<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Foogazi.com &#187; Security</title>
	<atom:link href="http://www.foogazi.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.foogazi.com</link>
	<description>Linux Tips, Tricks, and Opinions</description>
	<lastBuildDate>Thu, 18 Aug 2011 18:53:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
		<item>
		<title>Linux Malware &#8211; Proof that Linux is not as secure as we all think</title>
		<link>http://www.foogazi.com/2009/12/01/linux-malware-proof-that-linux-is-not-as-secure-as-we-all-think/</link>
		<comments>http://www.foogazi.com/2009/12/01/linux-malware-proof-that-linux-is-not-as-secure-as-we-all-think/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 00:43:59 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.foogazi.com/?p=398</guid>
		<description><![CDATA[There was an interesting post on Ask Slashdot discussing the ethics of releasing non-malicious Linux malware to simply prove a point to all of the people who rant and rave about Linux being so secure.  A developer by the name of buchner.johannes buchner.johannes writes: &#8220;I was fed up with the general consensus that Linux is [...]]]></description>
			<content:encoded><![CDATA[<p>There was an interesting <a title="Linux Malware - Proof that Linux is not as secure as we all think" href="http://ask.slashdot.org/story/09/12/01/0025213/Ethics-of-Releasing-Non-Malicious-Linux-Malware#topcomment">post</a> on Ask Slashdot discussing the ethics of releasing non-malicious Linux malware to simply prove a point to all of the people who rant and rave about Linux being so secure.  A developer by the name of buchner.johannes</p>
<p>buchner.johannes writes:</p>
<blockquote><p>&#8220;I was fed up with the general consensus that Linux is oh-so-secure and has no malware. After a week of work, I finished a package of malware for Unix/Linux. Its whole purpose is to help white-hat hackers point out that a Linux system can be turned into a botnet client by simply downloading BOINC and attaching it to a user account to help scientific projects. The malware does not exploit any security holes, only loose security configurations and mindless execution of unverified downloads. I tested it to be injected by a PHP script (even circumventing safe mode), so that the Web server runs it; I even got a proxy server that injects it into shell scripts and makefiles in tarballs on the fly, and adds onto Windows executables for execution in Wine. If executed by the user, the malware can persist itself in cron, bashrc and other files. The aim of the exercise was to provide a payload so security people can &#8216;pwn&#8217; systems to show security holes, without doing harm (such as deleting files or disrupting normal operation). But now I am unsure of whether it is ethically OK to release this toolkit, which, by ripping out the BOINC payload and putting in something really evil, could be turned into proper Linux malware. On the one hand, the way it persists itself in autostart is really nasty, and that is not really a security hole that can be fixed. On the other hand, such a script can be written by anyone else too, and it would be useful to show people why you need SELinux on a server, and why verifying the source of downloads (checksums through trusted channels) is necessary. Technically, it is a nice piece, but should I release it? I don&#8217;t want to turn the Linux desktop into Windows, hence I&#8217;m slightly leaning towards not releasing it. What does your ethics say about releasing such grayware?&#8221;</p></blockquote>
<p>This is a great thing for the community at large to see that Linux can be exploited with malware just like it&#8217;s rival operating systems.  However, I share the same concerns the developer does.  This indeed could result in a black-hat user injecting something malicious into the code and actually turning the example into real evil malware. I&#8217;m on the fence though, maybe this is what Linux users need to prove that we aren&#8217;t like typical Windows users who click any random link and download any random software from any random untrusted third-party site.  A user who goes by the name of <em>silentcoder </em>wrote: &#8220;Linux users (hardly ever) download and install software from the internet. We download and install packages from repositories. The average user simply cannot tell the difference between a useful piece of freeware and a bugridden-malware-spreading piece of add-ware.&#8221;</p>
<p>Paranoia aside, this definitely proves that Linux is just as susceptible to malware and viruses as any other operating system.  But, as I&#8217;ve always said, viruses and malware are usually a result of user error, no matter the operating system.</p>
