Network Security Library

Network Security Library / Auditing

Passive Information Gathering (Part 2)
Date - Feb 21, 2007
Author - Gunter Ollmann
Part 2 of what can be gathered passively in order to formulate a targeted attack.
Passive Information Gathering (Part 1)
Date - Feb 07, 2007
Author - Gunter Ollmann
What can be gathered passively in order to formulate a targeted attack.
The need for effective event management
Date - Nov 15, 2006
Author - GFI Software
Logs and their management are however one of the most important aspects in computer systems management. This white paper shows where GFI EventsManager fits in this picture and how it is an invaluable asset in the corporate toolbox.
Spreadsheet Assurance
Date - Jun 07, 2006
Author - Tom Olzak
To date auditors have not looked too deeply into the content or accuracy of spreadsheets in corporations. With Sarbanes-Oxley (SOX), and the recent Health Insurance Portability & Accountability Act (HIPAA), you can bet that they will start to take a closer look. Will your spreadsheet results pass an audit?
Analysis of Remote Active Operating System Fingerprinting Tools
Date - Aug 06, 2003
Author - Ryan Spangler
There are many tools today that are used for remote active operating system fingerprinting. They all have their own fingerprinting techniques. This paper gives an in-depth analysis of three such tools: Nmap, RINGv2, and Xprobe2. The purpose of the paper is to show how these tools work, and to understand the advantages and disadvantages they each offer.
Guide to Sybase Security
Date - Mar 20, 2003
Author - Network Intelligence India Pvt. Ltd.
This article provides a detailed explanation of security for a Sybase database. The article has been written from the perspective of both security auditing and implementation. The queries and details given have been tested on Sybase Adaptive Server Enterprise 12.5 but will be valid for other versions as well.
Ethical Hacking Techniques to Audit and Secure Web-enabled Applications
Date - Jun 07, 2002
Author - Sanctum, Inc.
Hacking Web Applications Using Cookie Poisoning
Date - Jun 07, 2002
Author - Amit Klein
Web Application Forensics: The Uncharted Territory
Date - Jun 07, 2002
Author - Ory Segal
Hacker Repellent
Date - Jun 07, 2002
Author - Amit Klein
Passive System Fingerprinting using Network Client Applications
Date - Feb 18, 2001
Author - Jose Nazario
Advanced Host Detection - Techniques To Validate Host-Connectivity
Date - Feb 18, 2001
Author - Dethy
Examining port scan methods - Analyzing Audible Techniques
Date - Feb 18, 2001
Author - Dethy
ICMP Usage In Scanning v2.5
Date - Dec 26, 2000
Author - Ofir Arkin
An Overview of Network Security Analysis and Penetration Testing
Date - Sep 03, 2000
Author - Network Security Team
10 Proposed 'first-aid' security measures against Distributed Denial Of Service attacks
Date - Apr 18, 2000
Author - Mixter
Tribe Flood Network 3000
Date - Apr 10, 2000
Author - Mixter
Why Computers are Insecure
Date - Apr 10, 2000
Author - Bruce Schneier
A Weakness in the 4.2BSD Unix TCP/IP Software
Date - Apr 10, 2000
Author - Robert T. Morris
A Critical Analysis of Vulnerability Taxonomies
Date - Apr 09, 2000
Author - Matt Bishop
A Taxonomy of UNIX and Network Security Vulnerabilities
Date - Apr 09, 2000
Author - Matt Bishop
Classifying Vulnerabilities
Date - Apr 09, 2000
Author - Matt Bishop
Practical Network Support for IP Traceback
Date - Apr 09, 2000
Author - Stefan Savage
Purgatory 101: Learning to cope with the SYNs of the Internet.
Date - Apr 09, 2000
Author - Rain Forest Puppy
Strategies for Defeating Distributed Attacks
Date - Apr 09, 2000
Author - Simple Nomad
The DoS Project's "trinoo" distributed denial of service attack tool.
Date - Apr 09, 2000
Author - David Dittrich
Towards a Taxonomy of Network Security Assessment Techniques
Date - Apr 09, 2000
Author - Adam Shostack
Advanced Buffer Overflow Exploit
Date - Apr 08, 2000
Author - Taeho Oh
Compromised - Buffer - Overflows, from Intel to SPARC Version 8
Date - Apr 08, 2000
Author - Mudge
Finding and Exploiting Programs with Buffer Overflows
Date - Apr 08, 2000
Author - prym
Buffer Overruns, Whats the Real Story?
Date - Apr 08, 2000
Author - Lefty
Smashing The Stack For Fun And Profit
Date - Apr 08, 2000
Author - Aleph One
strlcpy and strlcat--Consistent, Safe, String Copy and Concatenation
Date - Apr 08, 2000
Author - Todd C. Miller
w00w00 on Heap Overflows
Date - Apr 08, 2000
Author - Matt Conover
Win32 Buffer Overflows (Location, Exploitation and Prevention)
Date - Apr 08, 2000
Author - Dark Spyrit
The Open Source Security Testing Methodology Manual v2.0
Date - Feb 27, 2000
Author - Pete Herzog
Probing TCP Implementations
Date - Feb 23, 2000
Author - Douglas E. Comer
Continuous Assessment of a Unix Configuration: Integrating Intrusion Detection and Configuration Analysis
Date - Feb 21, 2000
Author - Abdelaziz Mounji
A Map of Security Risks Associated with Using COTS
Date - Feb 21, 2000
Author - Ulf Lindqvist
Commonly Overlooked Audit Trails on Intrusions
Date - Feb 21, 2000
Author - Mixter
The Remedy Dimension of Vulnerability Analysis
Date - Feb 21, 2000
Author - Ulf Lindqvist
Advanced Security Audit Trail Analysis on uniX. Implementation Design of the NADF Evaluator.
Date - Feb 20, 2000
Author - Naji Habra
ASAX: Software Architecture and Rule-base Language for Universal Audit Trail Analysis.
Date - Feb 20, 2000
Author - Naji Habra
GASSATA, A Genetic Algorithm as an Alternative Tool for Security Audit Trails Analysis
Date - Feb 20, 2000
Author - Ludovic Me

Network Security Library topic  

   [ 26 ] Anti Spam    [ 12 ] Anti Virus    [ 44 ] Auditing
   [ 60 ] Auth. & Access Control    [ 3 ] Content Management    [ 103 ] Cryptography
   [ 12 ] Disaster Recovery    [ 36 ] Firewalls & VPN's    [ 6 ] Forensics
   [ 41 ] Harmless hacking book    [ 1 ] Honeypots    [ 14 ] Information Warfare
   [ 26 ] Intrusion Detection    [ 7 ] Law    [ 3 ] Managed Security Solutions
   [ 50 ] Misc    [ 24 ] Mobile Code    [ 32 ] NCSC&DoD Rainbow series
   [ 13 ] NetWare    [ 31 ] Network Security    [ 4 ] Patch Management
   [ 3 ] Phishing    [ 38 ] Policy & Standards    [ 25 ] Privacy
   [ 21 ] Software Engineering    [ 2 ] Trojans    [ 2 ] Underground
   [ 82 ] Unix Security    [ 19 ] Web Security    [ 39 ] Windows Security
   [ 6 ] Wireless Security

Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center

Readers' Choice

Which is your preferred Patch Management solution?