★ wanayoo — archive 1999 http://www.linuxlinks.com/Software/Networking/Security/Nouvelle recherche | Portail wanayoo
Home | MyLinks | Headlines | Link Us | Add Link | Modify Link | New | Hot | Search
Linux Guide | Linux Package Guide | Linux Product Guide | Bookmark page

Top : Software : Networking : Security
Links:

  • otpCalc
    an OTP and S/Key calculator for X. The OTP system protects against external passive attacks against the authentication subsystem. It does not prevent a network eavesdropper from gaining access to private information and does not provide protection against either "social engineering" or active attacks new
  • SecureIT
    uses MD5 to generate fingerprints of some commonly-manipulated system files and alerts the system administrator via email if they have been altered new
  • yesCoder
    a tool to crypt data in ascii files
  • AGT
    easy administration of linux 2.4 iptables, written in c. Includes sample configuration files and startup scripts
  • Aide
    Advanced Intrusion Detection Environment - a free replacement for Tripwire(tm)
  • angst
    a simple active sniffer, based on libpcap and libnet
  • APS
    tries to print detailed info about network frames that are received from the ETH_P_ALL socket
  • attackwatch
    analyzes the firewall-output in near-realtime and will run scripts in response to incoming packets that got logged
  • authforce
    an HTTP authentication brute forcer. Using various methods, it attempts brute force username and password pairs for a site. It has the ability to try common username and passwords, username derivations, and common username/password pairs
  • BestCrypt
    creates and supports encrypted virtual volumes for Linux. BestCrypt volume is accessible as a regular filesystem on a correspondent mount point
  • BFBTester
    for doing quick, proactive, security checks of binary programs. BFBTester will perform checks of single and multiple argument command line overflows and environment variable overflows
  • Big Brother
    a combination of monitoring methods. Unlike SNMP where information is just collected and devices polled, Big Brother is designed in such a way that each local system broadcasts it's own information to a central location. Simultaneously, Big Brother also polls all networked systems from a central location
  • BLiND
    a brand new encryption algorithm which is fast, and very easy to implement
  • BWNM
    an improved version of WNM. It uses nmap to find all the computers in a given IP range with the netbios port open, then using nmblookup and smbmount it mounts all available shares in the current directory
  • CaclMgr
    a security package which enables UNIX users to have control over which user will get which UNIX command or SHELL script to be executed with my privilege
  • CDSA
    Common Data Security Architecture: provides a security framework that includes cryptographically signed modules to present an abstracted unified API to the application developer to perform cryptographic and security related operations
  • cgichk
    a web vulnerability tool that automatically searches for a series of interesting directories and files on a given site
  • chameleon file encryption
    an experimental file encryption tool using a password-generated, plaintext-feedbacked 2048 bit key, feedbacked xor-chains, and a dummy-header system
  • check-ps
    designed to detect rootkit versions of ps that fail to tell you about selected processes
  • Cmb
    a small utility that creates all the possible combinations from a user mask (that includes wildcards) and dumps them to stdout
  • cmd5checkpw
    a checkpassword compatible authentication program that uses CRAM-MD5 authentiaction mode
  • Crank
    a powerful and extensible environment for solving classical (pen-and-paper) ciphers, providing as much automation as possible
  • cruft
    a replacement for the UNIX crypt utility
  • cryptcat
    a modified version of the famous 'netcat' program
  • Cryptix
    a cleanroom implementation of Sun's Java Cryptography Extensions (JCE) version 1.1. In addition to that it contains the Cryptix Provider which delivers a wide range of algorithms and support for PGP 2.x. Cryptix 3 runs on both JDK 1.1 and JDK 1.2 (Java 2)
  • CryptoPadSplicer
    a conduit for a cryptographic MemoPad replacement application for the Palm(tm) computing platform called CryptoPad
  • dea
    a data encryption algorithm bitwise compatible with ANSI standard X3.92-1981, also known as DES. This software implements a command line utility and a library
  • Dragon
    a content-based IDS by Ron Gula than runs on Linux, Open/FreeBSD, and Solaris
  • dsniff
    a suite of utilities that demonstrate the insecurity of plaintext network protocols
  • ECC
    a package for working with Elliptic Curves
  • encrypt
    for turning plaintext words or strings into their encrypted forms in a variety of ways
  • exscan
    a network/Internet port scanner, that uses the strobe-scan technique of only scanning certain ports, instead of a full blown port scan
  • FakeBO
    fakes trojan servers and logs every attempt from client. It is possible to log attempts to file, stdout, stderr or to syslog. It can send fake pings and replies back to trojan client
  • FCheck
    an open source PERL script providing intrusion detection and policy enforcement of Windows 95/98/NT/3.x and Unix server administration through the use of comparative system snapshots.
