★ wanayoo — archive 1999 http://www.linuxlinks.com/Software/Networking/Security/index.shtmlNouvelle recherche | Portail wanayoo
Home | Headlines | Link Us | Add a Resource | Modify a Resource | New | Recommended | Search | Contact
Linux Guide | Linux Package Guide | Linux Product Guide

Top : Software : Networking : Security
Links:

  • nabou
    a perl script which you can use to check file integrity new
  • NOES
    Negative One Encryption Scheme: a simple encryption scheme using an XOR shift from a key file. The project is derived from SSES new
  • PGPacket
    analyzes and displays the contents of a PGP-encrypted file (or anything that follows the OpenPGP spec), showing the nature and contents of each packet (of course, the contents of many packets may be encrypted, and PGPacket does not decrypt) new
  • Aide
    Advanced Intrusion Detection Environment - a free replacement for Tripwire(tm)
  • APS
    tries to print detailed info about network frames that are received from the ETH_P_ALL socket
  • BestCrypt
    creates and supports encrypted virtual volumes for Linux. BestCrypt volume is accessible as a regular filesystem on a correspondent mount point
  • BFBTester
    for doing quick, proactive, security checks of binary programs. BFBTester will perform checks of single and multiple argument command line overflows and environment variable overflows
  • Big Brother
    a combination of monitoring methods. Unlike SNMP where information is just collected and devices polled, Big Brother is designed in such a way that each local system broadcasts it's own information to a central location. Simultaneously, Big Brother also polls all networked systems from a central location
  • BWNM
    an improved version of WNM. It uses nmap to find all the computers in a given IP range with the netbios port open, then using nmblookup and smbmount it mounts all available shares in the current directory
  • CaclMgr
    a security package which enables UNIX users to have control over which user will get which UNIX command or SHELL script to be executed with my privilege
  • cgichk
    a web vulnerability tool that automatically searches for a series of interesting directories and files on a given site
  • chameleon file encryption
    an experimental file encryption tool using a password-generated, plaintext-feedbacked 2048 bit key, feedbacked xor-chains, and a dummy-header system
  • check-ps
    designed to detect rootkit versions of ps that fail to tell you about selected processes
  • cipherczar
    a tool to assist in breaking simple ciphers
  • Cmb
    a small utility that creates all the possible combinations from a user mask (that includes wildcards) and dumps them to stdout
  • cmd5checkpw
    a checkpassword compatible authentication program that uses CRAM-MD5 authentiaction mode
  • cruft
    a replacement for the UNIX crypt utility
  • crypt_l
    a simple, small, but fast encryption utility
  • Cryptix
    a cleanroom implementation of Sun's Java Cryptography Extensions (JCE) version 1.1. In addition to that it contains the Cryptix Provider which delivers a wide range of algorithms and support for PGP 2.x. Cryptix 3 runs on both JDK 1.1 and JDK 1.2 (Java 2)
  • dea
    a data encryption algorithm bitwise compatible with ANSI standard X3.92-1981, also known as DES. This software implements a command line utility and a library
  • Dragon
    a content-based IDS by Ron Gula than runs on Linux, Open/FreeBSD, and Solaris
  • dsniff
    a suite of utilities that demonstrate the insecurity of plaintext network protocols
  • encrypt
    for turning plaintext words or strings into their encrypted forms in a variety of ways
  • exscan
    a network/Internet port scanner, that uses the strobe-scan technique of only scanning certain ports, instead of a full blown port scan
  • FakeBO
    fakes trojan servers and logs every attempt from client. It is possible to log attempts to file, stdout, stderr or to syslog. It can send fake pings and replies back to trojan client
  • FCheck
    an open source PERL script providing intrusion detection and policy enforcement of Windows 95/98/NT/3.x and Unix server administration through the use of comparative system snapshots.
