domingo, mayo 25, 2008

Lista de distros linux de seguridad - securitydistro

Security Distros
Here is the full list of Security Distros and their descriptions. Select the tool that best fits your needs.

BackTrack

BackTrack is a distribution based off of what used to be WHAX and Auditor . It is a full size distro built off of SLAX.
BackTrack Main Discuss Download Status: Active

Damn Vulnerable Linux ( DVL )

"Damn Vulnerable Linux (DVL) is a Linux-based tool for IT-Security. It was initiated for training tasks during university lessons by the IITAC (International Institute for Training, Assessment, and Certification) and S²e - Secure Software Engineering in cooperation with the French Reverse Engineering Team." - DamnVulnerableLinux.org
Damn Vulnerable Linux ( DVL ) Main Discuss Download Status: Active

DEFT

DEFT (acronym of "Digital Evidence & Forensic Toolkit) is a customized distribution of the Kubuntu live Linux CD. It is a very easy to use system that includes an excellent hardware detection and the best open source applications dedicated to incident response and computer forensics. -Deft.yourside.it
DEFT Main Discuss Download Status: Active

FCCU

The Gnu/Linux boot CD-Rom is made by the Belgian Federal Computer Crime Unit (FCCU)
It's based on the KNOPPIX Live CD version 4.02 by Klaus Knopper.
The main purpose of the CD : help the forensic analyze of computers
All scripts made by the FCCU begin with the "fccu" prefix -lnx4n6.be
FCCU Main Download Status: Active

Frenzy

"Frenzy is a "portable system administrator toolkit," LiveCD based on FreeBSD. It generally contains software for hardware tests, file system check, security check and network setup and analysis. Size of ISO-image is 200 MBytes (3" CD)"
-http://frenzy.org.ua/eng/
Frenzy Main Discuss Download Status: Active

grml

"grml is a bootable CD (Live-CD) based on Knoppix and Debian. grml includes a collection of GNU/Linux software especially for users of texttools and system administrators. grml provides automatic hardware detection. You can use grml for example as a rescue system, for analyzing systems/networks or as a working environment." -http://grml.org/
grml Main Discuss Download Status: Active

Hakin9

"a bootable distribution containing all the tools and materials needed for practising methods and techniques described in the hackin9 magazine"
-http://www.hakin9.org/en/index.php?page=hakin9_live-
Hakin9 Main Discuss Download Status: Active

Helix

"Helix is a customized distribution of the Knoppix Live Linux CD. Helix is more than just a bootable live CD. You can still boot into a customized Linux environment that includes customized linux kernels, excellent hardware detection and many applications dedicated to Incident Response and Forensics."
-http://www.e-fense.com/helix/-
Helix Main Discuss Download Status: Active

HeX

HeX is a live security distribution that focuses on security monitoring and forensics.
HeX Main Discuss Download Status: Active

KCPentrix

" The Kcpentrix Project was founded in May 2005 , KCPentrix 1.0 was liveCD designed to be a standalone Penetration testing toolkit for pentesters, security analysts and System administrators" - KCPentrix.com
KCPentrix Main Discuss Download Status: Active

Knoppix-NSM

"knoppix-nsm is dedicated to providing a framework for individuals wanting to learn about Network Security Monitoring or who want to qucikly and reliably deploy NSM in their network. Our goal is to provide an introduction to NSM and a distribution that can be used as a launch pad to bigger things." -www.securixlive.com
Knoppix-NSM Main Discuss Download Status: Active

Network Security Toolkit ( NST )

"This bootable ISO live CD is based on Fedora. The toolkit was designed to provide easy access to best-of-breed Open Source Network Security Applications and should run on most x86 platforms." -networksecuritytoolkit.org
Network Security Toolkit ( NST ) Main Discuss Download Status: Active

nUbuntu

"The main goal of nUbuntu is to create a distribution which is derived from the Ubuntu distribution, and add packages related to security testing, and remove unneeded packages, such as Gnome, Openoffice.org, and Evolution." - nubuntu.org
nUbuntu Main Discuss Download Status: Active