  • fCluster
    a multi-threaded client/server redundancy application for your Linux firewall solution. fCluster is designed for the production environment with features that include: dynamic firewall synchronization, support for both ipchains and netfilter, user definable polling intervals and fail-over sequence, and email notification of a system failure
  • fireparse
    a perl script that is executed daily that e-mails a report of all packets that have been logged by the v2.2.x kernel's ipchains packet filtering subsystem. The report includes source and destination ports, direction, packet count, ipchains rule, and fully resolved host name
  • firesoft
    a collection of perl scripts that include a log analyzer, packet analyzer, crontab script, and a bar chart creator for ipchains log
  • fk
    a free software replacement for the TIS fwtk
  • FreeVeracity
    a free intrusion detection tool for free platforms (GNU/Linux, FreeBSD, NetBSD, OpenBSD, etc.) that uses cryptographic hashes to detect file changes that may indicate a network intrusion
  • FreSSH
    a free implementation of the SSH communication protocol. It is compact, modular, portable, and designed for security and performance. It is a completely new implementation sharing no code with any other implementation of the SSH communication protocol
  • Geheimnis
    a KDE application that "wraps" around GPG/PGP's irksome command-line interface and makes it easier for users to use these programs
  • GnoScan
    a multi-threaded network scan and security utility with an intuitive graphical user interface
  • GNU Keyring
    lets you securely store digital secret keys on your Palm handheld computer
  • GnuPG.pm
    a perl module that interface with the Gnu Privacy Guard using the coprocess hooks provided by gpg. The communication mechanism used is shared memory and a status file descriptor
  • Gripwire
    a Frontend to Tripwire. Gripwire utilizes ssh and Tripwire to provide a single graphical interface which enables the user to easily create, check, and update file integrity databases for a whole network. Databases are saved locally and can be viewed in the Gripwire main window, together with some statistical information
  • HiSecure SurfProtector
    (commercial) provides secure encrypted communication betwenn hosts over an insecure network. You can redirect any TCP/IP ports over this secure encrypted channel.(in German)
  • HostSentry
    a host based login anomaly detection and response tool
  • hping2
    does TCP/IP stack auditing, to uncover firewall policy, to scan TCP port in a lot of different modes, to transfer files across a firewall and more
  • hunt
    the main goal of the HUNT project is to develop a tool for exploiting well-known weaknesses in the TCP/IP protocol suite. It implements some "new" features which apparently are not available in any other free product
  • ImSafe
    a host-based intrusion detection tool for Linux. It is performing anomaly detection at the process level and tries to detect various type of attacks
  • install-ssh
    a tool that downloads, compiles, and installs RPMS of the latest version of SSH (Secure Shell)
  • Intact
    (commercial) detects changes in computer systems by taking a snapshot of system objects and then comparing the snapshot to the active system in real-time
  • ip-masq-log
    a patch that can be used on a masquerading firewall (NAT) to keep a log of all the outgoing masqueraded TCP connections
  • ipfa
    can do per-ip accounting, free IP setting, user management, per-month, per-day, and per-minute logging, MAC-IP binding, firewall rule setting, online user monitoring,
  • Iplayer
    for sniffing traffic (or read a capture tcpdump file) and produces output that can be easily pasted into a NASLscript or passed as payload to Sendip
  • IPLimit
    a security tool to prevent some denial of services on common internet daemons. It will dynamically reject connections from hosts that already connected too many times on the same service or the same server
  • IPPS
    a port scanner which provides custom port scan range, subnet scan after the netmask of a host in that network, specified source port for the scan, output to file for letting it work all night without redirecting output in a huge command line
  • iptables-firewall
    a set of scripts which make setting up an IP Masq/NAT/Firewall system easy and (mostly) painless
  • ISIC
    IP Stack Integrity Checker: to test the stability of an IP Stack and its component stacks (TCP, UDP, ICMP et. al.) It does this be generating random packets of the desired protocol
  • ITS4
    a command-line tool for statically scanning C and C++ source code for security vulnerabilities
  • JavaPad
    a java implementation of the cryptography algorithm "one time pad" which is extremely secure
  • JCon
    a java hacking and security tool with a lot of features
  • jDES
    a highly optimized, highly configurable implementation of the Data Encryption Standard (DES) in Java
  • Jerry Crypt
    an encryption algorithm that was developed for fun
  • John the Ripper
    a password cracker, currently available for UNIX, DOS, WinNT/Win95. Its primary purpose is to detect weak UNIX passwords
  • keymgr
    a cryptographic policy engine
  • KeyNote
    a simple and flexible trust-management system designed to work well for a variety of large- and small- scale Internet-based applications
  • KFilecoder
    a KDE utility which encodes files in an archive with a password
  • Knetfilter
    a KDE application designed to manage the netfilter functionalities that will come with the new kernel 2.4.x.
