
Dias atrás em um cliente fizemos uma revisão de conceitos, tecnologias e softwares importantes na área de segurança física e computacional. Chamamos isto de Sprint e estamos realizando este tipo de serviço consultivo com mais freqüência em alguns clientes. Tópicos para Sprints incluem Segurança, Infra-Estrutura, Virtualização, Gerenciamento de Projetos e outras áreas de atuação da Franciosi Consultoria. Os objetivos são a revisão de conceitos, tecnologias atuais e melhores práticas nos assuntos selecionados.
Abaixo uma lista de links interessantes do último Sprint de Segurança. Sugerimos agendarem algumas horas, juntarem suas equipes de infra-estrutura/segurança e visitar cada um deles.
Referências Obrigatórias do CERT.BR/NIC.BR
- Práticas de Segurança para Administradores de Redes Internet
- Cartilha de Segurança para Internet: A Cartilha de Segurança para Internet contém recomendações e dicas sobre como o usuário pode aumentar a sua segurança na Internet. O documento apresenta o significado de diversos termos e conceitos utilizados na Internet e fornece uma série de procedimentos que visam melhorar a segurança de um computador.

Blogs
- Forensic Focus
- Forensic Incident Response
- Microsoft Security Response Center Blog
- Oracle Security Alerts
- pentestmonkey.net
- Schneier on Security
- TaoSecurity
Distros/Software
- Aircrack-ng: aircrack is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured.
- Anonym.OS LiveCD: kaos.theory’s Anonym.OS LiveCD is a bootable live cd based on OpenBSD that provides a hardened operating environment whereby all ingress traffic is denied and all egress traffic is automatically and transparently encrypted and/or anonymized.
- Arpwatch: Arpwatch is open-source software that monitors a computer network for ARP-activity.
- BackTrack: BackTrack is the most Top rated linux live distribution focused on penetration testing.
- BlueProximity: Add security to your desktop by automatically locking and unlocking the screen when you and your phone leave/enter the desk. Think of a proximity detector for your mobile phone via bluetooth.
- BrazilFW Firewall and Router
- Bro Intrusion Detection System: Bro is an open-source, Unix-based Network Intrusion Detection System (NIDS) that passively monitors network traffic and looks for suspicious activity.
- Driftnet: Driftnet is a program which listens to network traffic and picks out images from TCP streams it observes.
- Edge-Security
- Eraser: Eraser is an advanced security tool (for Windows), which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
- FreeRADIUS: The world’s most popular RADIUS Server.
- fwsnort: fwsnort parses the rules files included in the Snort intrusion detection system and builds an equivalent iptables ruleset for as many rules as possible.
- Inguma: A Free Penetration Testing and Vulnerability Research Toolkit.
- IPCop.org: Security distro.
- Medusa Parallel Network Login Auditor: Medusa is intended to be a speedy, massively parallel, modular, login brute-forcer. The goal is to support as many services which allow remote authentication as possible.
- Microsoft Cryptographic Service Providers
- Microsoft Security Assessment Tool
- milw0rm: exploits : vulnerabilities : videos : papers : shellcode
- Network Security Toolkit: The toolkit was designed to provide easy access to best-of-breed Open Source Network Security Applications and should run on most x86 platforms.
- Nmap: Nmap (”Network Mapper”) is a free and open source (license) utility for network exploration or security auditing.
- ophcrack: Ophcrack is a Windows password cracker based on rainbow tables.
- Proxifier: Proxifier is a program that allows network applications that do not support working through proxy servers to operate through an HTTPS or SOCKS proxy or a chain of proxy servers.
- Sguil: The Analyst Console for Network Security Monitoring
- Tcpreplay: Tcpreplay is a suite of tools which gives you the ability to use previously captured traffic in libpcap format to test a variety of network devices.
- tcptrack: tcptrack is a sniffer which displays information about TCP connections it sees on a network interface.
- Top 100 Network Security Tools
- Tor: anonymity online: Tor is a software project that helps you defend against traffic analysis, a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security.
- Umit, the nmap frontend
- Wfuzz - The web bruteforcer: Wfuzz is a tool designed for bruteforcing Web Applications, it can be used for finding resources not linked (directories, servlets, scripts, etc), bruteforce GET and POST parameters for checking different kind of injections (SQL, XSS, LDAP,etc), bruteforce Forms parameters (User/Password), Fuzzing,etc.
Documentação/Misc
- Anonymous Surfing & Free Proxy List
- Autoridade Certificadora do Estado do Rio Grande do Sul
- Brazilian Honeypots Alliance
- BS 25999 [Wikipedia]
- Business Continuity, Contingency Planning & Disaster Recovery
- Comparing MBSA, MU, WSUS, Essentials 2007 and SMS 2003 [Microsoft]
- CVE: CVE International in scope and free for public use, CVE is a dictionary of publicly known information security vulnerabilities and exposures.
- Debian Security Bug Tracker
- Default Password List
- Disaster Recovery Journal
- Establishing a VPN between OpenSWAN and a PIX firewall
- Fundamental Computer Investigation Guide for Windows [Microsoft]
- Information Security Management Maturity Model
- ISO/IEC 27001 [Wikipedia]
- Malware Block List: The Malware Block List is a free, automated and user contributed system for checking URLs for the presence of Viruses, Trojans, Worms, or any other software considered Malware.
- Malware Threat Center: Welcome to the Malware Threat Center. The data produced on this site is automatically generated each morning, and summarizes our latest observations of malware activity. We provide you this data as is, and without warranty, for your personal research purposes.
- MITRE: The MITRE Corporation is a not-for-profit organization chartered to work in the public interest. As a national resource, we apply our expertise in systems engineering, information technology, operational concepts, and enterprise modernization to address our sponsors’ critical needs.
- OpenPacket.org: Welcome to the new website. OpenPacket.org is a Web site whose mission is to provide a centralized repository of network traffic traces for researchers, analysts, and other members of the digital security community.
- OWASP: The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Our mission is to make application security “visible,” so that people and organizations can make informed decisions about application security risks.
- Open Resolver Test
- Paper shredder [Wikipedia]
- PhishTank: PhishTank is a collaborative clearing house for data and information about phishing on the Internet.
- Sarbanes-Oxley Act Forum
- Securing Wireless LANs with PEAP and Passwords [Microsoft]
- SOMAP.org: Security Officers Management & Analysis Project.
- VulnerabilityAssessment.co.uk: An information portal for Vulnerability Analysts and Penetration Testers alike.
- Vulnerable source packages in the testing suite: Debian Testing.
- WirelessDefence.org’s Wireless Penetration Testing Framework
