Home | 简体中文 | 繁体中文 | 杂文 | Search | ITEYE 博客 | OSChina 博客 | Facebook | Linkedin | 作品与服务 | Email

部分 X. Security

目录

128. Authentication
128.1. /etc/login.defs
128.2. PAM 插件认证
128.2.1. pam_tally2.so
128.2.2. pam_listfile.so
128.2.3. pam_access.so
128.2.4. pam_wheel.so
128.3. Network Authentication
128.3.1. Network Information Service (NIS)
128.3.1.1. 安装NIS服务器
128.3.1.2. Slave NIS Server
128.3.1.3. 客户机软件安装
128.3.1.4. Authentication Configuration
128.3.1.5. application example
128.3.1.6. Mount /home volume from NFS
128.3.2. OpenLDAP
128.3.2.1. Server
128.3.2.2. Client
128.3.2.3. User and Group Management
128.3.3. Kerberos
128.3.3.1. Kerberos 安装
128.3.3.2. Kerberos Server
128.3.3.3. Kerberos Client
128.3.3.4. Kerberos Management
128.3.3.5. OpenSSH Authentications
128.3.4. FreeRADIUS (Remote Authentication Dial In User Service)
128.3.4.1. 安装 FreeRADIUS
128.3.4.2. ldap
128.3.4.3. mysql
128.3.4.4. WAP2 Enterprise
128.3.5. SASL (Simple Authentication and Security Layer)
128.3.6. GSSAPI (Generic Security Services Application Program Interface)
129. Sniffer
129.1. nmap - Network exploration tool and security / port scanner
129.1.1. HOST DISCOVERY
129.1.1.1. -sP: Ping Scan - go no further than determining if host is online
129.1.2. SCAN TECHNIQUES
129.1.2.1. -sU: UDP Scan 扫描
129.1.2.2. -b <FTP relay host>: FTP bounce scan
129.1.3. PORT SPECIFICATION AND SCAN ORDER
129.1.3.1. -p <port ranges>: Only scan specified ports
129.1.4. SCRIPT SCAN
129.1.4.1. ftp-anon
129.1.4.2. mysql-info
129.1.4.3. http
129.1.4.4. snmp
129.1.4.5. SSHv1
129.1.4.6. --script-updatedb 更新脚本
129.1.5. OS DETECTION
129.1.5.1. -O: Enable OS detection 操作系统探测
129.1.6. OUTPUT
129.1.6.1. --open: Only show open (or possibly open) ports 操作系统探测
129.1.7. MISC
129.1.7.1. -6: Enable IPv6 scanning
129.1.7.2. -A: Enables OS detection and Version detection, Script scanning and Traceroute
129.1.8. Nmap Scripting Engine (NSE)
129.2. tcpdump - A powerful tool for network monitoring and data acquisition
129.2.1. 监控网络适配器接口
129.2.2. 监控主机
129.2.3. 监控TCP端口
129.2.4. 监控协议
129.2.5. 输出到文件
129.2.6. 保存结果
129.2.7. Cisco Discovery Protocol (CDP)
129.2.8. 案例
129.2.8.1. 监控80端口与icmp,arp
129.2.8.2. monitor mysql tcp package
129.2.8.3. HTTP 包
129.2.8.4. 显示SYN、FIN和ACK-only包
129.3. cdpr - Cisco Discovery Protocol Reporter
129.4. nc - TCP/IP swiss army knife
129.5. Unicornscan,Zenmap,nast
129.6. netstat-nat - Show the natted connections on a linux iptable firewall
129.7. Tcpreplay
129.8. Wireshark
130. sqlmap - automatic SQL injection and database takeover tool
130.1. Installation
130.2. 开始入住实验
130.2.1. 测试脚本
130.2.2. sqlmap.ini
130.3. Request参数
130.3.1. --method, --data
130.3.2. --cookie
130.3.3. --referer
130.3.4. --user-agent
130.3.4.1. -a
130.3.5. --headers
130.3.6. --referer
130.3.7. auth
130.3.7.1. --auth-type
130.3.7.2. --auth-cred
130.3.8. --proxy
130.3.9. --threads
130.3.10. --delay
130.3.11. --timeout
130.4. Injection
130.4.1. --dbms
130.4.2. --prefix
130.4.3. --postfix
130.4.4. --string
130.4.5. --regexp
130.4.6. --excl-str
130.4.7. --excl-reg
130.5. Techniques
130.5.1. --stacked-test
130.5.2. --time-test
130.5.3. --union-test
130.5.4. --union-tech
130.5.5. --union-use
130.6. Enumeration
130.6.1. dbs
130.6.2. --count
130.6.3. --dump/--dump-all
130.6.4. --sql-query
130.6.5. --sql-shell
130.7. Miscellaneous
130.7.1. --update
130.7.2. --save
131. Vulnerability Scanner
131.1. Nessus
131.2. OpenVAS
132. Injection & Penetration
132.1. Backtrack Linux
133. SELinux
133.1. getsebool - get SELinux boolean value
133.2. sestatus - SELinux status tool
133.3. setsebool - set SELinux boolean value
133.4. chcon - change file SELinux security context
133.5. rsync
134. Suricata Engine
135. psad
136. fwknop
137. fwsnort
138. nftables
139. Haka
comments powered by Disqus