Network World

Resource Links

Search / DocFinder:
Advanced search
Research Centers
Vendor Solutions
Site Resources
Special Issues

Signature SeriesEnterprise All-Stars
Enterprise All-Stars NEW

You in action
You in action

New Data Center The New Data Center: Wireless & Mobility
Wireless & Mobility NEW

The New Data Center: Server Virtualization
Server Virtualization

Security


Search Security
All Fusion Links only

New resources

Add a resource | Modify a link

Top rated resources

Sub-categories

pop AirSnort

"AirSnort is a wireless LAN (WLAN) tool which recovers encryption keys. AirSnort operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered." Free. Runs on Linux.

Hits: 6688
Rating: 1.00
Rate it
Comment: (1)


pop Angry IP Scanner

"Angry IP scanner simply pings each IP address to check if it's alive, then optionally it is resolving hostname and tries to connect at specified in Options dialog box TCP port. It also has additional features, like NetBIOS information (computer name, workgroup name, currently logged in user and MAC address), results saving to CSV, TXT, HTML or XML file, can be used as a command-line utility in a batch file, etc." Free. For Windows.

Hits: 2453
Rating: 5.50
Rate it
Comment on it


pop John the Ripper

Free password cracker, Linux, Unix, Windows and BeOS.

Hits: 2325
Rating: 7.50
Rate it
Comment on it


BackOfficer Friendly

"A useful little burglar alarm - simple, unobtrusive, and easy to install - which rings when someone rattles your doorknob. It identifies attacks from Back Orifice, one of the nastier hacking applications, as well as other sorts of scans." Free for personal use on Windows PCs.

Hits: 1129
Rating: 1.00
Rate it
Comment on it


BigFix Enterprise Suite Evaluation

"The automated patch management system that enables IT organizations to automatically detect system ulnerabilities and proactively fix them across their networks with a single action." Evaluation covers 30 seats. Network World review of BixFix (and three other patch management tools).

Platform(s): Windows 2000 Server or Advanced Server Edition.

Hits: 467
Rating: 1.00
Rate it
Comment on it


DenyHosts

"DenyHosts is a Python script that analyzes the sshd server log messages to determine what hosts are attempting to hack into your system. It also determines what user accounts are being targeted. It keeps track of the frequency of attempts from each host. Additionally, upon discovering a repeated attack host, the /etc/hosts.deny file is updated to prevent future break-in attempts from that host."

Open source.

Platform(s): Python, Linux.

Hits: 60
Rating: 10.00
Rate it
Comment on it


Desktop Orbiter

"Secure your network from a single point. Desktop Orbiter is a client-server solution capable of providing remote desktop security and management by means of a comfortable and easy-to-use interface."

Platform(s): Windows NT, Windows XP, Windows 2000.

Hits: 559
Rate it
Comment on it


dsniff

"Collection of tools for network auditing and penetration testing. ... Passively monitor a network for interesting data (passwords, e-mail, files, etc.) (and)facilitate the interception of network traffic normally unavailable to an attacker (e.g, due to layer-2 switching). sshmitm and webmitm implement active monkey-in-the-middle attacks against redirected SSH and HTTPS sessions by exploiting weak bindings in ad-hoc PKI." Free.

Hits: 2200
Rating: 3.00
Rate it
Comment on it


Enterprise Security Reporter

"Enterprise Security Reporter is a powerful tool designed to get answers to the questions you have about your network. By combing through the vast amount of data on your network and storing it in an open database, you now have the ability to analyze, query and report on the security and configuration of your network."

Platform(s): Windows 2000, Windows NT.

Hits: 711
Rate it
Comment on it


Fire & Water Toolkit

"Assessment and defense solution for security professionals. Ideal for both local and remote networks, Fire & Water is a collection of cohesive, interactive command line tools that perform network assessment, mapping and reporting; as well as robust Web server defense. By using XML output interactively, Fire & Water can easily and effectively manage multiple scans and their resulting data via standard [command line] output, CSV, and HTML reports (created via XSL templates provided with the tools). Custom report formats can be used by creating your own XSLT templates."

Platform(s): Windows.

Hits: 482
Rate it
Comment on it


Firewalk

"Firewalking is a technique developed by Mike D. Schiffman and David E. Goldsmith that employs traceroute-like techniques to analyze IP packet responses to determine gateway ACL filters and map networks. Firewalk the tool employs the technique to determine the filter rules in place on a packet forwarding device." For Unix and Linux.

