Affichage des articles dont le libellé est Server Security. Afficher tous les articles
Affichage des articles dont le libellé est Server Security. Afficher tous les articles

Top 10 Vulnerability Scanner

http://www.ehacking.net/2014/02/top-10-vulnerability-scanner.html
Vulnerability scanner is a software program that has been designed to find vulnerabilities on computer system, network and servers. In addition to the manual security test and code review, automatic tools always play their roles to make the vulnerability assessment efficient. There are many aspects that you should consider before using any tool; aspects are including but not limited to the cost, features, reporting pattern or simply management. This article contains the detail of top vulnerability scanner tools that you might required in your security testing process.

Nessus

The Nessus vulnerability scanner provides patch, configuration, and compliance auditing; mobile, malware, and botnet discovery; sensitive data identification and many other features.
·    Nessus and Nessus Perimeter Service™ subscriptions for commercial organizations and enterprises
·         Nessus evaluations for commercial organizations
·         Nessus Home for personal use in a non-commercial, home network

Operating System:Windows, Mac OS X, OpenBSD, FreeBSD, Solaris, and/or other UNIX variants
Price: Paid

OpenVAS

The Open Vulnerability Assessment System (OpenVAS) is a framework of several services and tools offering a comprehensive and powerful vulnerability scanning and vulnerability management solution.
 

The actual security scanner is accompanied with a daily updated feed of Network Vulnerability Tests (NVTs), over 33,000 in total (as of December 2013).

All OpenVAS products are Free Software. Most components are licensed under the GNU General Public License (GNU GPL).

Operating System:Linux, Windows and other operating systems.
Price: Free

Core Impact

As network security continues to harden, it's no surprise that cyber criminals have shifted their attack techniques to focus on applications and end users. 

With the release of version 12.5, CORE Impact Pro takes vulnerability assessment and testing far beyond traditional exploitation -- allowing commercial and government organizations to actively and accurately test the security of their network and application infrastructure using the same Advanced Persistent Threat and password-based techniques employed by cyber attackers.

Operating System:Windows
Price: Paid

Nexpose

Nexpose, the vulnerability management software, proactively scans your environment for mis-configurations, vulnerabilities, and malware and provides guidance for mitigating risks. Experience the power of Nexpose vulnerability management solutions by knowing the security risk of your entire IT environment including networks, operating systems, web applications, databases, and virtualization.

Exposing security threats including vulnerabilities, mis-configurations and malware.


Prioritizing threats and getting specific remediation guidance for each issue.
Integrating with Metasploit to validate security risk in your environment.

Operating System: Windows, Linux
                          

Price: Paid

GFI Lan Guard

Research consistently demonstrates that many of the vulnerabilities cybercriminals exploit can be prevented with updated software patches, and addressing of misconfigured network gear and unauthorized devices on the network.

GFI LanGuard scans and detects network vulnerabilities before they are exposed, reducing the time required to patch machines on your network. GFI LanGuard patches Microsoft ®, Mac® OS X®, Linux® and more than 50 third-party operating systems and applications, and deploys both security and non-security patches.

Operating System:Windows
Price: Paid

QualysGuard

QualysGuard Enterprise is an award-winning cloud security and compliance solution. It helps global businesses simplify IT security operations and lower the cost of compliance. It delivers critical security intelligence on demand and automates the full spectrum of auditing, compliance and protection for Internet perimeter systems, internal networks, and web applications.

Operating System:Windows
Price: Paid

MBSA

The Microsoft Baseline Security Analyzer provides a streamlined method to identify missing security updates and common security misconfigurations. MBSA 2.3 release adds support for Windows 8.1, Windows 8, Windows Server 2012 R2, and Windows Server 2012. Windows 2000 will no longer be supported with this release.

Operating System:Windows
Price: Freeware

Retina

With over 10,000 deployments since 1998, Beyond Trust Retina Network Security Scanner is the most sophisticated vulnerability assessment solution on the market. Available as a standalone application or as part of the Retina CS unified vulnerability management platform. 

