where a user can access a network remotely (because of direct permissions from the network administrator or by delegated permission) but cannot access any resources on the network. There is, therefore, a need for a network access control mechanism that understands the privileges of each remote network user on one hand, and the access control policies of various network resources on the other hand, and so can aid a remote user in accessing these resources based on the user's privileges. This research presents a software solution in the form of a centralized access control framework called an Access Control Service (ACS), that can grant remote users network presence and simultaneously aid them in accessing various network resources with varying access control policies. At the same time, the ACS provides a centralized framework for administrators to manage access to their resources.
    [Show full text]