Wiretapped - Computer Security Software etc.

Host Security

The host security directory contains software which can assist a system administrator increase and maintain the level of security on their systems. (A number of the host intrusion detection software packages are also listed here in host security)

  • ACUA (& RADACUA)
    ACUA is a software package designed to facilitate the administration of user accounts and the enforcement of access restrictions on a Linux system. ACUA is most often used on systems that host modem pools such as ISPs, BBSs, School Dial-Ups and Business Dial-Ups. RADACUA is a version of ACUA designed to operate with RADIUS servers.
    Browse: HTTP / FTP / HOMEPAGE

  • Cain & Abel
    Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary & Brute-Force attacks, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols.
    Browse: HTTP / FTP / HOMEPAGE

  • checkinstall
    Installs a compiled program from the program's source directory using "make install" or any other command supplied on checkinstall's command line. checkinstall will create a Slackware, RPM or Debian compatible package and install it using your distribution's standard package administration utilities.
    Browse: HTTP / FTP / HOMEPAGE

  • chkrootkit
    chkrootkit is a shell script that checks system binaries for rootkit modification. It checks a number of thing inside a number of system binaries, checks if any network interfaces are in promiscuous mode, checks for lastlog deletions, checks for wtmp deletions, checks for wtmpx deletions. (Solaris only), and checks for signs of LKM trojans.
    Browse: HTTP / FTP / HOMEPAGE

  • chrootuid
    chrootuid runs a command in a restricted environment. Uses include running network services at a low privelige level and with restricted filesystem address. Now available under a BSD-style license.
    Browse: HTTP / FTP

  • Forensics

  • imp
    Imp is a NetWare password cracking utility with a GUI (Win95/NT). It loads account information directly from NDS or Bindery files and and allows the user to attempt to compromise the account passwords with various attack methods.
    Browse: HTTP / FTP / HOMEPAGE

  • John The Ripper
    John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), DOS, Win32, and BeOS. Its primary purpose is to detect weak Unix passwords, but a number of other hash types are supported as well.
    Browse: HTTP / FTP / HOMEPAGE

  • lsof
    Lsof is a UNIX-specific tool. Its name stands for LiSt Open Files, and it does just that. It lists information about files that are open by the processes running on a UNIX system.
    Browse: HTTP / FTP / HOMEPAGE

  • mdcrack
    mdcrack is an md5/md4/NTLM1 hash brute forcer, taking a number of arguments including minimum password size, leading and/or trailing partial strings etc and brute forces this information to discover what input and/or what collisions will match the user-supplied hash.
    Browse: HTTP / FTP / HOMEPAGE

  • OS Hardening

  • pam_passwdqc
    pam_passwdqc is a simple password strength checking module for PAM-aware password changing programs, such as passwd(1). In addition to checking regular passwords, it offers support for passphrases and can provide randomly generated passwords. All features are optional and can be (re-)configured without rebuilding.
    Browse: HTTP / FTP / HOMEPAGE

  • Secure Deletion

  • shadow
    shadow is a shadow password suite for Linux. Most Linux users will know this package as "shadow utils". We are mirroring the source code of the package here.
    Browse: HTTP / FTP / HOMEPAGE

  • slocate
    Secure locate provides a secure way to index and quickly search for files on your system. It uses incremental encoding just like GNU locate to compress its database to make searching faster, but it will also check file permissions and ownership so that users will not see files they do not have access to.
    Browse: HTTP / FTP / HOMEPAGE

  • syslog-ng
    syslog-ng, as the name shows, is a syslogd replacement, but with new functionality for the new generation. The original syslogd allows messages only to be sorted based on priority/facility pairs; syslog-ng adds the possibility to filter based on message contents using regular expressions. Forwarding logs over TCP and remembering all forwarding hops makes it ideal for firewalled environments.
    Browse: HTTP / FTP / HOMEPAGE

  • whowatch
    whowatch is an interactive who-like program that displays information about the users currently logged on to the machine, in real time. Besides standard informations (login name, tty, host, user's process), the type of the connection (ie. telnet or ssh) is shown. You can toggle display between users' command or idle time. You can watch processes tree, navigate in it and send INT and KILL signals.
    Browse: HTTP / FTP / HOMEPAGE

Browse this directory with: HTTP / FTP

(Note: This list of software and information available at Wiretapped is not exhaustive. Users are encouraged to browse and search the archive and read any available "-README.txt" files that are available)

Changelog...

Questions / Suggestions:

Should you have any questions regarding Wiretapped or suggestions for additional software or material that we can mirror, please send an email to web[at]wiretapped.net

Google
Search Wiretapped.net
Search WWW

$Id: host-security.html,v 1.23 2005/03/18 16:38:44 gbayley Exp $