Retina Security Scanner enables you to efficiently identify IT exposures and prioritize remediation enterprise-wide. Retina Network Security Scanner, the industry’s most mature and effective vulnerability scanning technology, identifies the vulnerabilities – missing patches, configuration weaknesses, and industry best practices - to protect an organization’s IT assets.

Operating System:Windows
Price: Paid

Secunia PSI

Don’t let one vulnerable PC open your corporate network up to cyber attacks - Combining private and corporate Patch Management provides a 360° overview of all vulnerability threats

The Secunia Personal Software Inspector (PSI) is a free security tool designed to detect vulnerable and out-dated programs and plug-ins, which expose your PC to attacks. Once installed, the Secunia PSI can help you patch vulnerable programs and stay secure.

Operating System:Windows
Price: Freeware

Nipper

Nipper (short for Network Infrastructure Parser, previously known as Cisco Parse) audits the security of network devices such as switches, routers, and firewalls. It works by parsing and analyzing device configuration file which the Nipper user must supply. This was an open source tool until its developer (Titania) released a commercial version and tried to hide their old GPL releases (including the GPLv2 version 0.10 source tarball).


Operating System: Windows, Apple MAC OSX, Linux
Price: Paid



Further reading: Top 125 Network Security Tools

~ lundi 3 février 2014 0 commentaires

Top 10 FTP Software for Windows

http://www.ehacking.net/2014/01/top-10-ftp-software-for-windows.html
FTP is an acronym for File Transfer Protocol. As the name suggests, FTP is used to transfer files between computers on a network. You can use FTP to exchange files between computer accounts, transfer files between an account and a desktop computer, or access online software archives. Keep in mind, however, that many FTP sites are heavily used and require several attempts before connecting. There are many different FTP clients that you can download from the Internet. Some of these can be downloaded for free and others on a try before you buy basis.



FileZilla


FileZilla Client is a fast and reliable cross-platform FTP, FTPS and SFTP client with lots of useful features and an intuitive graphical user interface. FileZilla is an FTP program for file uploading and downloading to and from your FTP site, server, or host. The program lets you transfer files and navigate among folders, Web sites, and your computer. This software enables you to perform multiple file transfers simultaneously.

SmartFTP


SmartFTP is a commercial desktop FTP client written by SmartSoft LTD for Microsoft Windows. SmartFTP also offers secure, reliable and efficient transfers that make it a powerful tool. SmartFTP is available in three versions, Home, Professional and Ultimate. SmartFTP offers a host of features to help you get the most from your FTP server.
·         SmartFTP can check your file integrity after an upload or a download.
·         Scheduled, unattended file transfers – you don't even have to be around to transfer files.
·         Secure transfers with FTP-SSL.

Core FTP LE


Core FTP LE - free Windows software that includes the client FTP features you need. This free, secure FTP client gives you a fast, easy, reliable way to update and maintain your website via FTP.  Features like SFTP (SSH), SSL, TLS, FTPS, IDN, browser integration, site to site transfers, FTP transfer resume, drag and drop support, file viewing & editing, firewall support, custom commands, FTP URL parsing, command line transfers, filters, and much, much more!

Flash FXP


FlashFXP is the easiest to use FTP, FTPS, SFTP, FXP and most user-friendly to master client on the market. Use FlashFXP to publish and maintain your website. Upload and download files, such as documents, photos, videos, music and more! Transfer or backup local and remote files, plus (FXP) server to server ftp transfers. FlashFXP offers unique and complimentary advanced features for client configuration.

ZFTP Server


Now at version 3.0, zFTPServer Suite is still a free Windows FTP server and has gained a loyal following. It features multi-lingual user interfaces, flexible access control for both accounts and IP addresses, and passive as well as active mode connections. ZFTPServer supports all popular Windows operating systems (except Vista) and is designed for ease of use by beginning- and intermediate level users.