Ophcrack

"The ophcrack LiveCD contains a small linux system (SLAX6), ophcrack for linux and rainbow tables for alphanumerical passwords.The liveCD cracks passwords automatically, no installation necessary, no admin password necessary (as long as you can boot from CD). Windows Vista SAM can also be cracked." -Ophcrack.sourceforge.net
Ophcrack Main Discuss Download Status: Active

OWASP Labrat

"The OWASP Live CD (LabRat) is a bootable CD akin to knoppix but dedicated to Application Security. It shall serve as a vehicle and distrubition medium for OWASP tools and guides." -OWASP.org
OWASP Labrat Main Discuss Download Status: Active

Protech

Protech is a specially designed Linux distribution for security technicians and programmers.
It's imcomparable usability and stability makes this a unique product. -Techm4sters
Protech Main Discuss Download Status: Active

Stagos FSE

"Stagos FSE aims to be a computer forensic framework based on FLOSS operating system. Builds from Ubuntu, it has many feature to do forensics stuff. It supports read variant filesystem, include ntfs. It also support read some forensic imaging file from another forensic software such like ENCASE." -linuxforums.org
Stagos FSE Main Download Status: Active

Arudius

Arudius is a Linux live CD with tools that try to address the network security aspect (penetration testing and vulnerability analysis) of information assurance. It is based on Slackware (Zenwalk) for i386 systems and targets the information security audience.
Arudius Main Discuss Download Status: Inactive

Auditor

"The Auditor security collection is a Live-System based on KNOPPIX. With no installation whatsoever, the analysis platform is started directly from the CD-Rom and is fully accessible within minutes. Independent of the hardware in use, the Auditor security collection offers a standardised working environment, so that the build-up of know-how and remote support is made easier." - http://www.remote-exploit.org/index.php/Auditor_main-
Auditor Main Discuss Download Status: Inactive

FIRE

"FIRE is a portable bootable cdrom based distribution with the goal of providing an immediate environment to perform forensic analysis, incident response, data recovery, virus scanning and vulnerability assessment."
-http://fire.dmzs.com-
FIRE Main Discuss Download Status: Inactive

INSERT

"INSERT is a complete, bootable linux system. It comes with a graphical user interface running the fluxbox window manager while still being sufficiently small to fit on a credit card-sized CD-ROM."
-http://www.inside-security.de/insert_en.html-
INSERT Main Discuss Download Status: Inactive

Knoppix-STD

"STD is a Linux-based Security Tool. Actually, it is a collection of hundreds if not thousands of open source security tools. It's a Live Linux Distro, which means it runs from a bootable CD in memory without changing the native operating system of the host computer." - http://www.knoppix-std.org/-
Knoppix-STD Main Discuss Download Status: Inactive

Local Area Security ( LAS )


Local Area Security ( LAS ) Main Discuss Download Status: Inactive

NavynOS

"Navyn OS is a gnu/linux distribution based on Gentoo. Gentoo isn't a typical distribution like Debian or Slackware, it doesn't even have an installer, it is similar to making your own distribution. The main part of Gentoo is portage, a set of scripts for installing and removing programs." -http://navynos.linux.pl/
NavynOS Main Discuss Download Status: Inactive

Operator

"Operator is a complete Linux (Debian) distribution that runs from a single bootable CD and runs entirely in RAM." - www.ussysadmin.com/operator/

Operator Main Discuss Download Status: Inactive

Pentoo

"Pentoo is a penetration testing LiveCD distribution based on Gentoo. It features a lot of tools for auditing and testing a network, from scanning and discovering to exploiting vulnerabilities."
-http://www.pentoo.ch/-PENTOO-.html-
Pentoo Main Discuss Download Status: Inactive