Hits: 657
Rating: 10.00
Rate it
Comment on it


GFI LANguard Network Security Scanner

"GFI LANguard Network Security Scanner checks your network for possible security vulnerabilities by scanning your entire network for missing security patches, services packs, open shares, open ports, unused user accounts and more. With this information, you can easily lock down your network against hackers. Deploy missing patches and service packs in applications and OS."

Platform(s): Windows.

Hits: 215
Rate it
Comment on it


GFI LANguard Portable Storage Control

"GFI LANguard Portable Storage Control (P.S.C.) lets you control entry and exit of data via USB sticks and other devices and prevent users from taking confidential data or introducing viruses and trojans on your network."

Evaluation software.

Hits: 99
Rate it
Comment on it


GFI LANguard Security Event Log Monitor

"Performs event log based Intrusion detection and network wide event log management. Archives and analyses event logs of all network machines and alerts you in real time to security issues, attacks and other critical events."

Hits: 278
Rate it
Comment on it


GFI MailSecurity

"GFI MailSecurity is an email content checking, exploit detection, threats analysis and anti-virus solution for Exchange and SMTP server that removes all types of email-borne threats before they can affect your email users."

Platform(s): Exchange Server on Windows.

Hits: 546
Rating: 9.75
Rate it
Comment on it


GFI Network Server Monitor

"Monitors your network and servers for failures and fixes them automatically. Checks Exchange Server, SQL, Oracle, HTTP/FTP, disk health and space, event logs and more." 60-day trial version.

Platform(s): Windows 2000, Windows 2003, Windows XP Professional, Windows NT.

Hits: 437
Rating: 7.00
Rate it
Comment on it


GFI WebMonitor for ISA Server 3.0

"GFI WebMonitor is a utility for Microsoft ISA Server that allows you to monitor the sites users are browsing and what files they are downloading - in REAL TIME. In addition it can block access to adult sites as well as performing anti-virus scanning on all downloads. GFI WebMonitor is the perfect solution to transparently exercise a degree of access control over users' browsing habits and ensure legal compliance - in a manner that will not alienate your network users."
30-day evaluation.

Platform(s): Microsoft Windows 2000 (SP 3) or 2003 Server, Microsoft ISA server 2000 (not firewall only mode) OR Microsoft ISA server 2004 (Standard or Enterprise), Microsoft Internet explorer to access GFI WebMonitor.

Hits: 58
Rate it
Comment on it


HFNetChk

HFNetChk.exe is a multi-threaded command-line tool to assess a computer or selected group of computers for the presence or absence of security patches. You can use HFNetChk to assess patch status for the Windows NT 4.0, Windows NT Terminal Server, Windows 2000, Windows XP operating systems, as well as hotfixes and service packs for IIS 4.0, IIS 5.0, SQL Server 7.0, SQL Server 2000 (including MSDE), Exchange Server 5.5, Exchange Server 2000, Windows Media Player, Front Page Server Extensions, Microsoft Java Virtual Machine, Microsoft Data Access Components (MDAC), and Internet Explorer 5.01 or later.

Platform(s): Windows.

Hits: 457
Rating: 10.00
Rate it
Comment on it


Iris

"With Iris, automated filters can be set up in any number of combinations to flag and record specific network traffic that contains a particular MAC or IP address, unacceptable words or websites and more to quickly determine whether or not company security is being compromised or corporate policies abused. Iris also provides a larger variety of statistical measurements than any other traffic analyzer available." Runs on Windows.

Hits: 653
Rating: 10.00
Rate it
Comment on it


KAME

"A joint effort of six companies in Japan to provide a free IPv6 and IPsec (for both IPv4 and IPv6) stack for BSD variants to the world."

Hits: 344
Rate it
Comment on it


LANguard

"GFI LANguard Network Security Scanner scans your entire network and provides information such as service pack level of the machine, open shares, open ports, services/applications active on the computer, key registry entries, weak passwords, users and groups, and more. ... " For Windows NT and Windows 2000. Free for non-commercial use, $99 otherwise.

Hits: 847
Rating: 6.33
Rate it
Comment on it


Libsafe

Free software from Avaya that attempts to protect Unix servers from buffer overflow exploits: "Intercepts all function calls made to library functions that are known to be vulnerable. A substitute version of the corresponding function implements the original functionality, but in a manner that ensures that any buffer overflows are contained within the current stack frame."