<p>What do you all think, should this type of code be released as proof of concept even if it&#8217;s risking malicious manipulation?  Should we all just start using SELinux and be done with it?</p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=398&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d398').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d398" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;submitHeadline=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;title=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;title=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;title=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;bm_description=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;T=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;title=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;title=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think+@+http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2009%2F12%2F01%2Flinux-malware-proof-that-linux-is-not-as-secure-as-we-all-think%2F&amp;t=Linux+Malware+%26%238211%3B+Proof+that+Linux+is+not+as+secure+as+we+all+think" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d398').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2009/12/01/linux-malware-proof-that-linux-is-not-as-secure-as-we-all-think/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Basic Linux Security Tips</title>
		<link>http://www.foogazi.com/2007/10/28/basic-linux-security-tips/</link>
		<comments>http://www.foogazi.com/2007/10/28/basic-linux-security-tips/#comments</comments>
		<pubDate>Sun, 28 Oct 2007 19:05:12 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=100</guid>
		<description><![CDATA[William Stearns has a good write up on Linux security tips for first time Linux users. Here are a few: Set up regular updates for your particular Linux distribution Lock your system when you step away from it. To lock the Gnome graphical desktop, run the following command, part of the &#8220;gnome-screensaver&#8221; package:gnome-screensaver-command &#8211;lockFrom a [...]]]></description>
			<content:encoded><![CDATA[<p>William Stearns has a good <a href="http://isc.sans.org/diary.html?storyid=3514" title="Basic Linux Security Tips" target="_blank">write up</a> on Linux security tips for first time Linux users.</p>
<p>Here are a few:</p>
<ol>
<li>Set up regular updates for your particular Linux distribution</li>
<li>Lock your system when you step away from it.  To lock the Gnome graphical desktop, run the following command, part of the &#8220;gnome-screensaver&#8221; package:gnome-screensaver-command &#8211;lockFrom a text console, run this, part of the vlock package:vlock -aFor KDE, right click on the desktop and select &#8220;Lock Session&#8221;.  In Ubuntu, press Ctrl-Alt-l (the letter &#8220;Ell&#8221;, configurable in System/Preferences/Keyboard shortcuts).  All require the password of the logged-in user to continue work.</li>
<li>Do your day-to-day work with a non-root account.  When you need to do root-level tasks, become root with &#8220;sudo&#8221; or &#8220;su&#8221; long enough to do the task (alternately, log in as root on a text console for this task). <a href="http://www.stearns.org/doc/sudo.current.html">http://www.stearns.org/doc/sudo.current.html</a></li>
</ol>
<p>Go check out the rest of the tips.</p>
<p><!--adsense#square--></p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=100&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d100').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d100" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;submitHeadline=Basic+Linux+Security+Tips&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;title=Basic+Linux+Security+Tips" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;title=Basic+Linux+Security+Tips" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;title=Basic+Linux+Security+Tips" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;bm_description=Basic+Linux+Security+Tips" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;T=Basic+Linux+Security+Tips" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;title=Basic+Linux+Security+Tips" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;title=Basic+Linux+Security+Tips" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Basic+Linux+Security+Tips+@+http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2007%2F10%2F28%2Fbasic-linux-security-tips%2F&amp;t=Basic+Linux+Security+Tips" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d100').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2007/10/28/basic-linux-security-tips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Best Linux Security Tools</title>
		<link>http://www.foogazi.com/2007/01/03/the-best-linux-security-tools/</link>
		<comments>http://www.foogazi.com/2007/01/03/the-best-linux-security-tools/#comments</comments>
		<pubDate>Wed, 03 Jan 2007 19:26:41 +0000</pubDate>
		<dc:creator>Adam Kane</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[guides]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=76</guid>
		<description><![CDATA[You can never be too safe these days. Viruses, spyware, rootkits, remote exploits, you just never know what security issue is going to be your downfall. That&#8217;s why it is important as a Linux administrator to have an understanding of some of the best Linux security tools available to you. In this article, you will [...]]]></description>
