http://www.Linux-Sec.net




  • Hardening-Tightening

    Security_Policy

  • Hardening-HOWTO

    Linux Distros

    Distro Patches

    Kernel-Patches

    Dedicated Servers
  • Firewalls
  • DNS Servers
  • Mail Servers
  • Web Servers

    Turn-Off Daemons

    Tighten Inetd Services


  • Top-10 Vulnerabilities

    Top-7 Security Mistakes

    Top-10 Vulnerabilities

    Top-20 Most Critical Vulnerability


    Top-10 Virus


  • Scans/Attacks Stats

    Top-10 Attacks

    Hacked Servers


  • One Minute Audits
  • OpenPorts Audit


    AntiVirus - AntiSpam
  • Anti-Spam
  • Anti-Virus

  • spam.wav


    Wireless [In]Security
  • Sniffers


  • Security Tools

    SSH_SSL

    Firewalls

    MailServer

    FileSystem

    VPN

    Port Scan Detectors

    IDS Tools

    LogFile Analysis

    Ethernet Monitoring

    Server Monitoring

    Tracking & Forensics


  • Hackers Tools

    Audit Tools

    Port Scanners

    Hacking Tools

    Sniffer Tools

    Exploits & Vulnerbilities


  • Wireless

    Wireless [In]Security


  • Misc

    Statistics

    Linux/BSD Distros

    Links,Articles,WatchDogs

    Security Mailing Lists/FAQs

    Liability Insurance



  • 1U Rackmount Chassis

    Custom-Chassis.com

    Linux-1U.net

    1U-ITX.net


    ITX-Blades.net


    Small PC cases

    Mini-Box.net

    Wrap-Box.net

    Wrap-OS.net


    Wan-Sim.net



    Linux-Consulting.com

    Linux-CAE.net

    Linux-Sec.net

    Linux-Boot.net

    Linux-Backup.net

    Linux-Wireless.org

    Linux-Office.net

    Linux-Video.net

    Linux-Jobs.net

    Linux-Diff.net

    1U-Raid5.net


    Spam Reporting



    Free Linux CDs

    ISO9660.org

    Distro-CD.org

    Patch-CD.org




    Contact



    Linux is a registered trademark of
    Linus Torvalds

    More Linux Legalese


    Linux-Sec.net/Exploits


    Top-10 Common Security Mistakes

    Our Definition and Differences
    ( Exploits, Audits, PenTest, Vulnerabilities )


    Mailing Lists


    Exploits
    Server Exploits Daemon Exploits User Exploits Policy Exploits

    Vulnerability

    Audit

    Hacking Tools

    PenetrationTest


    RootKits



    DoS Testing

    SYN Attacks
    • Minimize SYN attacks
        echo 4096 >/proc/sys/net/ipv4/tcp_max_syn_backlog
        - or -
        /etc/sysctl.conf:
          # Reduce SYN Floods
          net.ipv4.tcp_max_syn_backlog=4096

      Cisco TCP SYNC DoS Attacks
      Cisco

    Ping Attacks
    • Minimize Ping Attacks ( and Smurfing innocent other target victims )
        echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts

    • Disable Ping attacks at the cisco router
        ...
        interface Serial0
          no ip directed-broadcast

      Insecure.org Ping-of-Death
      SourceForge.net hping2 - spoofing
      COTSE.com ping tools

    Smurf Attacks


    Copyright © 2000
    Linux-Consulting
    All Rights Reserved.
    Updated: Sun Nov 21 23:51:59 2004 PDT