Archive for the 'Linux' Category

If you work on remotely connected machines, most likely you’re going to use SSH to secure your connections. But, what if you just want to work with files on a remote server, but find SSH file transfer tedious in repetition and establishing a VPN tunnel is too complicated?
What you’re looking for is a simple tool [...]

Tunnel SSH through Tor

Privacy and being anonymous on the Internet are large concerns and top priorities for many online users. For communicating anonymously on the Internet you use Tor. For secure communications, so that nobody can read your private information you use SSH. Combine both, and you have a secure and anonymous communication. In this hack, we’ll show [...]

Protecting against SSH brute-force attacks

Practically all UNIX-based servers run a SSH server to allow remote administration across the Internet. From time to time, you might notice a large number of failed login attempts. Often, these are brute-force attacks against your SSH server
In this hack, we’ll show you 5 tips to protect machines running SSH daemons from brute-force attacks.

mod_auth_openpgp is an Apache module that adds support for OpenPGP signed HTTP requests. It allows web site owners to add an extra access authorization level to servers, virtual hosts and directors based on valid and known signatures.

VoIPong - VoIP calls sniffer

VoIPong is a free VoIP sniffer that detects all Voice-over-IP (VoIP) calls and gateways on a pipeline and produces audio files. It supports several types of VoIP protocols: SIP, H.323, Skinny Client Protocol, G711, RTP and RTCP.
A liveCD version, based on the FreeSBIE project, is also available. It has a pre-installed VoIPong release along with [...]

Plash: Sandbox Linux programs

Plash is an open source system utility for sandboxing Linux applications. Plash aims to downgrade the threats posed by executing untrusted programs by running them in a secure, restricted execution environment with the minimum authority and privileges they need to do their job.
Plash virtualizes the file name-space and provides per-sandboxed-process name-spaces. It locks the sandboxed [...]

aircrack-ptw - WEP Cracking tool

WEP, or Wired Equivalent Privacy, is the default protocol used for securing wireless LANs. It uses the RC4 stream to encrypt data which is transmitted over the air, using usually a single secret key - the WEP key - of a length of 40 or 104 bit.
aircrack-ptw is a WEP key cracking tool that utilizes [...]

FG-Injector is a free open source framework designed to help find SQL injection vulnerabilities in web applications. It includes a proxy feature for intercepting and modifying HTTP requests, and an interface for automating SQL injection exploitation.
It’s a common thought among web developers that by disabling error messages in their code, SQL injection vulnerabilities stop being [...]

Nessus to support IPv6 scanning

The upcoming release of Nessus, the popular security scanner for UNIX, will support scanning of IPv6 addresses. The current Beta release can already be used to perform limited scans of IPv6 addresses.
Although for most readers, IPv6 is just a buzzword, network administrators who deploy IPv6 enabled devices, must assure those devices satisfy government compliances and [...]




Security-Hacks is a web site that covers tips and tricks for security. Updated several times daily, Security-Hacks points out tools downloads, how-to's and tutorials.

Contact


Have a hot hack? want to request a hack? let us know - editor [at] security-hacks.com

subscribe

Enter your Email

Archives

Add to Technorati Favorites

Categories