» tagged pages
» logout

sorted by: recent | see : popular
Content Tagged with Tools + Security

AMANDA, The Advanced Maryland Automatic Network Disk Archiver

AMANDA, the Advanced Maryland Automatic Network Disk Archiver, is a backup system that allows the administrator to set up a single master backup server to back up multiple hosts over network to tape drives/changers or disks or optical media. Amanda uses n

open-source: del.icio.us tag/open-source

Kismac (Google code)

Open-source and free stumbler/scanner application for Mac OS X

opensource: del.icio.us tag/opensource

3 Reasons not to use Apache mod_rewrite

After reading this discussion on Slashdot regarding an anti-virus agent pretending to be Internet Explorer and flooding sites with requests I waited to see a response come from an Apache fan on using mod_rewrite to detect and stop the flood of useless traffic coming from these robots. It was sure to come, particularly after the first post in the discussion pointed out how to use an iRule to detect and "nuke from orbit" these nasty little requests. I was not disappointed. It's not the case that the solution won't work. It will, and it's certainly a viable solution. At least if you're only running 2 or 3 web servers. And you don't care about the need to interrupt service to implement the solution. And you aren't worried about potentially introducing errors into the server configuration. And you're aren't running IIS or some other web server. There are a few very good reasons not to use Apache mod_rewrite for this kind of situation.

technology: dzone.com: tech links

SunJCE is broken in J2SDK1.4.2 (Pankaj Kumar's Weblog) | Author of JSTK

As a workaround to this problem, I am making a maintenance release of JSTK, JSTK-1.0.1. This release allows a user to specify the keystore type as either JCEKS or JKS.

XML: del.icio.us/tag/xml

Helix - Incident Response & Computer Forensics Live CD by e-fense_, Inc.

Many security tools in one Linux LiveCD distribution including The Sleuth Kit and more.

knoppix: del.icio.us/tag/knoppix

Google opensources it's web security assesment tool

We're happy to announce that we've just open-sourced ratproxy, a passive web application security assessment tool that we've been using internally at Google. This utility, developed by our information security engineering team, is designed to transparently analyze legitimate, browser-driven interactions with a tested web property and automatically pinpoint, annotate, and prioritize potential flaws or areas of concern.

technology: dzone.com: tech links

Evil GIFs: Hiding Java in your image

What if you could encode a Jar file as an image and trick the browser to run it? This is what Ben Lorica reported from a black hat briefing webinar:

technology: dzone.com: tech links

Google gives away free Web application security scanner

Google has released for free one of its internal tools used for testing the security of Web-based applications. Ratproxy, released under an Apache 2.0 software license, looks for a variety of coding problems in Web applications, such as errors that could allow a cross-site scripting attack or cause caching problems.

technology: dzone.com: tech links

Page 1 | Next >>