network security news, articles, tools, links...
Dropped here by your search engine? Use the same keyword in the google box below to search this site.




























| Build your own gateway firewall |

Learn how to build your own gateway firewall using FreeBSD and old PC parts. The firewall will consist of the PF firewall, Snort IDS, various IPS applications, Squid proxy, and some intuitive web interfaces for auditing. The cost of this project should be between free and $200 depending on your resourcefulness. I built mine for free using spare parts that were stockpiled in personal storage and parts that the USMC was throwing away, but you can build one from used and/or new parts for dirt cheap.
(...Read more)| Home Network Router Security Secrets |

Most people who install a home network never delve inside the netherworld of security settings on their router. Who can blame them it's about as frightening as putting your hand in a shoebox full of rabid gerbils. Nevertheless, it's worth the effort if you know what you're doing.
That said, here are 10 router settings you can use to make your network more secure. For the purposes of this article, I used a popular router, the DLink DI524, to show you how to engage the features, because this router doesn't bite usually.
(...Read more)That said, here are 10 router settings you can use to make your network more secure. For the purposes of this article, I used a popular router, the DLink DI524, to show you how to engage the features, because this router doesn't bite usually.
| 10 things you should know about working with NTFS permissions |

NTFS and share level permissions both affect the user's ability to access resources on a network, and you need a good understanding of both types to untangle and resolve certain access issues. These tips and best practices will help you avoid some typical problems.
Managing and troubleshooting permissions can be challenging, especially when everything looks like it should work. These tips and best practices will help you avoid some common problems.
(...Read more)Managing and troubleshooting permissions can be challenging, especially when everything looks like it should work. These tips and best practices will help you avoid some common problems.
| Windows to Ubuntu Transition Guide |

Since this article's intent is to be a beginner's guide to Ubuntu Linux, I am going to be using the graphical interface for pretty much everything. As experienced Linux users may know, and you will soon find out, everything we are going to be doing can be done much quicker through the command line. Of course, this is not very user friendly, and a very un-Windows way to do things, so again, we will be sticking to the Ubuntu GUI (Graphical User Interface).
As you are reading, please bear in mind that Linux is not Windows. At a high level they appear to operate basically the same, but they are fundamentally different. Just keep an open mind and I promise learning Ubuntu Linux will be well worth your time.
(...Read more)As you are reading, please bear in mind that Linux is not Windows. At a high level they appear to operate basically the same, but they are fundamentally different. Just keep an open mind and I promise learning Ubuntu Linux will be well worth your time.
| Email Security Guide |

This All in One Guide is a collection of resources to help you secure your email systems regardless of where you are in the learning or buying process. If you're new to securing email, we recommend you start at the beginning with our Security School covering fundamental issues. If you're shopping for technology, skip ahead to the sections on evaluating your options, product reviews and engaging vendors.
If you're currently managing email security technology, check out the section on post implementation issues. In each section, we'll logically guide you through our resources to maximize your learning experience.
(...Read more)If you're currently managing email security technology, check out the section on post implementation issues. In each section, we'll logically guide you through our resources to maximize your learning experience.
| Encryption for the masses |

File and disk encryption needs to be simple and easy if it's going to be used. This article looks at Apple's FileVault and takes a sneak peak at what's coming in Windows Vista.
A few weeks ago there was a knock at my door, and my new MacBook Pro laptop had arrived. I was very excited, because it's one of the first of the new Intel-based dual core systems available. Yes, it's fast....
(...Read more)A few weeks ago there was a knock at my door, and my new MacBook Pro laptop had arrived. I was very excited, because it's one of the first of the new Intel-based dual core systems available. Yes, it's fast....
| Guide to Network Security |

These days, computer security is a serious and complex business. True security requires the coordination of staff and technology across the enterprise infrastructure, as well as educated and cooperative users. But even the best of information security policies and plans will fail if the underlying network is not secure. You may think you are doing all you can to protect your network, but think again.
(...Read more)| Optimizing Internet Explorer security settings |

Coming up with the optimal Internet Explorer security settings is tricky business. On one hand, you want to set security tightly enough that your network won't become infected with spyware should your users accidentally stumble upon a malicious Web site. On the other hand, the more that you tighten security, the better the chances that some Web sites will not display properly.
Unfortunately, Microsoft has not published any documents (that I could find) related to optimal Internet Explorer security settings. Therefore, the settings that I am going to show you are my own recommendations and may not be appropriate for all organizations.
(...Read more)Unfortunately, Microsoft has not published any documents (that I could find) related to optimal Internet Explorer security settings. Therefore, the settings that I am going to show you are my own recommendations and may not be appropriate for all organizations.
| Manage user credentials in Windows XP with the Stored User Names and Passwords tool |