Hits: 344
Rate it
Comment on it


Microsoft Baseline Security Analyzer

"MBSA runs on Windows Server 2003, Windows 2000, and Windows XP systems and will scan for common security misconfigurations in the following products: Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003, Internet Information Server (IIS) 4.0, 5.0, and 6.0, SQL Server 7.0 and 2000, Internet Explorer (IE) 5.01 and later, and Office 2000, 2002 and 2003. MBSA also scans for missing security updates for Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003, IIS, SQL, Exchange, IE, Windows Media Player, MDAC, MSXML, Microsoft VM, Office, Content Management Server, Commerce Server, Host Integration Server, and BizTalk Server." From Microsoft.

Platform(s): Windows.

Hits: 175
Rating: 10.00
Rate it
Comment on it


ModSecurity

"ModSecurity is an open source intrusion detection and prevention engine for web applications. Operating as an Apache Web server module, the purpose of ModSecurity is to increase web application security, protecting web applications from known and unknown attacks."

Platform(s): Apache.

Hits: 136
Rate it
Comment on it


Nessus

Remote auditing and port scanning tool. The server runs on Unix and Linux boxes; there is a Windows client. Free, open source.

Hits: 662
Rating: 10.00
Rate it
Comment on it


NetSQUID

"This project is a way to dynamically block hosts that are infected with some kind of virus or are in violation of a policy (scanning/hacking/etc...). However that's not where it stops. It can not only detect and quarantine infected hosts, it can also notify the infected host/user that they are in violation of something. It's basically a simple/easy way to take a great IDS (Intrusion Detection System) like Snort and transform it into an IPS (Intrusion Prevention System)."

Open source.

Platform(s): Linux, iptables, Perl.

Hits: 87
Rate it
Comment on it


NetToolX

Similar to netstat.exe, it shows all the connections to a machine, listening ports (identifying trojans), and can be used to close connections. For Windows 98, Windows ME, Windows NT and Windows 2000.

Hits: 817
Rating: 1.00
Rate it
Comment on it


Nikto

"Nikto is a web server scanner which performs comprehensive tests against web servers for multiple items, including over 2200 potentially dangerous files/CGIs, versions on over 140 servers, and problems on over 210 servers."

Platform(s): Perl.

Hits: 334
Rate it
Comment on it


Nmap

Free, open source Linux tool that "uses raw IP packets in novel ways to determine what hosts are available on the network, what services (ports) they are offering, what operating system (and OS version) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics."

Hits: 533
Rating: 10.00
Rate it
Comment on it


OpenSAML

"OpenSAML 1.0 is a set of open source Java and C libraries that are fully consistent with the SAML 1.0 and 1.1 CR specifications."

Hits: 65
Rate it
Comment on it


OpenSSL

"Collaborative effort to develop a robust, commercial-grade, full-featured, and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library." For Unix and Linux.

Hits: 352
Rate it
Comment on it


OpenVPN

"OpenVPN is an easy-to-use, robust, and highly configurable SSL VPN (Virtual Private Network) daemon which can be used to securely link two or more private networks using an encrypted tunnel over the internet."

Platform(s): Windows 2000, Windows XP, OS X, Unix, Linux.

Hits: 777
Rating: 9.00
Rate it
Comment on it


Outsourcing Management Zone

"Information, guidance and resources covering the whole gamut of outsourcing issues and topics."

Hits: 379
Rating: 8.00
Rate it
Comment on it


PatchMeister

Free tool designed to automatically find missing patches in Windows applications and OSes.

Hits: 776
Rating: 8.00
Rate it
Comment on it


Retina

"Retina can scan every machine on your network, including a variety of operating systems, networked devices and third-party or custom applications. ... After scanning, Retina delivers a comprehensive report that details all vulnerabilities on your systems and suggests appropriate fixes such as downloading related patches or using Retina's automatic repair capabilities." Runs on Windows XP, Windows NT and Windows 2000.

Hits: 916
Rate it
Comment on it


RideWayPN

Low-cost VPN alternative that uses gateway software installed on LANs to create a secure WAN. Software runs on Windows 95 and 98.

Hits: 286
Rate it
Comment on it


RogueAware

Free utility for detecting, monitoring and reporting on all AOL, MSN and Yahoo instant message traffic.

