More Reading

Here are books, tools and web sites that I find useful. Many of these were listed earlier as well.

General System Security

Web Security: A Step-by-Step Reference Guide
Lincoln Stein, Addison-Wesley Longman, 1998.

Practical Unix and Internet Security
Simson Garfinkle and Gene Spafford, O'Reilly & Associates, 1996.

Unix System Security: A Guide for Users and System Administrators
David Curry, Addison Wesley Longman, 1994

Firewalls and Internet Security
William Cheswick and Steve Bellovin, Addison-Wesley Longman, 1994.

BugTraq Archive
http://www.securityfocus.com

CERT Coordination Center (vulnerability reports)
ftp://info.cert.org/pub/

FIRST Incident and Response Security Teams
http://www.first.org/

System Configuration Checkers

COPS (system configuration checker)
ftp://ftp.cerias.purdue.edu/pub/tools/unix/scanners/cops/

TAMU
ftp://net.tamu.edu/pub/security/TAMU/

SATAN
http://www.cs.purdue.edu/coast/satan.html

Internet Security Scanner and Friends
http://www.iss.net

nmap port scanner
http://www.insecure.org/nmap

Tripwire
ftp://coast.cs.purdue.edu/pub/COAST/Tripwire/

Log Managers

Swatch
ftp://ftp.stanford.edu/general/security-tools/swatch/

Event Log Monitor
http://www.systemtools.com/

EventReader
http://www.strongsoftware.net/eventrd/

Aelita EventAdmin
http://www.aelita.net/Products/EventAdmin.htm

NTsyslog
http://www.sabernet.net/software/ntsyslog.html

User Management and Authentication

Sudo
http://www.courtesan.com/sudo/

Secure Shell
ftp://ftp.ssh.com/pub/ssh/

sbox
http://stein.cshl.org/~lstein/sbox/

Web Authoring Systems and Adjuncts

Apache::Stage (requires mod_perl)
http://www.cpan.org/

DAV
http://www.webdav.org

CVS
http://www.cyclic.com

FrontPage
http://www.microsoft.com

Apache Authentication

user_manage
http://stein.cshl.org/~lstein/user_manage/

Secure Sockets Layer

OpenSSL
http://www.openssl.org/

ftp://ftp.openssl.org/source/

mod_ssl
http://www.modssl.org/

ftp://ftp.modssl.org/source/

Verisign
http://digitalid.verisign.com/server/apacheNotice.htm

Thawte Consulting
http://www.thawte.com/certs/server/request.html


<< Previous Contents >> Next >>

Lincoln D. Stein, lstein@cshl.org
Cold Spring Harbor Laboratory
Last modified: Sun Jul 16 18:47:38 PDT 2000