PHLAK

"PHLAK is a modular live security Linux distribution (a.k.a LiveCD). PHLAK comes with two light gui's (fluxbox and XFCE4), many security tools, and a spiral notebook full of security documentation. PHLAK is a derivative of Morphix, created by Alex de Landgraaf." - http://www.phlak.org/modules/news/-
PHLAK Main Discuss Download Status: Inactive

PLAC

"PLAC is a business card sized bootable cdrom running linux. It has network auditing, disk recovery, and forensic analysis tools. ISO will be avialable and scripts to roll you own cd."
-http://sourceforge.net/projects/plac/-
PLAC Main Discuss Download Status: Inactive

Plan-B

"Plan-B is a bootable Linux environment without the need for a hard drive, it runs entirely in ram or from the cd, based on a basic, stripped installation of Red Hat Linux and the fundamental workings of the SuperRescue CD" -http://www.projectplanb.org/


Plan-B Main Discuss Download Status: Inactive

SENTINIX

"SENTINIX is a GNU/Linux distribution designed for monitoring, intrusion detection, vulnerability assessment, statistics/graphing and anti-spam. It's completely free; free to use, free to modify and free to distribute. SENTINIX includes the following software, installed and pre-configured; Nagios, Nagat, Snort, SnortCenter, ACID, Cacti, RRDTool, Nessus, Postfix, MailScanner, SpamAssassin, openMosix, MySQL, Apache, PHP, Perl, Python and lots more." -http://sentinix.tigerteam.se/
SENTINIX Main Discuss Download Status: Inactive

SNARL

snarl is a bootable forensics ISO based on FreeBSD and using @stake's autopsy and task as well as scmoo's list of known good checksums. -snarl.eecue.com
SNARL Main Download Status: Inactive

Talos

"Talos is a security LiveCD, based on SLAX 5.1.0 with over 90 security tools preinstalled. It runs directly from the CD without the need to install on the harddisk. Talos is currently on BETA version 0.1 and its available to download." -ISafe.gr
Talos Main Discuss Download Status: Inactive

ThePacketMaster

ThePacketMaster - Mission-Specific Live-CD Linux Distributions - thepacketmaster.com
ThePacketMaster Main Discuss Download Status: Inactive

Trinux

Minimal ramdisk linux distribution meant for network monitoring.
Trinux Main Discuss Download Status: Inactive

WarLinux

A linux distribution for WarDrivers.
WarLinux Main Discuss Download Status: Inactive

WHAX

Updated project from Whoppix. Currently discontinued and merged with BackTrack.
WHAX Main Discuss Download Status: Inactive

Whoppix

"Whoppix is a stand-alone penetration-testing live CD based on KNOPPIX. With the latest tools and exploits, it is a must for every penetration tester and security auditor. Whoppix includes several exploit archives, such as Securityfocus, Packetstorm, SecurityForest and Milw0rm, as well as a wide variety of updated security tools." -Distrowatch
Whoppix Main Discuss Download Status: Inactive


martes, mayo 20, 2008

Instalaccion de Damm Vulnerable Linux, SLAX y/o BackTrack en disco duro

http://www.offensive-security.com/documentation/backtrack-hd-install.pdf

viernes, mayo 09, 2008

VirtualBox 1.6 Portable Multileguaje

Con la aparicion de esta nueva version de este emulador de SO aparece esta version oprtable del mismo multilenguaje. Se ha tomado comor eferencia para su ensamblado los scripts de antiguas versiones portables del mismo tomadas de la web del autor: http://z0rz.com/ aunque esta ultima version y en soporte multilenguaje ya bajo las manos de sun no ha dado la luz.

Descarga: http://rapidshare.com/files/113696850/xVM_VirtualBox_Portable_1.6.rar


domingo, mayo 04, 2008

Estafas en ebay - etc ....

