Latest Post
Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

Vulture - Open Source Reverse Proxy / Web Application Firewall

Written By Unknown on Friday, 22 February 2013 | 00:56


Vulture is a reverse proxy that features Web-SSO and application firewall. Vulture is based on Apache2, mod_perl and mod_security. Vuture interfaces between Web applications and Internet to provide unified security and authentication.

The main features of Vulture are: 
  • SSO users with many methods supported 
  • LDAP, SQL, text file, RADIUS server, digital certificates ... 
  • Modular design allows you to add new authentication methods
  • The spread of authentication protected applications 
  • Encryption flow 
  • Filtering and rewriting content 
  • An application firewall based on ModSecurity 
  • Load balancing




    IPFire 2.13 - Core 66 released - An Open Source Firewall Distribution

    Written By Unknown on Thursday, 21 February 2013 | 23:23


    IPFire 2.13 is a new major version of IPFire, the Open Source Firewall distribution. The list of changes, enhancements, and fixes is endless.Following features which we’re the most excited about:

    Base System

    The most important components of the base system have been updated to include a brand new kernel based on the Linux 3.2 release. With that, IPFire now supports more hardware than ever before and many of the hardware problems from the past should be gone.
    The most basic system libraries have been replaced as well, giving us great performance and fixing some general security issues. If you’d like to know more about this specifically, please read this post on our planet.

    Quality of Service with CoDeL

    In case you are struggling with a slow internet connection, CoDeL is your solution. This new algorithm shares the bandwidth fairly between all connections. It doesn’t need any configuration at all, but when tied together with our Quality of Service features, CoDeL gives you the most out of your connection.

    ARM

    We have finally declared the ARM versions of IPFire as stable. Since the very first testing release back in October 2011, a multitude of things have improved. As of today, IPFire runs on many different platforms, such as Marvell Kirkwood and Texas Instruments OMAP4-based systems, and of course, the Raspberry Pi computer.
    The vast amount of people who have already been using IPFire ARM since we began to port it to the ARM architecture know that there was never really any big trouble to begin with. You can find more about this over here.

    IPsec VPNs with strongswan 5

    The IPsec implementation strongswan recently released a new version which cleaned up a significant amount of old code, some of which has been in use for over a decade. If you want to know the details, check out the IPFire planet post.

    Wireless LAN

    From our wishlist, we’ve implemented proper support for 5 GHz WLANs. Read this planet post to learn about the benefits.
    Latest release: IPFire 2.13 - Core 66
    Please click the button to download the IPFire ISO image for i586-compatible computers. This is the default image, you will most likely need to install IPFire. You may also pick your desired architecture from the tabs above and see a list of all image formats.
    Download IPFire 2.13 - Core 66 (ISO-Image - i586 - 93.4M)
    IPFire is a server distribution with intended to use as a firewall. It focuses on flexibility, and scales from small to middle sized business networks and home networks.

    Along with this hardened, minimalist come lots of addons that can be installed with a simple click. That's what makes IPFire different from other firewall distributions: it is easy to configure for any task, and easy to administer once it's set up.

    Features
    • stateful inspection firewall based on linux netfilter architecture
    • intrusion detection system with Guardian addon as extension (IPS system)
    • filter for invalid/non-standard packages
    • separate network segments for server (DMZ) and wireless with custom policies
    • DoS attack protection
    • application proxies for HTTP and FTP (with access control and content filtering) and DNS
    • incoming and outgoing packet filtering
    • Quality of Service and traffic shaping
    Source-

    Devil-Linux 1.6.3 released

    Written By Unknown on Friday, 11 January 2013 | 10:59


    Devil-Linux is a distribution which boots and runs completely from CDROM or USB flash drive. The configuration can be saved to a floppy diskette or a USB pen drive. Devil Linux was originally intended to be a dedicated firewall/router but now Devil-Linux can also be used as a dedicated server for many applications. Attaching an optional hard drive is easy, and many network services are included in the distribution.
    Because boot/OS and (optionally) configuration [in a tarball] are stored on read-only media, Devil-Linux offers high security with easy and safe upgrades, the system being fully configurable with no writeable system device. If hard drive(s) are added for data storage, LVM is standard (easing expansion and backup) and software Raid is straightforward. Virtual machine use is also well supported, with VMware modules built-in.

    Mon 31st Dec,2012 - Devil-Linux 1.6.3 released

    Author - Heiko

    Devil-Linux 1.6.3 has been released! This release brings lots of software updates, in addition to support for being a file and backup server for Apple computers. Please see the change log for details.

