My Account
View Cart
Home
Community
Books & Videos
Safari Books Online
Conferences
Training
School of Technology
About
Complete List
Bestsellers
New Releases
Rough Cuts
Upcoming Titles
Ebooks
By Publisher
By Series
Out of Print
Order Info
Search
Search Tips
Tell a friend
Network Security Hacks, Second Edition
Tips & Tools for Protecting Your Privacy
By
Andrew Lockhart
October 2006
Pages: 478
|
Table of Contents
|
Index
|
Sample Chapter
Table of Contents
Chapter 1
Unix Host Security
Secure Mount Points
Scan for SUID and SGID Programs
Scan for World- and Group-Writable Directories
Create Flexible Permissions Hierarchies with POSIX ACLs
Protect Your Logs from Tampering
Delegate Administrative Roles
Automate Cryptographic Signature Verification
Check for Listening Services
Prevent Services from Binding to an Interface
Restrict Services with Sandboxed Environments
Use proftpd with a MySQL Authentication Source
Prevent Stack-Smashing Attacks
Lock Down Your Kernel with grsecurity
Restrict Applications with grsecurity
Restrict System Calls with systrace
Create systrace Policies Automatically
Control Login Access with PAM
Restrict Users to SCP and SFTP
Use Single-Use Passwords for Authentication
Restrict Shell Environments
Enforce User and Group Resource Limits
Automate System Updates
Chapter 2
Windows Host Security
Check Servers for Applied Patches
Use Group Policy to Configure Automatic Updates
List Open Files and Their Owning Processes
List Running Services and Open Ports
Enable Auditing
Enumerate Automatically Executed Programs
Secure Your Event Logs
Change Your Maximum Log File Sizes
Back Up and Clear the Event Logs
Disable Default Shares
Encrypt Your Temp Folder
Back Up EFS
Clear the Paging File at Shutdown
Check for Passwords That Never Expire
Chapter 3
Privacy and Anonymity
Evade Traffic Analysis
Tunnel SSH Through Tor
Encrypt Your Files Seamlessly
Guard Against Phishing
Use the Web with Fewer Passwords
Encrypt Your Email with Thunderbird
Encrypt Your Email in Mac OS X
Chapter 4
Firewalling
Firewall with Netfilter
Firewall with OpenBSD’s PacketFilter
Protect Your Computer with the Windows Firewall
Close Down Open Ports and Block Protocols
Replace the Windows Firewall
Create an Authenticated Gateway
Keep Your Network Self-Contained
Test Your Firewall
MAC Filter with Netfilter
Block Tor
Chapter 5
Encrypting and Securing Services
Encrypt IMAP and POP with SSL
Use TLS-Enabled SMTP with Sendmail
Use TLS-Enabled SMTP with Qmail
Install Apache with SSL and suEXEC
Secure BIND
Set Up a Minimal and Secure DNS Server
Secure MySQL
Share Files Securely in Unix
Chapter 6
Network Security
Detect ARP Spoofing
Create a Static ARP Table
Protect Against SSH Brute-Force Attacks
Fool Remote Operating System Detection Software
Keep an Inventory of Your Network
Scan Your Network for Vulnerabilities
Keep Server Clocks Synchronized
Create Your Own Certificate Authority
Distribute Your CA to Clients
Back Up and Restore a Certificate Authority with Certificate Services
Detect Ethernet Sniffers Remotely
Help Track Attackers
Scan for Viruses on Your Unix Servers
Track Vulnerabilities
Chapter 7
Wireless Security
Turn Your Commodity Wireless Routers into a Sophisticated Security Platform
Use Fine-Grained Authentication for Your Wireless Network
Deploy a Captive Portal
Chapter 8
Logging
Run a Central Syslog Server
Steer Syslog
Integrate Windows into Your Syslog Infrastructure
Summarize Your Logs Automatically
Monitor Your Logs Automatically
Aggregate Logs from Remote Sites
Log User Activity with Process Accounting
Centrally Monitor the Security Posture of Your Servers
Chapter 9
Monitoring and Trending
Monitor Availability
Graph Trends
Get Real-Time Network Stats
Collect Statistics with Firewall Rules
Sniff the Ether Remotely
Chapter 10
Secure Tunnels
Set Up IPsec Under Linux
Set Up IPsec Under FreeBSD
Set Up IPsec in OpenBSD
Encrypt Traffic Automatically with Openswan
Forward and Encrypt Traffic with SSH
Automate Logins with SSH Client Keys
Use a Squid Proxy over SSH
Use SSH As a SOCKS Proxy
Encrypt and Tunnel Traffic with SSL
Tunnel Connections Inside HTTP
Tunnel with VTun and SSH
Generate VTun Configurations Automatically
Create a Cross-Platform VPN
Tunnel PPP
Chapter 11
Network Intrusion Detection
Detect Intrusions with Snort
Keep Track of Alerts
Monitor Your IDS in Real Time
Manage a Sensor Network
Write Your Own Snort Rules
Prevent and Contain Intrusions with Snort_inline
Automatically Firewall Attackers with SnortSam
Detect Anomalous Behavior
Automatically Update Snort’s Rules
Create a Distributed Stealth Sensor Network
Use Snort in High-Performance Environments with Barnyard
Detect and Prevent Web Application Intrusions
Scan Network Traffic for Viruses
Simulate a Network of Vulnerable Hosts
Record Honeypot Activity
Chapter 12
Recovery and Response
Image Mounted Filesystems
Verify File Integrity and Find Compromised Files
Find Compromised Packages
Scan for Rootkits
Find the Owner of a Network
Colophon
Return to
Network Security Hacks