The time now is Tue 18 Jun 2013, 18:51
All times are UTC - 4 |
| Author |
Message |
kitten
Joined: 13 Dec 2008 Posts: 8
|
Posted: Sun 18 Oct 2009, 16:38 Post_subject:
Nine ways LiveCD security could be defeated |
|
Look how clearly solutions to the online banking problem were laid out five years ago...
http://www.1729.com/secureinternetbanking/index.html
Wouldn't a bank be smart to offer its customers secure on-line banking that included -- (for a profit line set-up fee)
1: a business card size CD, that was the only way they could access their account via internet. Its single ap would be a locked-down browser that could only access their secure servers, using the account name and key for user to which it was issued.
2: a 2nd factor, wallet PIN card where PIN was only good for single transaction login. For deny ability, a customer could destroy its function by some special duress/panic PIN, like "911".
Since this problem is so technical to set up right, and fraught with slip up peril...
http://www.1729.com/blog/TenWaysLiveCDSecurityCouldFail.html
This is a problem for some BANK's big-bucks marketing and IT teams?
Consumers only get what they demand. Customers refusal to bank on-line costs banks money. I'd sure be attracted to a bank that offered the plan above.
And surely there is a way in this money area to raise contributions for Puppy's advancement.
|
|
Back to top
|
|
 |
kitten
Joined: 13 Dec 2008 Posts: 8
|
Posted: Tue 20 Oct 2009, 17:00 Post_subject:
I'm hearing security sirens, from the Pres on down... |
|
Here is where others with a Black Ops bent are taking their distros...
http://www.openwall.com/Owl/Owl-CD-large.shtml
or another example, this time lightweight: Note the FluxBox menus and tiny widget. Note "System Hardening" as a menu option.
http://techm4sters.org/forum/index.php?action=gallery;sa=view;id=46
But yea, its a daunting task...
http://mirrors.unixsol.org/netsecl/docu/netsecldocu.html
Yet since as even the Pres says, October "is national cyber security month in the US, with hundreds of federal, state and local government agencies, companies, non-profits and everyday citizens deploying themselves to educate millions of Americans about the importance of online security to themselves, their communities and the nation" - Peter Dinham in...
http://www.itwire.com/content/view/28614/53/
Every other day we read that Window$, unlike Linux, did not design-in security from the kernel. So now the country and the world must pay for its greed and rush to market.
Any inherent advantage the pristine Puppy CD has in privacy or security may be run over, unless we train each generation of Puppies to fight or evade new intruders and protect their RAM and their disk.
|
|
Back to top
|
|
 |
Lobster
Official Crustacean

Joined: 04 May 2005 Posts: 15109 Location: Paradox Realm
|
Posted: Thu 22 Oct 2009, 10:37 Post_subject:
|
|
We have a program under Network 'MTR traceroute'
this sounds like "geeky, geeky geek geek" to me - what does it mean if anything for security?
http://en.wikipedia.org/wiki/Traceroute
Developing GROWL for simple enhancements
http://www.murga-linux.com/puppy/viewtopic.php?p=353455#353455
_________________ Puppy WIKI
|
|
Back to top
|
|
 |
clarf

Joined: 13 Jun 2007 Posts: 606 Location: The old Lone Wolf
|
Posted: Fri 30 Oct 2009, 17:45 Post_subject:
|
|
A needed read for Linux security audits:
http://www.sans.org/score/checklists/linuxchecklist.pdf
|
|
Back to top
|
|
 |
mac84
Joined: 18 Feb 2008 Posts: 43
|
Posted: Sat 12 Dec 2009, 18:54 Post_subject:
|
|
iway officiallyway antway othingnay otay oday ithway isthay
|
|
Back to top
|
|
 |
SickPuppy
Joined: 17 Jan 2010 Posts: 46
|
Posted: Sat 30 Jan 2010, 11:04 Post_subject:
|
|
Black Ops Puppy could easily become a hit in China.
|
|
Back to top
|
|
 |
Q5sys

Joined: 11 Dec 2008 Posts: 887
|
Posted: Wed 03 Mar 2010, 14:17 Post_subject:
|
|
| droope wrote: | And here I found some interesting links:
http://murga-linux.com/puppy/viewtopic.php?search_id=965048490&t=24431
A user thinks we should have available:
nmap, hping2, wireshark, nessus, metsploit, ettercap, firewalk, paros, john the ripper, burp, webscarab.
|
Some are available as pets if you search the site, others arent. What would be nice is if someone could package them all together as an SFS file that we can load/unload as needed. I've got nmap, aircrack, nessus, wireshark loaded on my system currently.
BT is as far as im concerned the standard for a PenTesting Distro. And while I would never think that a puppy version could surpass it, it'd be nice if as I said above; there was a SFS file that we could load with alot of the tools that we'd use on a regular basis.
Is anyone else up for this? Making a SecTool SFS package? I'd be willing to pitch in and help on it.
Ive already got a list somewhere of what id consider a worthy addition.
|
|
Back to top
|
|
 |
clarf