    Devil-Linux Downloads

    Hungary

      Luxembourg

      Greece

      Worldwide

      USA

        Austria

        Germany

        France

        Source-
        http://www.devil-linux.org/news/index.php?item=1999

        m0n0wall 1.34 released

        Written By Unknown on Tuesday, 13 November 2012 | 23:13

        m0n0wall is a project aimed at creating a complete, embedded firewall software package that, when used together with an embedded PC, provides all the important features of commercial firewall boxes (including ease of use) at a fraction of the price (free software).
        m0n0wall is based on a bare-bones version of FreeBSD, along with a web server, PHP and a few other utilities. The entire system configuration is stored in one single XML text file to keep things transparent.
        m0n0wall is probably the first UNIX system that has its boot-time configuration done with PHP, rather than the usual shell scripts, and that has the entire system configuration stored in XML format.

        m0n0wall provides many of the features of expensive commercial firewalls, including:
        • web interface (supports SSL)
        • serial console interface for recovery
          • set LAN IP address
          • reset password
          • restore factory defaults
          • reboot system
        • wireless support (including access point mode)
        • captive portal
        • 802.1Q VLAN support
        • IPv6 support
        • stateful packet filtering
          • block/pass rules
          • logging
        • NAT/PAT (including 1:1)
        • DHCP client, PPPoE and PPTP support on the WAN interface
        • IPsec VPN tunnels (IKE; with support for hardware crypto cards, mobile clients and certificates)
        • PPTP VPN (with RADIUS server support)
        • static routes
        • DHCP server and relay
        • caching DNS forwarder
        • DynDNS client and RFC 2136 DNS updater
        • SNMP agent
        • traffic shaper
        • SVG-based traffic grapher
        • firmware upgrade through the web browser
        • Wake on LAN client
        • configuration backup/restore
        • host/network aliases
        m0n0wall 1.34 released on 11/12/2012
        There are ready-made binary images for embedded computers from Soekris Engineering and PC Engines, a CF/IDE HD image for most standard PCs (other embedded ones may work, too) with either keyboard/monitor or serial console, a CD-ROM (ISO) image for standard PCs, a VMware image, as well as a tarball of the root filesystem. Refer to the installation instructions for information on how to install these files on the various platforms.
        Known issues:
        • WARNING: this version (any platform) no longer fits on 8 MB CF cards! (>= 16 MB required)
        • When upgrading from generic-pc 1.2x, you must install 1.3b7 first before you install this image. Other platforms are not affected.
        Changes in this release:
        • Backported from beta branch:
          • Eliminate modifying GETs from webGUI pages.
            Note: the API pages exec_raw.php and uploadconfig.php now require different parameters than before. exec_raw.php now requires the cmd to be given in a POST, and both pages need a valid CSRF magic token, which can be obtained by issuing a GET first without any parameters (see example in exec_raw.php comment).
          • Make rule moving and deletion on shaper rules page work like for firewall rules.
          • Add csrf-magic for CSRF protection in webGUI.
          • Fix potential XSS in diag_ping.php and diag_traceroute.php.
        • Increase key size of auto-generated webGUI certificates to 2048 bits.
        • Update default webGUI certificate/key.
        • Remove domain name handling from dhclient-script and change ARP command not to use sed (not used/available in m0n0wall).
        • Change virtualHW version to 7 for VMWare image to avoid errors in ESX 4
        Version: 1.34
        Release date:
        11/12/2012


        Source -

        MODSECURITY V-2.7.0 - Open Source Web Application Firewall

        Written By Unknown on Wednesday, 17 October 2012 | 03:33

        ModSecurity is a web application firewall that can work either embedded or as a reverse proxy. It provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.

        changes version 2.7.0 :

          * Fixed Pause action should work as a disruptive action (MODSEC-297).
          * Fixed Problem loading mod_env variables in phase 2 (MODSEC-226).
          * Fixed Detect cookie v0 separator and use it for parsing (MODSEC-261).
          * Fixed Variable REMOTE_ADDR with wrong IP address in NGINX version (MODSEC-337).
          * Fixed Errors compiling NGINX version.
          * Added Include directive into standalone module. IIS and NGINX module should
            support Include directive like Apache2.
          * Added MULTIPART_INVALID_PART flag. Also used in rule id 200002 for multipart strict
            validation.
          * Updated Reference Manual.