  • KPGPCrypt
    Key Managment for PGP 5.xx, PGP 6.xx and GPG 1.xx. Supports Add, Delete, Sign, Revoke, Disable Enable keys in graphical environment
  • KSnuffle
    a network packet sniffer for KDE
  • kssh
    a KDE Secure Shell Frontend
  • KWoodhammer
    encrypts messages in the enigma cypher, and the well-known Caesar method, to help find the keys of codes
  • LCAP
    allows a system administrator to remove specific capabilities from the kernel in order to make the system more secure. "Capabilities" are a form of kernel-based access control
  • lids
    Linux IDS Patch (lids) for Linux is an intrusion detect system in Linux kernel
  • lightbar
    a login enhancement for FreeBSD and Linux. It adds features from BSD4.4 SunOS(solaris) and HP-UX into a Linux, FreeBSD portable and simple login program
  • Logcheck
    helps spot problems and security violations in your logfiles automatically and will send the results to you in e-mail. This program is free to use at any site
  • mcrypt
    a replacement of the old unix crypt(1) under the GNU General Public License. Unix Crypt(1) was a popular(?) file encryption program in unix boxes. It was based on the enigma encryption algorithm but it was considerable trivialized. Mcrypt uses some modern block encryption algorithms. It also has a compatibility mode with unix crypt and with solaris des(1). It supports several block algorithms like Blowfish, Twofish, DES, 3DES, 3-WAY, SAFER-SK64/128, SAFER+, LOKI97, GOST, RC2, RC6, IDEA and CAST-128/256
  • md5mon
    a very basic security auditing script. It checks that certain system files have not been modified and it uses "md5sum" to compute checksums of files, reporting any differences from previously recorded checksums
  • MindTerm
    a free SSH client program written in Java (non-certified). It can be run as a stand-alone program or as an applet in a webpage
  • nabou
    a perl script which you can use to check file integrity
  • NBChk
    a multi-threaded perl banner checking utility that is fully configurable and can scan a full/partial class c network, hosts from a file, or a single host for configured vulnerabilities
  • Nessus
    a free, open-sourced and easy-to-use security auditing tool
  • NOES
    Negative One Encryption Scheme: a simple encryption scheme using an XOR shift from a key file. The project is derived from SSES
  • Nstreams
    analyzes the streams that occur on a network. It displays which streams are generated by the users between several networks, and between the networks and the outside. It can optionally generate the ipchains or ipfw rules that will match these streams, thus only allowing what is required for the users, and nothing more
  • Nutcracker
    a fast password cracker for Linux/Unix
  • OpenKeyServer
    (commercial) a public keys server for storing PGP public keys
  • OpenSSH
    a Linux port of OpenBSD's excellent OpenSSH. This Linux port basically consists of a few fixes to deal with the way that OpenSSL is usually installed on Linux systems, a few replacements for OpenBSD library functions and the introduction of PAM support. This version tracks changes made to the OpenBSD CVS version
  • Osiris Scripts
    compare one catalog of executable files with another catalog of executable files
  • OutGuess
    a universal steganographic tool that allows the insertion of hidden information into the redundant bits of data sources. The nature of the data source is irrelevant to the core of OutGuess. The program relies on data specific handlers that will extract redundant bits and write them back after modification. In this version the PNM and JPEG image formats are supported
  • overwrite
    a UNIX utility for secure deletion. It's based on Peter Gutmann's paper "secure deletion of data from magnetic and solid state memory"
  • P-Synch
    (commercial) a password management software toolkit that can: synchronize user passwords across all systems and platforms; enforce enterprise-wide password strength policies; allow help desk staff to reset passwords on every system, with no special administrative rights; allow authenticated users to reset their own forgotten passwords
  • PaGeMan
    a password generator and manager which has many options. Source included. GPL
  • PAIP
    a universal filter application. It uses plugins to transmit and convert data. They can be nested, so the inner structures can become quite complex
  • pam_cryptocard
    a PAM module that authenticates a user using challenge-response
  • PDScanner
    a network port scanner for GNOME. It's designed for system administrators to check their networks for security holes
  • Perl Necklace
    a wrapper for the perl binary to increase site-wide security
  • pgp-gui
    a small and easy to use PGP frontend
  • PGPacket
    analyzes and displays the contents of a PGP-encrypted file (or anything that follows the OpenPGP spec), showing the nature and contents of each packet (of course, the contents of many packets may be encrypted, and PGPacket does not decrypt)
  • pgpforwarder
    a Perl server that accepts plain-text mails for users and sends them out encrypted
  • Pgpgpg
    a wrapper around Gnu Privacy Guard which takes PGP 2.6 command line options, translates them and then call GnuPG (Gnu Privacy Guard) to perform the desired action
  • Phantom Cipher