Seguramente si eres vendedor o lo has sido en alguna ocasion de ebay hayas recibido mensajes durante la venta de tu producto donde te ofrecen a precios realmente bajos la compra de productos electronicos a muy bajo precio. Suelen respaldarse bajo un origen oriental aunque las paginas estan en castellano. En el mismo mensaje envian la direccion de correo de hotmail para contactar con el vendedor. Realmente los precios son sucluentos para cualquiera que quiera comprarse un determinado producto y no quiera pagar un precio demasiado excesivo. Ultimas marcas a precios por debajo de la mitad de lo ofrecido en las tiendas.
Un ejemplo de este timo puede encontrarse en esta pagina http://www.ele-ok.com. Como esta hay otras muchisimas mas que como digo llegan solas al poner a la venta un producto en ebay. La mayoria de ellas siempre ofrecen el pago mediante varios metodos aunque el vendedor con el que vas a contactar por messenger para un trato personal te va a instar a pagar mediante western union. Dichos vendedores dicen residir en paises como china o japon aunque las paginas suelen encontrarse albergadas en EEUU y tanto la pagina como el vendedor hablan en ingles.
Mi consejo no es otro que aunque parezca muy suculento estos precios no realizar la compra ya que el resultado sera el envio de dinero a un destino de donde no se volvera a recibir nada.
Otras veces no existe pagina web y el vendedor ofrece un producto a un precio ligeramnete mas bajo que los demas, una vez ganada la puja el vendedor se pone en contacto contigo mediante email o bien messenger y a partir de ahi comienzan los engaños para instar al potencial estafado a abonar el precio de un articulo que nunca recibira. En la mayoria de este ultimo caso son usuarios que han robado la cuenta y una vez finalizada la compra y el vendedor se ha puesto en contacto el usurio desaparece y ebay cancela al usuario de su base de datos.
Casi siempre se ofrecera y se insta a pagar por wester union ya que es el modo mas impersonal para recibir una cantidad de dinero sin necesidad de acreditacion personal.

viernes, mayo 02, 2008

Linuxeando - Unificacion de las distros de linux en una sola

Bueno pues me dispongo a hablar un poco sobre mi idea sobre el software libre mas concretamente sobre las multiples distros que existen disponibles en internet sin tener que abonar nada incluso en algunos casos las envian a casa gratuitamente como es el caso de Sun Solaris (unix no linux) o Ubuntu en sus variantes.
Mi opnion sobre esto es que existe un gran esfuerzo por la comunidad linuxera para hacer tantas distrobucciones que a resumidas cuentas no hacen mas que ser la misma pero con diferentes aspectos o bien encaminadas a diferentes entornos dependiendo del software que contengan.
Mi opnion sobre las livecd es buena para probar ciertas utilidades sin ser necesaria una instalaccion previa aunque si bien esaria deacuerdo que incluso estas tubieran como base la misma distribuccion. Ello no solo daria un mejor servicio a los usuarios sino que todos los esfuerzos serian e iririan encaminados para mejorar un solo SO de base sin necesidad de tener trabajando millones de personas para diferentes distribucciones siendo cuando menos el resultado de todas ellas realmente similar. Por ello y hablabndo claro mi punto de vista y mi lucha es por la unificacion de toda la comunidad linux en una sola distribuccion para que asi esta sea mejor. Es bien sabido que la mayoria de usuarios linux son verdederos hackers, es una pena que pierdan parte de su tiempo en compilar una distribuccion que a fin de cuentas es similar a la otra. El proyecto que mas se acerca segun mi enteder a esta unificacion de forma totalmente libre es Ubuntu por ser el linux mas utilizado, mas facil de instalar y con mas adeptos. El propio cd permite la instalacion o ejecucion del mismo desde el cd de instalaccion nota a tener en cuenta para crear ciertas livecd con determinadas caracteristicas para su uso.
Es tan solo una opnion pero creo que seria lo ideal para que la ya gran comunidad linuxera aumentara considerablemente para hacer un frente realmente estable contra windows.