        Download latest Version :
        Microsoft IIS : ModSecurityIIS_2.7.0.msi (3.1 MB)
        Apache : modsecurity-apache_2.7.0.tar.gz (1.0 MB)
        Download other version |
        For more information & source -

        http://www.modsecurity.org/

        Previous posts regarding ModSecurity -
        http://santoshdudhade.blogspot.in/2012/04/what-ismodsecurity-or-modsecurity.html
        http://santoshdudhade.blogspot.in/2012/09/modsecurity-270-rc3-candidate-released.html
        http://santoshdudhade.blogspot.in/2012/04/secure-apache-2x-web-server-with.html
        http://santoshdudhade.blogspot.in/2012/07/mod-security-v267.html
        http://santoshdudhade.blogspot.in/2012/06/modsecurity-v270-rc1.html

        IPFire 2.11 - Core Update 62 released

        Written By Unknown on Friday, 14 September 2012 | 07:08

        IPFire is a Linux distribution that focusses on easy setup, good handling and high level of security. It is operated via an intuitive web-based interface which offers many configuration options for beginning and experienced system administrators. IPFire is maintained by developers who are concerned about security and who update the product regularly to keep it secure. IPFire ships with a custom package manager called Pakfire and the system can be expanded with various add-ons.

        Ip fire releasing the 62nd Core Update for IPFire 2.11. This update fixes some security problems and also adds some new functionality.

        We recommend that you update your IPFire installations as soon as possible if you are using the outgoing firewall in mode 1.
        Fixed: Outgoing firewall permits hosts on BLUE to access the internet

        In earlier releases, it was possible for hosts on the BLUE network to access resources on the internet which are allowed by the outgoing firewall although no permission has been granted to the host (blue access). This is a moderate risk.

        The connection overview on the web user interface now shows return paths. This means you are now able to see which host on the local and NATted network opened the connections.

        php has been update to version 5.3.16, which fixes a number of security problems and various bugs of other types as well.

        IPFire comes now with a script which lets you create VLAN interfaces for GREEN, BLUE and/or ORANGE. However, it is only possible to configure this from the command line. Check /var/ipfire/ethernet/vlans for the configuration.

        There are also updates to the usual set of databases: GeoIP, USB modeswitch, and PCI/USB devices.

        Latest release: IPFire 2.11 - Core 62

        Download IPFire 2.11 - Core 62
        (ISO-Image - i586 - 77.6M)
        Please click the button to download the IPFire ISO image for i586-compatible computers. This is the default image, you will most likely need to install IPFire.
        You may also pick your desired architecture from the tabs above and see a list of all image formats.

        Previous post regarding IPfire -

        ModSecurity 2.7.0-RC3 Candidate Released - Web application firewall

        Written By Unknown on Thursday, 13 September 2012 | 06:19

        ModSecurity is a web application firewall that can work either embedded or as a reverse proxy. It provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.


        XX NNN 2012 - 2.7.0-rc3 release log 

         * Fixed requests bigger than SecRequestBodyNoFilesLimit were truncated even engine mode was detection only.
         * Fixed double close() for multipart temporary files (Thanks Seema Deepak).
         * Fixed many small issues reported by Coverity Scanner (Thanks Peter Vrabek).
         * Fixed format string issue in ngnix experimental code. (Thanks Eldar Zaitov).
         * Added ctl:ruleRemoveTargetById/Tag/Msg and removed ctl:ruleUpdateTargetById/Tag/Msg.
         * Added IIS and Ngnix platform code.
         * Added new transformation utf8toUnicode.

        Download other versions -

        Documentation
        Live Wiki Documentation
        The Wiki Documentation will always be the most up-to-date.
        Reference Manual
        FAQ
        Migration Matrix
        Log Data Format Documentation
        Roadmap


        Visit website -

        http://www.modsecurity.org/
        Stable Releases

        ModSecurity is an open source product licensed under ASLv2. It comes with full source code and documentation. Older releases are signed by Ivan Ristic or Brian Rectanus. Newer releases are signed by Breno Silva. These public keys are available via most PGP key server mirrors.
        modsecurity-apache_2.6.7.tar.gz (PGP MD5)

        NOTE: Direct downloads are handled by the SourceForge.net project page. More downloads are available there than listed on this page.
        Snapshot/Candidate Releases

        As part of an ongoing effort to improve the overall release process, these snapshots will be very similar to full releases, except that they might also have some small issue to solve before release a stable version.
        ModSecurity v2.7.0 modsecurity-apache_2.7.0-rc3.tar.gz (v2.7.0-RC3) (CHANGES)

