|
 |
dilluns, 14 / febrer / 2005 |
Nova versió de Nessus, disponible a http://www.nessus.org.
Nessus 2.2.3 contains a new option called "silent dependencies" which can be used to filter out the noise generated by some plugins not directly enabled by the user. It also contains a slightly more intuitive GUI which now contains a "Credentials" tab to put Windows and SSH usernames and passwords.
|
23:52 (# Enllaç permanent) | Comentaris: | Trackback:
|
|
[NTA] VPN Security Flaws White Paper. Estudi sobre el nivell de seguretat de les xarxes privades virtuals:
- El 90% dels accessos remots via VPN tenen vulnerabilitats que poden ser explotades
- Possibilitat d'enumerar els noms d'usuari
Many remote access VPNs have vulnerabilities that allow valid usernames to be guessed through a dictionary attack, because they respond differently to valid and invalid usernames. One of the basic requirements of a username/password authentication scheme is that an incorrect login attempt should not leak information as to whether the username or password was incorrect, because the attacker can then deduce if the username is valid or not. However, many VPN implementations ignore this rule.
- Manca de bones pràctiques d'implementació
- Les VPN són un objectiu pels atacants:
VPNs carry sensitive information over an insecure network and remote access VPNs often allow full access to the internal network, while VPN traffic is usually invisible to IDS monitoring. With increasing security in other areas e.g. more organisations installing firewalls, moving Internet servers onto the DMZ and automatically patching servers, the VPN becomes a more tempting target. L'estudi és el resultat de la monitorització dels sistemes d'accés remot de grans organitzacions
|
07:33 (# Enllaç permanent) | Comentaris: | Trackback:
|
|
nms is a set of web programs that are intended as drop-in replacments for the scripts at Matt's Script Archive. Matt's Script Archive (MAS) has been on the web since 1995. It is a repository of web scripts written in Perl by a programmer called Matt Wright.
MSA is probably the most popular repository of web scripts currently available on the internet.
The problem is that the scripts in Matt's Script Archive aren't very good. The scripts are well known amongst the Perl community to be badly written, buggy, and insecure.
(...)
In 2001, the London Perl Mongers decided to address this problem and write a series of drop-in replacements for Matt's scripts. This project is the result.
|
07:22 (# Enllaç permanent) | Comentaris: | Trackback:
|
|
Ara fa un any, més o menys, Microsoft imitava a l'ex-ministre Trillo... el responsable de seguretat de Microsoft deia que mai «ningú s'ha aprofitat d'una vulnerabilitat de Windows abans de que es publiqués el pegat».
Ara és el torn d'imitar al ministre Bono tot dient que Windows és més segur que Linux: «Microsoft's Security Chief Says Windows Safer Than Linux».
«Even with the relatively large number of bulletins we released this week, we compare favorably,» he said. «Year-to-date for 2005, Microsoft has fixed 15 vulnerabilities affecting Windows Server 2003. In the same time period, for just this year, Red Hat Enterprise Linux 3 users have had to patch 34 vulnerabilities and SuSE Enterprise Linux 9 users have had to patch over 78 vulnerabilities» Evidentment s'oblida d'indicar que gairebé totes les vulnerabilitats de Linux són de productes accessoris mentre que moltes vulnerabilitats que cita de Windows són únicament del nucli del sistema operatiu; no inclou les vulnerabilitats de l'Office, per exemple. És a dir, compara patates amb peres...
|
07:01 (# Enllaç permanent) | Comentaris: | Trackback:
|
|
© Copyright 2003-2005 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicència Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.
|
 |
 |
 |
 |
Contingut actualitzat
Categories
Darrers comentaris
Arxiu
Contingut antic
(ja no s'actualitza)
Versions anteriors
d'aquesta pàgina
|
 |
 |
 |
 |
|