Joined: 13 Jun 2007 Posts: 606 Location: The old Lone Wolf
|
Posted: Fri 26 Mar 2010, 11:36 Post_subject:
Hacker_busts_IE8_on_Windows_7_in_2_minutes |
|
"The lesson from this year's Pwn2Own is pretty simple, suggested Charlie Miller, another of Wednesday's winners. "What you can see at Pwn2Own is that bugs are still in software, and exploit mitigations like DEP and ASLR don't work. Even as [defensive measures] improve, researchers still end up winning"
More info at:
http://www.computerworld.com/s/article/9174101/Hacker_busts_IE8_on_Windows_7_in_2_minutes
|
|
Back to top
|
|
 |
edoc

Joined: 07 Aug 2005 Posts: 3942 Location: Southeast Georgia, USA
|
Posted: Wed 15 Sep 2010, 15:11 Post_subject:
|
|
Just as this fascinating thread was moving toward solutions it seems to have died ... sure was lots of fun to read!
Was a new thread started somewhere?
Please tell me that my favorite show has not been canceled!
_________________ Thanks! David
Home page: http://nevils-station.com
Don't google Search! http://duckduckgo.com
Multiple computers - currently running Puppy Exprimo ver. 5x15
|
|
Back to top
|
|
 |
Aitch

Joined: 04 Apr 2007 Posts: 6825 Location: Chatham, Kent, UK
|
Posted: Thu 16 Sep 2010, 08:27 Post_subject:
|
|
| Q5sys wrote: | Is anyone else up for this? Making a SecTool SFS package? I'd be willing to pitch in and help on it.
Ive already got a list somewhere of what id consider a worthy addition |
seems to have been the last interesting comment, though I don't think it got implemented, doc
Aitch
|
|
Back to top
|
|
 |
Lobster
Official Crustacean

Joined: 04 May 2005 Posts: 15109 Location: Paradox Realm
|
Posted: Thu 16 Sep 2010, 08:59 Post_subject:
|
|
This thread was created in response to those
terrified that their root running computers were
malware magnets and hacker (cracker) havens
Keep your mind clear
http://murga-linux.com/puppy/viewtopic.php?p=398158#398158
and you won't have to use GROWL (I never do)
http://murga-linux.com/puppy/viewtopic.php?p=335216#335216
Over to the Tin foil hat brigade . . .
_________________ Puppy WIKI
|
|
Back to top
|
|
 |
edoc

Joined: 07 Aug 2005 Posts: 3942 Location: Southeast Georgia, USA
|
Posted: Thu 16 Sep 2010, 09:57 Post_subject:
|
|
My primary interest is:
1. A small app optimized to seek out available public Wifi sites.
2. An app to defend my little Netbook Puppy when using public Wifi's.
3. An app for when a friend or neighbor needs help troubleshooting Wifi, especially for router security problems.
Is Growl a suotable answer?
Or ???
_________________ Thanks! David
Home page: http://nevils-station.com
Don't google Search! http://duckduckgo.com
Multiple computers - currently running Puppy Exprimo ver. 5x15
|
|
Back to top
|
|
 |
Q5sys

Joined: 11 Dec 2008 Posts: 887
|
Posted: Thu 25 Nov 2010, 12:40 Post_subject:
|
|
| Aitch wrote: | | Q5sys wrote: | Is anyone else up for this? Making a SecTool SFS package? I'd be willing to pitch in and help on it.
Ive already got a list somewhere of what id consider a worthy addition |
seems to have been the last interesting comment, though I don't think it got implemented, doc
Aitch  |
hadnt checked this thread in ages... I eventually made this... dont know if it'd be of interest to anyone.
_________________
My PC is for sale
|
|
Back to top
|
|
 |
edoc

Joined: 07 Aug 2005 Posts: 3942 Location: Southeast Georgia, USA
|
Posted: Thu 25 Nov 2010, 13:15 Post_subject:
|
|
Downloading now ...
_________________ Thanks! David
Home page: http://nevils-station.com
Don't google Search! http://duckduckgo.com
Multiple computers - currently running Puppy Exprimo ver. 5x15
|
|
Back to top
|
|
 |
Aitch

Joined: 04 Apr 2007 Posts: 6825 Location: Chatham, Kent, UK
|
Posted: Fri 26 Nov 2010, 01:24 Post_subject:
|
|
Q5sys
That's one way to fool the crackers....slip a puppy in unannounced with no fanfare.....
Interesting, but I think we still need better Lan/Wifi setup wizard to take full advantage of its capabilities
Couldn't go wardriving easily eh? [not with my eyes, I can't see the white on black... ]
Aitch
|
|
Back to top
|
|
 |
|
|
|
Rules_post_cannot Rules_reply_cannot Rules_edit_cannot Rules_delete_cannot Rules_vote_cannot You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001, 2005 phpBB Group
|