        ModSecurity for IIS v2.7.0 ModSecurityIIS_2.7.0-rc3.msi

        Development Releases

        If you would like to test out new features that are available in development releases, just follow these steps to sync with the SourceForge SVN repository:

        1. Create a directory to clone the code:
          mkdir /path/to/home/svn/modsecurity
          cd /path/to/home/svn
        2. Clone the source code:
          SVN:
          svn co https://mod-security.svn.sourceforge.net/svnroot/mod-security/m2/trunk modsecurity
          GIT:
          git svn clone --prefix=svn/ https://mod-security.svn.sourceforge.net/svnroot/mod-security/m2/trunk modsecurity
        Community-Produced Binary packages
        There are no binary packages on modsecurity.org. Below is a list of third-party sites that sometimes have an up-to-date binary version of ModSecurity:
        RHEL/CentOS Yum Repository (Jason Litka)
        http://www.jasonlitka.com/yum-repository/

        Debian (Alberto Gonzalez Iniesta):
        http://packages.debian.org/search?searchon=sourcenames&keywords=modsecurity-apache

        Fedora Core (Michael Fleming):
        http://fedoraproject.org/wiki/EPEL
        FreeBSD (Alex Dupre):
        http://www.freebsd.org/cgi/ports.cgi?query=mod_security&stype=all
        Gentoo:
        http://www.gentoo-portage.com/www-apache/mod_security
        Apache 2.x on Windows (Steffen):
        http://www.apachelounge.com/
        HP-UX (Internet Express):
        http://h20338.www2.hp.com/hpux11i/cache/324414-0-0-0-121.html
        Netware, Windows (Guenter Knauf):
        http://www.gknw.at/development/apache/


        Resources
        [1]   ModSecurity home page: http://www.modsecurity.org/

        Previous post regarding ModSecurity -
        http://santoshdudhade.blogspot.in/2012/04/what-ismodsecurity-or-modsecurity.html
        http://santoshdudhade.blogspot.in/2012/04/secure-apache-2x-web-server-with.html
        http://santoshdudhade.blogspot.in/2012/07/mod-security-v267.html

        Zentyal 3.0-rc2 released

        Written By Unknown on Friday, 7 September 2012 | 07:19

        Zentyal is an open source alternative to Windows Small Business Server
        Zentyal (formerly eBox Platform) is a Linux Small Business Server that can act as a Gateway, UTM, Office Server, Infrastructure Manager, Unified Communications Server or a combination of them. Zentyal offers an easy-to-use web interface to manage all your network services, from Internet access, network security, resource sharing, network infrastructure or communications.

        Zentyal is the open source alternative to Windows Small Business Server and it is being widely used in the small and medium businesses regardless of sector, industry or location as well as in the public administrations or in the education sector. It is estimated that there are over 50,000 active Zentyal installations all over the globe.

        Zentyal Migration Tool for Windows Server is also available for download, making the migration process from existing Windows environments easier.

        Zentyal development is funded by eBox Technologies that offers commercial support and cloud-based services on top of Zentyal server.


        Features

        • Gateway: transparent caching, load balancing, traffic shaping, content filtering...
        • UTM: firewall, IDS, VPN management, antispam, antivirus, ...
        • Infrastructure management: DHCP, DNS, NTP, certificates, ...
        • Office server: LDAP, PDC, file & printer sharing, backup, groupware, ...
        • Unified Communications: email, IM, VoIP
        • LDAP replication and Windows Active Directory synchronization

        Download other versions -

        Visit Website -
        Documentation -

        1st Step: Download Zentyal 2.2-2


        Choose the version you prefer (32-bit or 64-bit version) and download the latest stable version of Zentyal. 

        Alternatively, you can also test Zentyal quickly and easily with the Virtual Machine images.

        2nd Step: Install Zentyal

        Once you have finished downloading Zentyal, create a CD or USB stick with the ISO image. Then, insert the CD/USB stick in your CD drive/USB port, restart your computer and follow the instructions that appear on your screen. 
        Helpful Information



        360-FAAR Firewall Analysis Audit Repair v0.2.4

        Written By Unknown on Friday, 27 July 2012 | 05:33

        360-FAAR Firewall Analysis Audit Repair - 360-FAAR Analyze FW1 Cisco Netscreen Policy Offline Using Config/Logs

        360-FAAR (Firewall Analysis Audit and Repair) is an offline, command line, Perl firewall policy manipulation tool to filter, compare to logs, merge, translate and output firewall commands for new policies, in Checkpoint dbedit, Cisco ASA or ScreenOS commands, and its one file!