You can view or change any of the user credentials in your Windows XP system by saving them to your user profile. Log on to your machine and have all your IDs at the ready! Greg Shultz gives us the identifying information.
When you log in to your Windows XP system and supply a username and a password, the operating system stores this information as your user credentials. When you connect to other computers in your workgroup or on the Internet that require a username and password, Windows XP will attempt to use your existing user credentials to make an authenticated connection.
(...Read more)When you log in to your Windows XP system and supply a username and a password, the operating system stores this information as your user credentials. When you connect to other computers in your workgroup or on the Internet that require a username and password, Windows XP will attempt to use your existing user credentials to make an authenticated connection.
| Nine ways to lock down Windows 2000 Server |

Even though using Windows Server 2003 is in vogue, a lot of shops are still running Windows 2000 Server and with good reason. It was a pretty solid release, with a lot of useful features, and the improvements in Windows Server 2003, while nice, weren't compelling enough for some companies to make the jump. However, as with any older operating system, security is a concern that grows with each passing day. Here are some tips on thwarting threats against your Windows 2000 Server machines.
(...Read more)| Program Teaches Kids About Cyber Security |
A group of students at Rome Catholic School are learning how to become the future defenders of cyberspace through a pilot program that officials say is the first of its kind in the country. The program teaches students about data protection, computer network protocols and vulnerabilities, security, firewalls and forensics, data hiding, and infrastructure and wireless security.
(...Read more)| Why All Networked PCs Need Anti Virus Software |

Many computer owners mistakenly think that if they run anti virus software on the computer connected to the Internet then all PCs on the network are protected. However, if you use Microsoft's Internet Connection Sharing (ICS) and Internet Connection Firewall (ICF)programs to share a DSL or cable modem line with several PCs, you need to use anti-virus to protect each PC.
Even though only one PC is directly connected to the Internet, any system with Internet access is capable of accidentally downloading or opening virus infected files. For that reason, it's absolutely imperative that you install a good anti virus package on all of your computers.
(...Read more)Even though only one PC is directly connected to the Internet, any system with Internet access is capable of accidentally downloading or opening virus infected files. For that reason, it's absolutely imperative that you install a good anti virus package on all of your computers.
| Hacking your Linksys WRT54G, Changing to 3rd party firmware |

First off, if you don't have a stateful packet inspection firewall/router protecting your broadband connection, you should get one. For those needing wireless support and want good security, I highly suggest the Linksys WRT54G family of wireless routers. I recommend them because they are solid boxes and one of the few wireless routers I have found that do stateful packet inspection.
(...Read more)| Troubleshooting Windows Firewall settings in Windows XP SP2 |

Microsoft Windows XP Service Pack 2 (SP2) includes Microsoft Windows Firewall, the updated firewall software that replaces Internet Connection Firewall (ICF). If Microsoft Windows Firewall is blocking a port that is used by a service or by a program, you can configure the Windows Firewall to create an exception. Windows Firewall may be blocking a program or a service if the following conditions are true:
? Programs do not respond to a client's request.
? Client programs do not receive data from the server.
A Windows Firewall Security Alert may notify you that Windows Firewall is blocking a particular program.
(...Read more)? Programs do not respond to a client's request.
? Client programs do not receive data from the server.
A Windows Firewall Security Alert may notify you that Windows Firewall is blocking a particular program.
| CERT: Windows Intruder Detection Checklist |

This document outlines suggested steps for determining whether your Windows system has been compromised. System administrators can use this information to look for several types of break-ins. We also encourage you to review all sections of this document and modify your systems to address potential weaknesses.
This document does not provide intrusion detection methods for Windows 9x (including Windows ME). These operating systems lack the underlying subsystems necessary to secure them and should not be used in a commercial environment or on workstations where data is considered critical.
(...Read more)This document does not provide intrusion detection methods for Windows 9x (including Windows ME). These operating systems lack the underlying subsystems necessary to secure them and should not be used in a commercial environment or on workstations where data is considered critical.
| Sam 0wn3d How to crack SAM File and own Windows |

Instead of storing passwords in clear-text, Windows generates and stores user account passwords by using two different password representations, known as "hashes." The SAM file could be found in the folder c:\Windows\system32\config. However it cannot be accessed because the operating system locks the file. In this article I will discuss various methods that can be used to crack SAM and own the server.
(...Read more)| WiFi Security at Work and on the Road |

Whenever you communicate over the Internet using a wired or wireless connection, you may want to ensure that your communications and files are private and protected. If your transmissions are not secure, you take the risk of others intercepting your business e-mails, examining your corporate files and records, and using your network and Internet connection to distribute their own messages and communications.
How secure you want your network to be depends on how you use the Internet. If you're just surfing to do research or watch movies, you may not care if anyone picks up part of the transmission, but that's up to you.
(...Read more)How secure you want your network to be depends on how you use the Internet. If you're just surfing to do research or watch movies, you may not care if anyone picks up part of the transmission, but that's up to you.
| Protect Your Data Effectively and Safely with EFS |

