http://Linux-Sec.net




  • Hardening-Tightening

    Security_Policy

  • Hardening-HOWTO

    Linux Distros

    Distro Patches

    Kernel-Patches

    Dedicated Servers
  • Firewalls
  • DNS Servers
  • Mail Servers
  • Web Servers

    Turn-Off Daemons

    Tighten Inetd Services


  • Top-10 Vulnerabilities

    Top-7 Security Mistakes

    Top-10 Vulnerabilities

    Top-20 Most Critical Vulnerability


    Top-10 Virus


  • Scans/Attacks Stats

    Top-10 Attacks

    Hacked Servers


  • One Minute Audits
  • OpenPorts Audit


    AntiVirus - AntiSpam
  • Anti-Spam
  • Anti-Virus

  • spam.wav


    Wireless [In]Security
  • Sniffers


  • Security Tools

    SSH_SSL

    Firewalls

    MailServer

    FileSystem

    VPN

    Port Scan Detectors

    IDS Tools

    LogFile Analysis

    Ethernet Monitoring

    Server Monitoring

    Tracking & Forensics


  • Hackers Tools

    Audit Tools

    Port Scanners

    Hacking Tools

    DDOS Tools

    Sniffer Tools

    Spoof Tools

    Exploits & Vulnerbilities


  • Wireless

    Wireless [In]Security


  • Misc

    Statistics

    Linux/BSD Distros

    Links,Articles,WatchDogs

    Security Mailing Lists/FAQs

    Liability Insurance



  • 1U Rackmount Chassis

    Custom-Chassis.net

    Linux-1U.net

    1U-ITX.net


    ITX-Blades.net


    Small PC cases

    Mini-Box.net

    Wrap-Box.net

    Wrap-OS.net


    gigEnn.net

    WanSim.net



    Linux-Consulting.com

    Linux-CAE.net

    Linux-Sec.net

    Linux-Boot.net

    Linux-Backup.net

    Linux-Wireless.org

    Linux-Office.net

    Linux-Video.net

    Linux-VOIP.net

    Linux-Jobs.net

    Linux-Diff.net

    1U-Raid5.net

    Linux-Howto.net


    Spam Reporting



    Free Linux CDs

    ISO9660.org

    Distro-CD.org

    Patch-CD.org




    Contact



    Linux is a registered trademark of
    Linus Torvalds

    More Linux Legalese


    Linux-Sec.net/Audit


    Top-10 Common Security Mistakes

    Our Definition and Differences
    ( Exploits, Audits, PenTest, Vulnerabilities )


    Mailing Lists


    Exploits


    Vulnerability


    Audits
    Network Audits
    Server Audits
    Policy Audits


    Hacking Tools

    PenetrationTest


    RootKits



    Password Policy

    • Passwords should be:
      • passwords should have a combination of numbers, letters and punctuation
      • passwords should be 8 characters or longer
      • passwords should NOT be listed as words in (foreign) dictionaries
        • it'd just take a few seconds to guess your dictionary based password
      • passwords should expire and should be rotated
      • passwords should be computer generated but people cannot easily remember it
      • if you have to write down your passwords, do NOT write down what/where its for
      • if you have to write down your passwords, keep it encrypted
      • password-less computer systems are very bad ...
          break into one system and you have free access to "everything"

    • it is well known and common sense that:
      • people tend to re-use passwords they can easily remember
        • birthdays, names of spouses, family members, pets, coworkers, hobbies ..
      • people tend to re-use their same password to gain access to their computers at work and at home, online shopping sites, online banking including ATM PIN#
      • people tend to write down their passwords on paper, computers and/or cell phone
        • passwords are usually found under the computer, under the keyboard, under the drawers, on the monitors, on the back of business cards ..
      • people tend NOT to encrypt and protect this confidential data
      • people tend to sign up for online forums/blogs and still use confidential password used for work
      • people tend NOT to pay attention to encrypted https login vs clear text http websites
      • corporations/people tend to send new passwords via un-encrypted emails and un-encrypted web pages
      • your passwords can be sniffed by anybody from anywhere in the world

    Passwd Auditing Tools

    Check FileSystem


    Copyright © 2000
    Linux-Consulting
    All Rights Reserved.
    Updated: Sun Apr 22 17:54:38 2012 PDT