        Read Policy and Logs for -

        Checkpoint FW1 (in odumper.csv / logexport format),
        Netscreen ScreenOS (in get config / syslog format),
        Cisco ASA (show run / syslog format),

        360-FAAR uses both inclusive and exclusive CIDR and text filters, permitting you to split large policies into smaller ones for virutalisation at the same time as removing unused connectivity.

        360-FAAR supports, policy to log association, object translation, rulebase reordering and simplification, rule moves and duplicate matching automatically. Allowing you to seamlessly move rules to where you need them.

        TRY: 'print' mode. One command, and spreadsheet for your audit needs!


        Features
        • WRITTEN IN SIMPLE Perl - NEEDS ONLY STANDARD MODULES - IS ONE FILE
        • Easy to Edit Menu Driven Text Interface
        • Capable of manipulating tens of thousands of rules, objects and groups
        • Handles infinitely deep groups
        • Capable of CIDR filtering connectivity in/out of policy rulebases.
        • Capable of merging rulebases.
        • Identifies existing connectivity in rulebases and policies
        • Automatically performs cleanup if a log file is provided.
        • Keeps DR connecitvity via any text or IP tag
        • Encryption rules can be added during policy moves to remove the "merge from" rules for traffic that would be encrypted by the time it reached the firewall on which the "merge to" policy is to be installed - sounds complicated but its not in practice - apropriate ike and esp rules should be added manually
        • Runs consistency checks on its own objects and rule definitions
        • Extendable via a simple elsif in the user interaction loop section.
        • EASY TO EXECUTE:
        • ./360-faar.pl <FW CONFIG TYPE> <log> <config> <nats> <FW CONFIG TYPE> <log> <config> <nats> <FW CONFIG TYPE> <log> <config> <nats>
        • CONFIG TYPES: - cisco soon!
        • od = logexported logs, object dumper format config, fwdoc format nat rules csv
        • ns = syslog format logs, screenos6 format config, nats are included in policy but not processed fuly yet, fwdoc format nats can be used though
        • cs = cisco asa syslog file, cisco ASA format config, - not ready yet
        • OUTPUT TYPES:
        • od = output an odumper/ofiller format config to file, and print the dbedit for the rulebase creation to screen
        • ns = outputs netscreen screenos6 objects and policies (requires a netscreen config or zone info)
        • cs = cisco asa format config - not ready yet
        • By default 360-FAAR accepts exactly 3 configs on the command line.
        • Make an empty file called "fake" and and use this as the file name, for log config and nats if you want to process less than 3 configs at once.
        • Log file headders in fw1 logexported logs are found automatically so many files can be cated together
        • FUTHER PROCESSING AND MANUAL EDITING:
        • Output odumper/ofiller format files and make them more readable (watchout for spaces in names) using the numberrules helper script
        • Edit these csv's in Openoffice or Excell using any of the object or group definitions from the three loaded configs.
        • You can then use this file as a template to translate to many different firewalls using the 'bldobjs' mode
        Download other version files -

        Visit website -
        For more information -
        Screenshot -


        Mod Security v2.6.7

        Written By Unknown on Wednesday, 25 July 2012 | 04:35

        ModSecurity is a web application firewall that can work either embedded or as a reverse proxy. It provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.


        23 Jul 2012 - 2.6.7
        * Fixed PCRE mismtach version warning message (Thanks Victor Julien).
        * Fixed explicit target replacement using SecUpdateTargetById was broken.
        * The ctl:ruleUpdateTargetById is deprecated and will be removed for future versions since
        there is no safe way to use it per-request.
        * Added ctl:ruleRemoveTargetById that can be used to exclude targets to be processed per-request.

        22 Jun 2012 - 2.7.0-rc2
        * Fixed compilation errors and warnings under Windows platform.
        * Fixed SecEncryptionKey was not working as expected.

        Download ModSecurity 2.6.7 – 

        Previous posts regarding ModSecurity

        Devil Linux - the firewall

        Written By Unknown on Saturday, 21 July 2012 | 02:14

        Devil-Linux is a distribution which boots and runs completely from CDROM or USB flash drive. The configuration can be saved to a floppy diskette or a USB pen drive. Devil Linux was originally intended to be a dedicated firewall/router but now Devil-Linux can also be used as a dedicated server for many applications. Attaching an optional hard drive is easy, and many network services are included in the distribution.