Microsoft Windows XP comes with the ability to securely encrypt your data so that nobody but you will be able to access or view the files. This encryption is called EFS, or Encrypted File System.
Note: Windows XP Home edition does not come with EFS. To secure or protect data with encryption on Windows XP Home, you will need to use a 3rd-party encryption software of some sort.
(...Read more)Note: Windows XP Home edition does not come with EFS. To secure or protect data with encryption on Windows XP Home, you will need to use a 3rd-party encryption software of some sort.
| Computer Security for the Novice |

Computer technology has changed quite a bit over the past 20 years. People who would normally never touch a computer now utilize such a device almost every day to get their work done. They use email and surf the web regularly. These folks all need to take computer security seriously.
Recently, I've been watching users and how they interact with their computers, and I've been asking them questions about their computer usage. I asked them about their knowledge of the subject in general, and specifically I asked them about security. Very few of them really knew much about computing in general and practically none of them knew anything about security. 20 years ago this may not have been as much of a problem, but in today's world of online banking and identity theft, this can be a huge problem.
(...Read more)Recently, I've been watching users and how they interact with their computers, and I've been asking them questions about their computer usage. I asked them about their knowledge of the subject in general, and specifically I asked them about security. Very few of them really knew much about computing in general and practically none of them knew anything about security. 20 years ago this may not have been as much of a problem, but in today's world of online banking and identity theft, this can be a huge problem.
| What To Look For In Antivirus Software |

With up to 100 new malware threats being discovered per day, antivirus software is, for many home computer users, the primary method for protecting their computer from threats.
Many computers come with some sort of antivirus software, often a trial version, installed. Unfortunately, many users fail to properly configure the antivirus software or keep it up to date, and many may let the antivirus software expire without even realizing their computer is no longer protected against current malware threats.
(...Read more)Many computers come with some sort of antivirus software, often a trial version, installed. Unfortunately, many users fail to properly configure the antivirus software or keep it up to date, and many may let the antivirus software expire without even realizing their computer is no longer protected against current malware threats.
| Wireless Security while Roving |

John Doe checks in at the airport terminal thirty minutes early. He decides to check on a few things so he opens his laptop thinking how great wireless is. First, he checks home to see if the new nanny has gotten the baby her breakfast. He checks the baby?s room first and seeing nothing moves on to the kitchen where he sees the nanny just finishing feeding the baby. Feeling good, he decides to check on his son at school.
He logs onto the school website and enters his password. His computer screen shows his son and classmates classroom working hard on an assignment. Next he wonders if his wife has made it to her appointment. As a pharmaceutical representative, she is often required to travel throughout the state . John enters the web address then password to access the GPS interface site. The report and map shows her pulling into the parking lot of her first appointment of the morning. Encouraged that the morning is going so smoothly, John next checks his e-mail. Immediately an urgent message catches his attention. His secretary informs him a caller complained after seeing one of the company?s distinctive red and white trucks speeding down a residential street.
(...Read more)He logs onto the school website and enters his password. His computer screen shows his son and classmates classroom working hard on an assignment. Next he wonders if his wife has made it to her appointment. As a pharmaceutical representative, she is often required to travel throughout the state . John enters the web address then password to access the GPS interface site. The report and map shows her pulling into the parking lot of her first appointment of the morning. Encouraged that the morning is going so smoothly, John next checks his e-mail. Immediately an urgent message catches his attention. His secretary informs him a caller complained after seeing one of the company?s distinctive red and white trucks speeding down a residential street.
| I installed my Home Wireless Network and my neighbor was using it |

There are many reasons why you may want to install a wireless network at your home or office. Some people just like the freedom that wireless networking provides. If you use a laptop, being able to move from the office, to the family room, to the deck is a unshackling experience. Others turn to wireless networking to overcome obstacles like structural challenges. In many older homes and offices the walls are not so easy to run network cables in. Even if you are able to run network cables in your home or small office there is the cost of doing so. Usually many times more expensive than installing a wireless network. Then there are those, like many of us (like me), who absolutely must have the latest and greatest gadgets on the market.
(...Read more)| 6 easy steps to help secure your home wireless |

