Archive for the ‘LINKS’ Category.

John Taylor Gatto

Deploying your web app on Tomcat

FreeBSD FreeBSD-SA-01:33: globbing vulnerability in ftpd

Security Flaw with Linux 2.4 Kernel and IPTables

Tempest Security Advisory:
Security Flaw with Linux 2.4 Kernel and IPTables [via Slashdot]

Security Advisory – #01/2001

Security flaw in Linux 2.4 IPTables using FTP PORT

Author: Cristiano Lincoln Mattos, CISSP, SSCP
Systems affected: Firewalls using Linux Kernel 2.4.x with IPTables

Release date: 16 April 2001

Platforms: Linux Kernel 2.4.x

Impact: If an attacker can establish an FTP connection passing through a Linux 2.4.x IPTables firewall with the state options allowing “related” connections (almost 100% do), he can insert entries into the firewall’s connection tables…

Anti-Hacking premiums 25% higher for Win NT

United States v. Hubbell: Encryption and the Discovery of Documents

Techies Learn to Go It Alone

Techies Learn to Go It Alone. Rensselaer Polytechnic Institute receives a $1 million donation to pump up entrepreneurship at the university. Also: Black colleges assess their information technology goals…. [Wired News]

SecurityPortal: Ask Buffy – ports; log search tools, DNS – UDP or TCP

From SecurityPortal: Ask Buffy – ports; log search tools, DNS – UDP or TCP [via Linux Today]:

Log Tool

We have all these NT 4.0 logs, but it there a tool that can help sift
through information and present it with meaning? With regard to security,
I just want to get to the information that I need. I need to get to this
information quickly. Do you have any suggestions?

Kevin M Moker

 

This is a subject for which there is a ton of information available.
There is an excellent FAQ available at:

http://www.heysoft.de/nt/eventlog/faq.htm

And an entire book on the subject available from O’Reilly:

http://www.oreilly.com/catalog/winlog/

As for actual products that will monitor your log files and respond to
events, there are several dozen solutions; for example:

http://www.sql-server-performance.com/event_log_monitor.asp

http://www.ipsentry.com/dlfiles/addins/ipsevmon.htm

http://www.eventreporter.com/

You can also export NT event logs, using a variety of products, to UNIX
syslog machines and use your favorite syslog monitoring tool.

Buffy (buffy@securityportal.com)

Security for Web Database Applications

Security for Web Database Applications. You know you want to protect yourself, and your database. Here’s how. [WebReview.com]

Why UDDI Will Succeed, Quietly