    a block cipher that has a block length of 128 bits, and a key size of 256 bits
  • PinePgp
    provides PGP and GnuPG filters for Pine
  • polyalphabetic substitution
    encrypts and decrypts plaintext using different monoalphabetic substitutions as it proceeds through a plaintext message
  • pppit
    allows one to tunnel through a firewall which only allows proxy telnet, such as SWAN
  • pspg
    a Pretty Simple Password Generator
  • PSR
    Password Storage and Retrieval System: securly encrypts passwords, and then uses them to obtain an AFS token before your job starts, and keep refreshing the token for the length of your job so that your AFS token does not expire in the middle of your run
  • pvm_crack
    a pvm (Beowulf) enabled brute force password cracker for standard unix passwords
  • pyCA
    tries to make it easier for people to set up and run a organizational certificate authority which fulfills the need for a fairly secure certification processing.
  • Quintuple Agent
    keeps passphrases and passwords in memory for a configurable timespan
  • Refugee
    implements blowfish and is portable between big- and little-endian platforms
  • Riley
    a file integrity checker written in Perl
  • SafeGossip
    an implementation of RFCs 2487 and 2595(which define standards for using TLS with IMAP, POP and SMTP). SafeGossip also provides implementations of the draft FTP and telnet RFCs
  • SafeRelay
    a certificate authority center, based on OpenSSL, for network administrators who want to deploy certificates on a LAN
  • Saint
    Security Administrator's Integrated Network Tool, the successor to SATAN
  • sanitizer
    a filter that rewrites MIME messages so as to 'defang' well known email-based exploits and trojan horse
  • SAStk
    Slackware Administrators Security tool kit: a set of tools and utilities to install and maintain a reasonable level of security for the Slackware Linux distribution
  • SATAN
    Security Administrator's Tool for Analyzing Networks
  • SBScan
    a localhost security scanner. It checks for numerous security problems on a linux box
  • SCAIN
    Simple Crypto Algorithm Ideated by a Novice: a simple cryptographic algorithm that generates different output with the same input and the same password. It uses pass phrases and keys of 128 bits; the idea is to hide the key in the cipher based on the password
  • Scan Detect
    listens on a given TCP port and if any host on the internet connects to that TCP port, Scan Detect uses Ipchains to block that host from connecting to your Linux system
  • Scanner
    a small yet fast port scanner that can scan a range of IP Addresses for open ports
  • Seahorse
    a Gnome front end for GnuPG - the Gnu Privacy Guard file encryption/decryption program. Both English and Japanese support is provided
  • SecPanel
    serves as a graphical user interface for managing and running SecureShell (SSH) connections
  • Secure Shell
    a shell script for secure logins using encryption and dual authorization. It prevents non-authorized users from logging into a shell server even if they have the correct login/pass
  • Secure Sockets Agent
    a system for securing the insecure or insufficiently secure communication between the existing network applications. It provides almost any client/server application with strong cryptographic security, ensuring both integrity and confidentiality of the exchanged data as well as authenticating both the client and the server
  • Sentinel
    a fast file/drive scanning utility similar to the Tripwire and Viper.pl utilities available. It uses a database similar to Tripwire, but uses a RIPEMD-160bit MAC checksumming algorithm (no patents) which is more secure than the patented MD5 128 bit checksum
  • sharesecret
    splits a secret into parts given a threshold t, such that at least t parts are needed to reconstruct the secret
  • sigs
    provides secure digital signatures with verification at secret-key speeds. 2048-bit verification on a Pentium-100 takes under 150 microseconds
  • Slurpie
    a passwd file cracker similar to CrackerJack and John the Ripper except that it can be run in a distributed environment
  • Smart Sign
    provides smartcard-based "digital signature" and "local authentication" security services. It relies on a working Certification Authority that issues a public key certificate for the user
  • Solsoft NP-Lite
    allowing users to define, implement and maintain granular policies on their servers, DMZs and access to the Internet
  • Sportal
    monitors files that you select, for "hot words" that you also select, through a graphical interface
  • Spy
    a LAN Protocol Analyzer running on UNIX platforms. It has a built-in interface to capture LAN traffic via a network interface. This capture facility supports Ethernet, FDDI, SLIP/CSLIP, PPP and PLIP. SPY also provides a so called User Capture Interface (UCI), where own programs can feed SPY with their packets. Of course, captured data can be stored to files in binary format for later analysis
  • srm
    Secure rm is designed to delete files in a secure fashion by overwriting files before actually deleting it
  • SRP
    Secure Remote Password protocol is a password-based authentication and key exchange mechanism where no information about the password is leaked during the authentication process.