Hits: 1428
Rating: 9.50
Rate it
Comment on it


Sandcat Web Security Suite

"Four applications - Sandcat Scanner, Sandcat Miner, Sandcat Log Analyzer (L.A.) and Sandcat Web Security Hardening (W.S.H.) - are implemented together via a central interface and updated to include new features and new add-ons. Sandcat Web Security Suite helps maintain the security of web sites and the implementation of security documents, such as the SANS/FBI Top 20 List and the OWASP Top 10 2004 List."

Evaluation software.

Platform(s): Windows.

Hits: 88
Rate it
Comment on it


SecureCentral PatchQuest

"SecureCentral PatchQuest is an automated, patch management software for distributing and managing patches, security hotfixes and updates across heterogeneous networks comprising Windows, Red Hat Linux and Debian Linux systems, in just a few simple clicks. ... Its supports patches in the English language for operating systems and applications like Windows XP Professional,2000 Professional and Server, NT 4.0 Workstation and Server,IE,IIS,SQL Server,MDAC,Media Player etc. and Red Hat Linux and Debian Linux. The 10 system small network edition is also available free of cost."

Hits: 57
Rating: 10.00
Rate it
Comment on it


SecureConsole

Control what level of access individual users or NetWare groups have to your console, including what console commands they can use, what console applications they can see. Protocom.

Hits: 356
Rate it
Comment on it


Security Auditor's Research Assistant (SARA)

Free SATAN-derived toolkit for testing and finding vulnerabilities on a network. Runs on Unix and Linux boxes.

Hits: 448
Rate it
Comment on it


Security Explorer

Utility to search for and modify Windows NT security on NTFS drives, the Registry and shares. Sunbelt Software.

Hits: 457
Rate it
Comment on it


Sniffer

Windows program for capturing and analysis of packets transmitted on a network. Having installed on one of computers of a local network it is possible to observe all traffic, including packets not addressed to the chosen computer. Sniffer is extensible with plugins for different protocols: IP, TCP, UDP, IPX and NetBeui. Supports RAS-connections.

Hits: 1412
Rating: 1.00
Rate it
Comment on it


SQLBlock

"SQLBlock is an ODBC driver with patent pending automatic SQL injection blocking feature. It works as a ordinary ODBC data source and monitors every SQL statements being executed. If the client application tries to execute any un-allowed SQL statements, SQLBlock will block the execution and send an alert to administrator."

Hits: 32
Rate it
Comment on it


Squid Web Proxy Cache

Free, open-source proxy for Unix servers.

Hits: 350
Rating: 5.50
Rate it
Comment on it


squidGuard

Free app that adds URL and domain-name filtering to Squid.

Hits: 305
Rate it
Comment on it


Stegdetect

"Stegdetect is an automated tool for detecting steganographic content in images. It is capable of detecting several different steganographic methods to embed hidden information in JPEG images."

Open source.

Platform(s): Linux, Unix, Windows.

Hits: 102
Rate it
Comment on it


Sun identy management servers

Directories, certificate and identity servers from Sun's Sun ONE product line.

Platform(s): Unix.

Hits: 199
Rate it
Comment on it


SysUpdate Policy Compliance & Enforcement

"Policy driven patch management for Windows, Solaris, and Linux, and policy driven security policy compliance and enforcement for Windows 2000 and XP. Together, identifies vulnerabilities and exposures that are out of compliance and remediates them with Multiple Path Remediation (MPR) technology to bring machines back to security policy baseline determined by the administrator. Thereby, proactively enforces network patch and security policies on an ongoing basis." 15-day evaluation.

Platform(s): Windows.

Hits: 115
Rate it
Comment on it


Tauscan

Scans Windows PCs for Trojan horses. From Agnitum.

Hits: 551
Rate it
Comment on it


THC-HYDRA

"THC-Hydra - the best parallized login hacker: for Samba, FTP, POP3, IMAP, Telnet, HTTP Auth, LDAP, NNTP, MySQL, VNC, ICQ, Socks5, PCNFS, Cisco and more. Includes SSL support and is part of Nessus."

Platform(s): Windows, Unix, Linux.

Hits: 148
Rate it
Comment on it


Threat Modeling Tool

"The Threat Modeling Tool allows users to create threat model documents for applications. It organizes relevant data points, such as entry points, assets, trust levels, data flow diagrams, threats, threat trees, and vulnerabilities into an easy-to-use tree-based view. The tool saves the document as XML, and will export to HTML and MHT using the included XSLTs, or a custom transform supplied by the user."