  • fireparse
    a perl script that is executed daily that e-mails a report of all packets that have been logged by the v2.2.x kernel's ipchains packet filtering subsystem. The report includes source and destination ports, direction, packet count, ipchains rule, and fully resolved host name
  • firesoft
    a collection of perl scripts that include a log analyzer, packet analyzer, crontab script, and a bar chart creator for ipchains log
  • Geheimnis
    a KDE application that "wraps" around GPG/PGP's irksome command-line interface and makes it easier for users to use these programs
  • GNU Keyring
    lets you securely store digital secret keys on your Palm handheld computer
  • GnuPG.pm
    a perl module that interface with the Gnu Privacy Guard using the coprocess hooks provided by gpg. The communication mechanism used is shared memory and a status file descriptor
  • Gripwire
    a Frontend to Tripwire. Gripwire utilizes ssh and Tripwire to provide a single graphical interface which enables the user to easily create, check, and update file integrity databases for a whole network. Databases are saved locally and can be viewed in the Gripwire main window, together with some statistical information
  • GtkPortScan
    a simple portscanner written in Gtk+. It features dialog boxes for IP addresses, start port, stop port, CList windows for returned ports along with buttons for your clicking needs. It will scan an IP address and let you know of the open/available ports through a GUI interface that is user-friendly
  • Hand
    provides a secure execution environment for all types of Unix applications including utilities, system services and graphical application programs
  • HiSecure SurfProtector
    (commercial) provides secure encrypted communication betwenn hosts over an insecure network. You can redirect any TCP/IP ports over this secure encrypted channel.(in German)
  • HostSentry
    a host based login anomaly detection and response tool
  • hping2
    does TCP/IP stack auditing, to uncover firewall policy, to scan TCP port in a lot of different modes, to transfer files across a firewall and more
  • hunt
    the main goal of the HUNT project is to develop a tool for exploiting well-known weaknesses in the TCP/IP protocol suite. It implements some "new" features which apparently are not available in any other free product
  • install-ssh
    a tool that downloads, compiles, and installs RPMS of the latest version of SSH (Secure Shell)
  • Intact
    (commercial) detects changes in computer systems by taking a snapshot of system objects and then comparing the snapshot to the active system in real-time
  • ipfa
    can do per-ip accounting, free IP setting, user management, per-month, per-day, and per-minute logging, MAC-IP binding, firewall rule setting, online user monitoring,
  • IPLimit
    a security tool to prevent some denial of services on common internet daemons. It will dynamically reject connections from hosts that already connected too many times on the same service or the same server
  • IPPS
    a port scanner which provides custom port scan range, subnet scan after the netmask of a host in that network, specified source port for the scan, output to file for letting it work all night without redirecting output in a huge command line
  • ISIC
    IP Stack Integrity Checker: to test the stability of an IP Stack and its component stacks (TCP, UDP, ICMP et. al.) It does this be generating random packets of the desired protocol
  • ITS4
    a command-line tool for statically scanning C and C++ source code for security vulnerabilities
  • Jerry Crypt
    an encryption algorithm that was developed for fun
  • John the Ripper
    a password cracker, currently available for UNIX, DOS, WinNT/Win95. Its primary purpose is to detect weak UNIX passwords
  • keymgr
    a cryptographic policy engine
  • KeyNote
    a simple and flexible trust-management system designed to work well for a variety of large- and small- scale Internet-based applications
  • Knetfilter
    a KDE application designed to manage the netfilter functionalities that will come with the new kernel 2.4.x.
  • KPGPCrypt
    Key Managment for PGP 5.xx, PGP 6.xx and GPG 1.xx. Supports Add, Delete, Sign, Revoke, Disable Enable keys in graphical environment
  • KSnuffle
    a network packet sniffer for KDE
  • KWoodhammer
    encrypts messages in the enigma cypher, and the well-known Caesar method, to help find the keys of codes
  • LCAP
    allows a system administrator to remove specific capabilities from the kernel in order to make the system more secure. "Capabilities" are a form of kernel-based access control
  • lids
    Linux IDS Patch (lids) for Linux is an intrusion detect system in Linux kernel
  • lightbar
    a login enhancement for FreeBSD and Linux. It adds features from BSD4.4 SunOS(solaris) and HP-UX into a Linux, FreeBSD portable and simple login program
  • Logcheck
    helps spot problems and security violations in your logfiles automatically and will send the results to you in e-mail. This program is free to use at any site
  • mcrypt
    a replacement of the old unix crypt(1) under the GNU General Public License. Unix Crypt(1) was a popular(?) file encryption program in unix boxes. It was based on the enigma encryption algorithm but it was considerable trivialized. Mcrypt uses some modern block encryption algorithms. It also has a compatibility mode with unix crypt and with solaris des(1). It supports several block algorithms like Blowfish, Twofish, DES, 3DES, 3-WAY, SAFER-SK64/128, SAFER+, LOKI97, GOST, RC2, RC6, IDEA and CAST-128/256
  • md5mon
    a very basic security auditing script. It checks that certain system files have not been modified and it uses "md5sum" to compute checksums of files, reporting any differences from previously recorded checksums
  • MindTerm
    a free SSH client program written in Java (non-certified). It can be run as a stand-alone program or as an applet in a webpage
  • NBChk
    a multi-threaded perl banner checking utility that is fully configurable and can scan a full/partial class c network, hosts from a file, or a single host for configured vulnerabilities
  • nero
    a tool to assist in breaking simple ciphers. It currently supports simple substitution ciphers with a bit of extra support for rotations.