        Because boot/OS and (optionally) configuration [in a tarball] are stored on read-only media, Devil-Linux offers high security with easy and safe upgrades, the system being fully configurable with no writeable system device. If hard drive(s) are added for data storage, LVM is standard (easing expansion and backup) and software Raid is straightforward. Virtual machine use is also well supported, with VMware modules built-in.

        What makes Devil Linux the best Firewall on the market
        Devil-Linux is not like any other distribution. It is created from IT Administators for IT Administrators. We know what you need, because we need it too!

        Boots from CD

        Traditionally Devil Linux boots from a CD-ROM which is read-only by nature. This means an intruder will not be able to install i.e. an "ordinary" root kit.

        Boots from USB pendrive

        As all movable parts in your computer, the CD-ROM is prone to failure. This is the reason why we provide a script to install the entire system on an USB pendrive. Note: You need a computer which is able to boot from USB harddisks, in order to use this feature.

        Configuration is saved on a floppy disc or on a USB Flash Media

        Due to the read-only nature of CD-ROMs, you need a place to save your configuration files. This can either traditionally be on a floppy disc or on a USB flash media (like a pendrive), to increase the reliability.

        Configuration can be burned on CD

        There are cases when you have to ensure that the configuration can't be modified. This is the reason why we provide the feature for loading the configuration archive from the (read-only) CD-ROM.

        No need for a harddisk although it can optionally be used for data storage

        Most distributions need a harddisk for data storage, with DL this is completely optional. Reasons for adding harddisk data storage would be, i.e. when you use DL as your email hosting server or for file sharing. DL uses dynamic disc configuration via the Logical Volume Manager, which makes adding and maintaining the harddisk storage easy (regardless if you have only 1 GB or 1 TB of data).

        Support for Intel 486 and higher

        Got some old boxes in your bone yard? For most internet connection an old computer is enough to play the role of your Firewall, this is the reason why we still support 486 CPUs. But we're not stuck with old technologies, we also provide you a version vor 686 CPUs with SMP support.

        IPTables/Netfilter Support

        State of-the-art firewall functionality is provided by IPTables/Netfilter, which includes features like connection tracking. Devil-Linux adds many more Netfilter modules then you find in your standard Linux Kernel.

        Create your own, customized version with our Build System

        Since everybody has different requirements, Devil-Linux provides you with an easy-to-use build system, which enables you to create your own customized version. You can i.e. only add the packages you need on your machine or even add features which are currently missing in the mainstream version.

        Directly supported by Firewall Builder

        Don't like writing your Firewall rules by hand? Get Firewall Builder and use a great GUI tool to create your ruleset. Firewall Builder supports writing the rules directly onto your configuration floppy.

        No graphical desktop

        Devil-Linux has not support for i.e. X-Server. This greatly reduces the requirements to run DL and also greatly increases security by reducing the number of running programs. (Try this on Windows...)

        Almost all binaries are compiled with the GCC Stack Smashing Protector

        Except of a very few exceptions, all binaries are compiled with the GCC Stack Smashing Protector. Applications written in C will be protected by the method that automatically inserts protection code into an application at compilation time. The protection is realized by buffer overflow detection and the variable reordering feature to avoid the corruption of pointers.

        Improved Kernel Security through GRSecurity

        GRSecurity adds several new features and protection mechanisms to the Linux Kernel itself. This includes Chroot restrictions (did you know that it is easy to break out of a non-protected chroot jail?), Address space modification protection (like PAX), Auditing features, Randomization features and much more.

        Easy to use chroot

        Devil-Linux has support for chroot jails which is easy to use. Just define what you need in a configuration file and our jail script will take care of the rest. Some pre-defined configurations are already available.
        Applications for Devil-Linux

        The traditional application for Devil-Linux is to use it as Router/Firewall. Below you see a list of other possible applications:
        Proxy Server
        DNS Server
        Mail Server with TLS support and Spam and Virus filtering
        HTTP Server
        FTP Server
        File Server
        VPNs with X.509 support
        DHCP Server
        NTP Server
        IDS Node

        Screenshots-



         
        Support : Creating Website | Johny Template | Mas Template
        Copyright © 2011. Turorial Grapich Design and Blog Design - All Rights Reserved
        Template Created by Creating Website Published by Mas Template
        Proudly powered by Blogger