  • ssh
    a program to log into another computer over a network, to execute commands in a remote machine, and to move files from one machine to another. It provides strong authentication and secure communications over insecure channels. It is intended as a replacement for rlogin, rsh, rcp, and rdist
  • SSH Buddy
    a GUI frontend for ssh, based on TCL/Tk
  • ssh-gui
    a front-end for ssh which can open multiple xterms with connections. Supports all ssh options and soon will support user-host config saving and xterm config
  • ssldump
    an SSLv3/TLS network protocol analyzer. It identifies TCP connections on the chosen network interface and attempts to interpret them as SSLv3/TLS traffic. When it identifies SSLv3/TLS traffic, it decodes the records and displays them in a textual form to stdout
  • Steghide
    designed to be portable and configurable and features hiding data in bmp, wav and au files, blowfish encryption, MD5 hashing of passphrases to blowfish keys and pseudo-random distribution of hidden bits in the container data
  • Strip
    Secure Tool for Recalling Important Passwords
  • TEA Total
    an extremely small 128 bit private key based encryption/decryption system which uses the new variant of TEA (Tiny Encryption Algorithm)
  • tkauth
    a graphical interface to xauth, the X authorization control program. It gives the user a quick and easy method of controlling access to his or her machine, without requiring any knowledge of xauth
  • Tknetbus
    a Tcl/TK-Client for the netbusserver, a trojan which allows intruders to control the computer with netbusservers running on
  • TkPGP
    a GUI front-end for PGP and GnuPG crypto software on Linux/BSD/UNIX. It is written in Tcl/Tk and is highly portable. Most of usual procedures (encryption, signing, decryption) are supported
  • Topsecret
    a shareware program to encrypt your sensitive files
  • Topsecret_Net
    a network encryption program. It allows you to transfer files across a lan or internet and offers protection against electronic eavesdropping of data in transit
  • Tripwall
    a GPL Tripwire clone intended for use with the Linux Router Project
  • Tripwire
    a commercial system integrity checker and a utility that compares properties of designated files and directories against information stored in a previously generated database
  • Turfkeeper
    a network logging suite designed for easy use and low resource demand
  • Twonz
    a program for "password management"
  • userv
    a Unix system facility to allow one program to invoke another when only limited trust exists between them
  • ViperDB
    a smaller & faster option to Tripwire
  • VPS
    a linux-based VPN solution for connecting disparate networks securely over the internet. Using this software, you can connect multiple networks to each other without having to pay for expensive leased lines or dedicated connections
  • webNIS
    a simple authentication mechanism. It provides a server, or inetd service which simply takes in a login and a password, and responds with the user's real name (as listed in the gecos records) or nothing in case of failure
  • wipe
    a little command for securely erasing files from magnetic media. It compiles under various UNIX platforms, including Linux 2.0, AIX 4.1, SunOS 5.5.1
  • wipe
    a secure file wiping utility. however, it does not set the media access bit on scsi commands, therefore it is not 100% secure unless your drive has no write cache
  • XML Security Suite
    provides security features such as digital signature, element-wise encryption, and access control to Internet business-to-business transactions
  • yyyRSA
    a simple program to encrypt and decipher messages with the RSA asymetrical encryption algorithm
  • Zebedee
    a simple program to establish an encrypted, compressed TCP/IP "tunnel" between two systems. This allows TCP-based traffic such as telnet, ftp and X to be protected from snooping as well as potentially gaining performance over low-bandwidth networks from compression
  • Zodiac
    a DNS protocol analyzation and exploitation program. It is a robust tool to explore the DNS protocol
Category:  
About | Advertise | FAQ | Press Releases | LinkBack | Privacy | Awards | Contact
Pages Updated: 8-May-2001 Portal version: 0.4
Email us with your comments about this site