  • Nessus
    a free, open-sourced and easy-to-use security auditing tool hot
  • Nstreams
    analyzes the streams that occur on a network. It displays which streams are generated by the users between several networks, and between the networks and the outside. It can optionally generate the ipchains or ipfw rules that will match these streams, thus only allowing what is required for the users, and nothing more
  • Nutcracker
    a fast password cracker for Linux/Unix
  • OpenKeyServer
    (commercial) a public keys server for storing PGP public keys
  • OpenSSH
    a Linux port of OpenBSD's excellent OpenSSH. This Linux port basically consists of a few fixes to deal with the way that OpenSSL is usually installed on Linux systems, a few replacements for OpenBSD library functions and the introduction of PAM support. This version tracks changes made to the OpenBSD CVS version
  • Osiris Scripts
    compare one catalog of executable files with another catalog of executable files
  • OutGuess
    a universal steganographic tool that allows the insertion of hidden information into the redundant bits of data sources. The nature of the data source is irrelevant to the core of OutGuess. The program relies on data specific handlers that will extract redundant bits and write them back after modification. In this version the PNM and JPEG image formats are supported
  • overwrite
    a UNIX utility for secure deletion. It's based on Peter Gutmann's paper "secure deletion of data from magnetic and solid state memory"
  • P-Synch
    (commercial) a password management software toolkit that can: synchronize user passwords across all systems and platforms; enforce enterprise-wide password strength policies; allow help desk staff to reset passwords on every system, with no special administrative rights; allow authenticated users to reset their own forgotten passwords
  • PDScanner
    a network port scanner for GNOME. It's designed for system administrators to check their networks for security holes
  • Perl Necklace
    a wrapper for the perl binary to increase site-wide security
  • pgp-gui
    a small and easy to use PGP frontend
  • pgpforwarder
    a Perl server that accepts plain-text mails for users and sends them out encrypted
  • Pgpgpg
    a wrapper around Gnu Privacy Guard which takes PGP 2.6 command line options, translates them and then call GnuPG (Gnu Privacy Guard) to perform the desired action
  • Phantom Cipher
    a block cipher that has a block length of 128 bits, and a key size of 256 bits
  • PinePgp
    provides PGP and GnuPG filters for Pine
  • polyalphabetic substitution
    encrypts and decrypts plaintext using different monoalphabetic substitutions as it proceeds through a plaintext message
  • PortZilla
    a portscanner for Linux, XFree86 and Windows. It has an easy to use interface (Console, Qt), 4 types of scanning and provides operating system reconition
  • pspg
    a Pretty Simple Password Generator
  • pyCA
    tries to make it easier for people to set up and run a organizational certificate authority which fulfills the need for a fairly secure certification processing.
  • SafeGossip
    an implementation of RFCs 2487 and 2595(which define standards for using TLS with IMAP, POP and SMTP). SafeGossip also provides implementations of the draft FTP and telnet RFCs
  • Saint
    Security Administrator's Integrated Network Tool, the successor to SATAN hot
  • sanitizer
    a filter that rewrites MIME messages so as to 'defang' well known email-based exploits and trojan horse
  • SATAN
    Security Administrator's Tool for Analyzing Networks
  • SBScan
    a localhost security scanner. It checks for numerous security problems on a linux box
  • SCAIN
    Simple Crypto Algorithm Ideated by a Novice: a simple cryptographic algorithm that generates different output with the same input and the same password. It uses pass phrases and keys of 128 bits; the idea is to hide the key in the cipher based on the password
  • Scan Detect
    listens on a given TCP port and if any host on the internet connects to that TCP port, Scan Detect uses Ipchains to block that host from connecting to your Linux system
  • Scanner
    a small yet fast port scanner that can scan a range of IP Addresses for open ports
  • Seahorse
    a Gnome front end for GnuPG - the Gnu Privacy Guard file encryption/decryption program. Both English and Japanese support is provided
  • seclog
    a light & clean, fast log auditing tool. it will grab any suspicious information from /var/log/messages and will email it to a specified user or email address
  • SecPanel
    serves as a graphical user interface for managing and running SecureShell (SSH) connections
  • Secret Agent
    keeps passphrases and passwords in memory for a configurable timespan
  • secret-share
    a very simple program that implements n-way secret sharing. A file is cryptographically split into n shares, all of which are needed to reconstruct the original file.