Serv-U FTP Server


Serv-U FTP server for Windows and Linux supports SFTP (SSH), secure FTP (FTPS), secure file sharing, web transfers, and remote administration. Access files from anywhere via mobile devices, web browsers and FTP clients, and avoid data at rest in the DMZ with our MFT gateway. Let your end users share files or request files with anyone through an intuitive web interface that replaces insecure or unreliable cloud-based applications

Xlight FTP Server


Xlight FTP Server is a high performance and easy to use ftp server software for Windows. It is designed to handle thousands of simultaneous ftp clients and use very little CPU and memory. Xlight FTP Server has three editions: personal, standard, professional. Personal edition is free for personal use and home users. You can click here to see the difference of three editions.

Golder FTP Server


Golden FTP Server is extremely easy to use personal FTP server for Windows and can be run by any person who has the most basic computer skills. The program loads automatically on Windows startup and you can identify the files you want to share with two mouse clicks via the dialog window that works in the same way as the standard Windows "Open File:" dialog or via the Windows Explorer context menu.

War FTP Daemon


This site is the primary source for information about the War FTP Daemon. War FTP Daemon is the original free FTP server for Windows. When it was released in 1996, it became an instant success. After that, the server has earned its status as one of the "essential" Internet Server Applications for Windows. Unlike many other "free" Windows applications, War FTP Daemon contains absolutely no spyware or adware. The program is designed to transfer files to and from the server, according to your demands - and nothing else. There are no backdoor, no advertizing pop-ups, no "reporting home" nonsense or any other hidden "features". The only security or privacy risk with the (at any time) latest version of War FTP Daemon, is misconfigurations or yet undiscovered bugs.

WS FTP Server



WS_FTP® Server is the easiest way to securely store, share and transfer information between systems, applications, groups and individuals. Access files from web browsers, or FTP clients such as WS FTP Professional, and share files with vendors and partners securely. For more than 20 years, Ipswitch’s server software has been used by thousands of companies to transfer and protect confidential information.

~ lundi 13 janvier 2014 0 commentaires

7 Best Linux Server Security Tips

Linux seems to be the most secure and powerful server, but remember nothing is secure in the world you have to make the thing secure, if you are running Linux server and not patched it than it may be compromise so the point is that an administrator should make the box secure from hackers (crackers). There are different level of security like application layer security means web application security like SQL-Injection, XSS.

Application layer security is not the point of this article, in this article I will discuss Linux server hardening security tips.

Use Strong Passwords
I consider that you have an idea about the importance of passwords and password based attack, so use strong password that has upper and lower case alphabet, numbers and special characters, try to make the password policy strict.

Use Cryptography  
Cryptography the art of secrete communication, all the data that goes through network may be sniffed so use encryption technique to secure your data. Use OpenVPN is a cost-effective, lightweight SSL VPN. Use scp, ssh, rsync, or sftp for file transfer.

Avoid Remote Log Ins  
As mentioned on the previous tip that data goes on the network may be captured, services like FTP, Telnet, and different file transfer protocols may be compromised so avoid using these services by a remote location if you need to use these services than you must use secure channel like use OpenSSH, FTPS etc.

Patched Management 

There are different exploits available for different software(s) and services, so make sure to follow the patch management strategy to keep update your Linux kernel and all the software's and services running on that server. Keep up to date your OS to secure the Linux, if you have a question like why patch management and about patch management policies than follow the link to learn.
 
Use Intrusion Detection Systems
Firewalls has different limitation so use intrusion detection systems (IDS), you must be configure both network IDS (NIDS) and host IDS (HIDS) to protect the attacks like DOS,port scanning etc. We have discussed about IDS in different articles with detail click here to learn.

Use Linux Security Extensions
To secure the Linux kernel is the key point to secure the Linux server, there are various security packages available to provide the additional security to Linux kernel, try to use the software's like SELinux, AppArmor or GRSecurity.

Use Log Management
Use a strong log management policy to keep an eye on the changes and errors, beside Linux built in log management files there are different software's that provides auditing and log management policies.

Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ samedi 9 juillet 2011 0 commentaires