Platform(s): Windows 2000, Windows Server 2003, Windows XP, Microsoft .NET Framework Version 1.1.

Hits: 173
Rate it
Comment on it


tinc

Open source VPN software for Linux, FreeBSD, OpenBSD and Solaris.

Hits: 263
Rating: 10.00
Rate it
Comment on it


Top 75 Network Security Tools

A listing of useful tools based on a survey of nmap users. From Insecure.org.

Hits: 815
Rate it
Comment on it


Tor

Toolkit for anonymizing Internet communications via onion routing. Open source.

Platform(s): Windows, Linux, Unix.

Hits: 61
Rate it
Comment on it


Tunnel Vision

Open source VPN software for Linux (kernel 2.2.x and above).

Hits: 264
Rate it
Comment on it


VLAD the Scanner

"VLAD the Scanner is an open-source security scanner that checks for the SANS Top Ten security vulnerabilities commonly found to be the source of a system compromise." Open source, written in Perl.

Platform(s): Unix, Linux.

Hits: 316
Rate it
Comment on it


whisker

Free Perl script and library for detecting vulnerabilities in Web CGI applications.

Hits: 424
Rate it
Comment on it


Xintegrity

"Xintegrity makes it virtually impossible for anybody or anything to modify your files without being detected. When Xintegrity detects a modified file it will show exactly how and when the file was modified and display the contents of the modified file in comparison with an optionally backed up copy of the file. All your files [including operating system files] can be protected. Xintegrity can automatically create protected backup files [optionally encrypted with 256 bit AES] allowing you the option of restoring the file when modification is detected."

Platform(s): Windows.

Hits: 64
Rate it
Comment on it


XML Security Library

C library, based on LibXML2 that implements the XML Digital Signature and XML Encrytpion specifications. Open source.

Hits: 263
Rate it
Comment on it


Page updated on: Tue Jul 31 2007 - 16:14:20

Vendor Solutions

White Papers

Symantec State of the Data Center Report
- Symantec

Memory Analysis in Eclipse
- Quest Software, Inc.

Selecting Effective Virtual Directories
- Symlabs

More...

Special Report

Network World Executive GUide: The Virtualization Equation - Zenith
Virtualization technology has moved from the science world to the mainstream and is now touted as the one of the fastest, easiest ways for users to save money. Learn how network IT executives are deploying it in the real world and what vendors have planned for the technology.


Research Centers: Applications | Application Development | Applications-Standards | Applications Vendor Solutions | Collaboration | CRM / ERP | Databases | Directories | Grid Computing | Java | Messaging | .Net | RFID | SOAP | Web Services | XML | Convergence & VoIP | Convergence Regulatory | Convergence Services | Convergence Standards | Convergence VoIP Vendor Solutions | Video | IP PBX | SIP | VoIP | VoIP Services | E-Business | DNS | RFID | Supply Chain | Web security LANs & Routers | Acceleration | Gigabit Ethernet | Lans-Standards | Routers | Wireless LANs | Network Management | Application Management | Desktop Management | Management Test Patch Management | Operating Systems | Linux | NetWare | Unix | Windows Outsourcing | Managed Services | Offshoring Security | Firewalls - VPN - Intrusion | Identity management | Patch Management | Microsoft Security | Privacy | Security Standards | Spam & Phishing | Viruses & worms | Web Security | Wireless Security | Servers & Desktop | Backup-Recovery | DataCenter | Desktops | Desktop Management | Grid | Servers | Server Blades | Servers Desktops | Utility Computing | Small & Medium Business | Broadband | Telework | Handhelds & PDAs | Home Networking | Security | Storage | Compliance | Infiniband | Network-Attached Storage | SANs | Storage Management | Storage Virtualization | Virtualization | Vendor News | Bankruptcy | Earnings | Lawsuits | Layoffs | Standards | Start Ups | Vendor Markets | Education | Financial | Healthcare | HIPAA | Manufacturing | Retail | Wide Area Network | Broadband | Carriers | Frame Relay | Metro Ethernet | MPLS | Service providers | Wireless services | Wireless & Mobile | Wireless LANs | PDAs & handhelds | Wireless Security | Wireless Services | Wireless Standards | Wireless Switches | All Company Profiles