  • Secure Portal
    made for people that need to know what is going on in their systems. It monitors files that you select, for "hot words" that you also select, through a graphical interface
  • Secure Shell
    a shell script for secure logins using encryption and dual authorization. It prevents non-authorized users from logging into a shell server even if they have the correct login/pass
  • Secure Sockets Agent
    a system for securing the insecure or insufficiently secure communication between the existing network applications. It provides almost any client/server application with strong cryptographic security, ensuring both integrity and confidentiality of the exchanged data as well as authenticating both the client and the server
  • Sentinel
    a fast file/drive scanning utility similar to the Tripwire and Viper.pl utilities available. It uses a database similar to Tripwire, but uses a RIPEMD-160bit MAC checksumming algorithm (no patents) which is more secure than the patented MD5 128 bit checksum
  • sharesecret
    splits a secret into parts given a threshold t, such that at least t parts are needed to reconstruct the secret
  • sigs
    provides secure digital signatures with verification at secret-key speeds. 2048-bit verification on a Pentium-100 takes under 150 microseconds
  • Slurpie
    a passwd file cracker similar to CrackerJack and John the Ripper except that it can be run in a distributed environment
  • Smart Sign
    provides smartcard-based "digital signature" and "local authentication" security services. It relies on a working Certification Authority that issues a public key certificate for the user
  • Sportal
    monitors files that you select, for "hot words" that you also select, through a graphical interface
  • Spy
    a LAN Protocol Analyzer running on UNIX platforms. It has a built-in interface to capture LAN traffic via a network interface. This capture facility supports Ethernet, FDDI, SLIP/CSLIP, PPP and PLIP. SPY also provides a so called User Capture Interface (UCI), where own programs can feed SPY with their packets. Of course, captured data can be stored to files in binary format for later analysis
  • srm
    (download only) Secure rm is designed to delete files in a secure fashion by overwriting files before actually deleting it hot
  • SRP
    Secure Remote Password protocol is a password-based authentication and key exchange mechanism where no information about the password is leaked during the authentication process.
  • ssh
    a program to log into another computer over a network, to execute commands in a remote machine, and to move files from one machine to another. It provides strong authentication and secure communications over insecure channels. It is intended as a replacement for rlogin, rsh, rcp, and rdist
  • SSH Buddy
    a GUI frontend for ssh, based on TCL/Tk
  • ssh-gui
    a front-end for ssh which can open multiple xterms with connections. Supports all ssh options and soon will support user-host config saving and xterm config
  • Steghide
    designed to be portable and configurable and features hiding data in bmp, wav and au files, blowfish encryption, MD5 hashing of passphrases to blowfish keys and pseudo-random distribution of hidden bits in the container data
  • Strip
    Secure Tool for Recalling Important Passwords
  • tkauth
    a graphical interface to xauth, the X authorization control program. It gives the user a quick and easy method of controlling access to his or her machine, without requiring any knowledge of xauth
  • Tknetbus
    a Tcl/TK-Client for the netbusserver, a trojan which allows intruders to control the computer with netbusservers running on
  • TkPGP
    a GUI front-end for PGP and GnuPG crypto software on Linux/BSD/UNIX. It is written in Tcl/Tk and is highly portable. Most of usual procedures (encryption, signing, decryption) are supported
  • Topsecret
    a shareware program to encrypt your sensitive files
  • Tripwall
    a GPL Tripwire clone intended for use with the Linux Router Project
  • Tripwire
    a commercial system integrity checker and a utility that compares properties of designated files and directories against information stored in a previously generated database
  • Turfkeeper
    a network logging suite designed for easy use and low resource demand
  • Twonz
    a program for "password management"
  • userv
    a Unix system facility to allow one program to invoke another when only limited trust exists between them
  • ViperDB
    a smaller & faster option to Tripwire
  • VPS
    a linux-based VPN solution for connecting disparate networks securely over the internet. Using this software, you can connect multiple networks to each other without having to pay for expensive leased lines or dedicated connections
  • wipe
    a little command for securely erasing files from magnetic media. It compiles under various UNIX platforms, including Linux 2.0, AIX 4.1, SunOS 5.5.1
  • wipe
    a secure file wiping utility. however, it does not set the media access bit on scsi commands, therefore it is not 100% secure unless your drive has no write cache
  • XML Security Suite
    provides security features such as digital signature, element-wise encryption, and access control to Internet business-to-business transactions
  • yyyRSA
    a simple program to encrypt and decipher messages with the RSA asymetrical encryption algorithm
  • Zebedee
    a simple program to establish an encrypted, compressed TCP/IP "tunnel" between two systems. This allows TCP-based traffic such as telnet, ftp and X to be protected from snooping as well as potentially gaining performance over low-bandwidth networks from compression
  • Zodiac
    a DNS protocol analyzation and exploitation program. It is a robust tool to explore the DNS protocol
Category:  
About | Advertise | FAQ | Press Releases | LinkBack | Privacy | Awards
Pages Updated: 22-Aug-2000
Please email us with your comments about this site