Securing your home wireless isn't that difficult, but it can take a few extra steps to accomplish. Before I get into this let me say that I'm by no means an expert in wireless security, these are just some suggestions that I have seen and have implemented on my own network at home. I'm going to use my equipment as an example and that is all it is, an example. Most of the suggestions will work on most wireless routers, but you may have to consult the manual on exactly how to configure your device. With that said here are a few ways to secure your wireless home network.
Most of the wireless routers that people have at home come with some defaults turned on that will allow easy access to your system by the snooping onlooker. These defaults are all too often left unchanged and this can be a problem. So let's start with what a few things to update and/or change.
(...Read more)Most of the wireless routers that people have at home come with some defaults turned on that will allow easy access to your system by the snooping onlooker. These defaults are all too often left unchanged and this can be a problem. So let's start with what a few things to update and/or change.
| Introduction to Network Security |
Network security is a complicated subject, historically only tackled by well-trained and experienced experts. However, as more and more people become ``wired'', an increasing number of people need to understand the basics of security in a networked world. This document was written with the basic computer user and information systems manager in mind, explaining the concepts needed to read through the hype in the marketplace and understand risks and how to deal with them.
Some history of networking is included, as well as an introduction to TCP/IP and internetworking . We go on to consider risk management, network threats, firewalls, and more special-purpose secure networking devices.
This is not intended to be a ``frequently asked questions'' reference, nor is it a ``hands-on'' document describing how to accomplish specific functionality. It is hoped that the reader will have a wider perspective on security in general, and better understand how to reduce and manage risk personally, at home, and in the workplace.
(...Read more)Some history of networking is included, as well as an introduction to TCP/IP and internetworking . We go on to consider risk management, network threats, firewalls, and more special-purpose secure networking devices.
This is not intended to be a ``frequently asked questions'' reference, nor is it a ``hands-on'' document describing how to accomplish specific functionality. It is hoped that the reader will have a wider perspective on security in general, and better understand how to reduce and manage risk personally, at home, and in the workplace.
| Improving Home Network Security with Windows XP |

If you have more than one computer connected at home, then you have a home network. Home networks make it easier to share Internet access, files, printers, and more. Unfortunately, networks also make it easier for hackers, viruses, and worms to intrude on your privacy. Windows XP Service Pack 2 (SP2) contains a number of improvements that help protect your security, especially on a home network. Read on to find out more about how your new or existing home network will be protected.
(...Read more)| A Practical Guide to Basic Security in Linux Production Systems |

This Linux Security HOWTO is intended for a technical audience, Linux system administrators, and security people in corporations and organizations that have to use commercial Linux distributions in production. The main objective for this Linux Security guide is to discuss basic Linux security requirements for production systems that are being audited. This document covers various system services like SSH which are usually enabled on most Linux production servers. However, this article does not cover services like Apache, Samba etc. since these services are usually not needed on all production systems. Also, this article does not cover various security features that require kernel patching. For most companies this is not an option due to support issues.
(...Read more)| Best Practices for Wireless and Mobile Security |

Featured speaker, Jack Gold of META Group will be presenting his latest research on the mobile and wireless market. Additionally, iAnywhere will be presenting some case studies. The presentation will help answer critical questions like:
* What are the best practices for securing laptops and handhelds
* Why managed security is a necessity
* How to protect the enterprise when introducing mobile devices
* How to mitigate risks
* How to enforce security policies
* What are the common unforeseen risks of mobile/wireless deployments
(...Read more)* What are the best practices for securing laptops and handhelds
* Why managed security is a necessity
* How to protect the enterprise when introducing mobile devices
* How to mitigate risks
* How to enforce security policies
* What are the common unforeseen risks of mobile/wireless deployments
| 15 Minutes to Complete Data Protection |
Is your network data really safe? Despite having the best security devices deployed, many high profile organizations have recently had their valuable customer data stolen. Most organizations' valuable data is still sent in the clear, open for exploitation. As networks expand, this practice becomes more perilous and the risk of data loss increases.
So, how do you approach securing that dynamic data? According to best practices espoused by top security experts, encrypting the data in motion over the network is key to protecting it. Download this paper to learn how you can quickly and easily protect all of your data in motion within just 15 minutes with revolutionary new technology that is ideally suited to protecting data for storage, wireless and LAN campus networks.
(...Read more)So, how do you approach securing that dynamic data? According to best practices espoused by top security experts, encrypting the data in motion over the network is key to protecting it. Download this paper to learn how you can quickly and easily protect all of your data in motion within just 15 minutes with revolutionary new technology that is ideally suited to protecting data for storage, wireless and LAN campus networks.
You are browsing the old version of "The Network Security. Org", Please
click here to visit the
new version.
Categories
Web Security
Basic Security
Network Tools
Archived Articles
Wireless Security
Networking Basics
Disaster Recovery
Enterprise Security
Intrusion Detection
More Archived Articles
Exploits & Vulnerabilities
Viruses & other Malware
Basic Security
Network Tools
Archived Articles
Wireless Security
Networking Basics
Disaster Recovery
Enterprise Security
Intrusion Detection
More Archived Articles
Exploits & Vulnerabilities
Viruses & other Malware