			<content:encoded><![CDATA[<p>You can never be too safe these days. Viruses, spyware, rootkits, remote exploits, you just never know what security issue is going to be your downfall. That&#8217;s why it is important as a Linux administrator to have an understanding of some of the <strong>best Linux security tools</strong> available to you. In this article, you will learn about ten of <strong>the best Linux security tools</strong>, and resources on how to use them to your advantage.</p>
<p><!--adsense#square--></p>
<ul>
<li><strong><a href="http://insecure.org/nmap/" title="Nmap Security Scanner" target="_blank">Nmap Security Scanner</a><br />
</strong> Nmap, which stands for &#8220;Network Mapper&#8221; is a free open source utility that allows you to explore and audit a network. From the website: &#8220;Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics.&#8221;<br />
For Nmap installation documents, go <a href="http://insecure.org/nmap/install/" target="_blank" title="Nmap installation documents">here</a>.<br />
There is a very useful tutorial <a href="http://www.nmap-tutorial.com/html/nmap-tutorial-single.html" title="Nmap Tutorial" target="_blank">here</a> on the numerous scan types Nmap allows.<br />
<a href="http://insecure.org/nmap/docs/nmap-mindmap.pdf" target="_blank" title="Nmap Mindmap">This PDF</a> is a great print-out reference that includes all of the major Nmap options.</li>
<li><a href="http://www.nessus.org/" target="_blank" title="Nessus Security Scanner"><strong>Nessus Vulnerability Scanner</strong><br />
</a>Nessus is a vulnerability scanner that probes your network machines against an up-to-date security vulnerability database, alerting you of security holes, with detailed analysis on how to fix each hole.   From the Nessus website: &#8220;Nessus is the world&#8217;s most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the world&#8217;s largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications.&#8221;<br />
See an example scan report <a href="http://www.nessus.org/demo/report.html" title="Nessus example scan report" target="_blank">here</a>.<br />
For Nessus installation documents, go <a href="http://www.nessus.org/documentation/index.php?doc=install" title="Nessus installation documents" target="_blank">here</a>.<br />
A nice technical guide to Nessus can be found <a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1159345,00.html" title="Nessus technical guide" target="_blank">here</a>.<br />
The Nessus knowledge base is <a href="http://www.edgeos.com/nessuskb/" title="Nessus knowledge base" target="_blank">here</a>.</li>
<li><strong><a href="http://clamav.net/" title="Clam AntiVirus">Clam AntiVirus</a></strong><br />
ClamAV is a GPL anti virus toolkit. The main purpose of ClamAV is the integration with mail servers, but can also be used to scan files for viruses on the command line. It provides a flexible and scalable multi-threaded daemon, a command line scanner and a virus database that is kept up to date.  The most popular use of ClamAV is on a mail server, tied in with a anti-spam application like <a href="http://spamassassin.apache.org/" target="_blank" title="Spam Assassin">Spam Assassin</a>.<br />
For installation help, go <a href="http://wiki.clamav.net/Main/FirstInstallation" target="_blank" title="Clam AntiVirus Installation Help">here</a>.<br />
The Clam AntiVirus wiki can be found <a href="http://wiki.clamav.net/Main/WebHome" target="_blank" title="Clam AntiVirus Wiki">here</a>.<br />
<a href="http://clamav.net/doc/latest/clamdoc.pdf" target="_blank" title="Clam AntiVirus PDF Document">This PDF</a> document covers all you need to know about ClamAV.</li>
<li><a href="http://snort.org/" title="Snort" target="_blank"><strong>Snort</strong><br />
</a>Snort is one of the greatest weapons you can have in the fight against intrusions.  Snort is mainly used in three different ways: as a packet sniffer, a packet logger, or as a complete intrusion detection system (IDS).  From the website: &#8220;Snort is an open source network intrusion prevention system, capable         of performing real-time traffic analysis and packet logging on IP networks.         It can perform protocol analysis, content searching/matching and can         be used to detect a variety of attacks and probes, such as buffer overflows,         stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts,       and much more.&#8221;<br />
The official Snort users manual can be found <a href="http://snort.org/docs/snort_htmanuals/htmanual_261/" title="Snort Users Manual" target="_blank">here</a>.<br />
For a very complete comprehensive list of documents, go <a href="http://snort.org/docs/" title="Snort Documents" target="_blank">here</a>.</li>
<li><a href="http://www.chkrootkit.org" title="Chkrootkit" target="_blank"><strong>Chkrootkit</strong><br />
</a>Chkrootkit is a tool designed to locally check for signs of a root kit on your Linux machine.  &#8220;Root kits&#8221; are basically files that can hide on your machine after a break in that allow the attacker to gain access to your computer in the future.<br />
<a href="http://www.giac.org/practical/gsec/Bill_Hutchison_GSEC.pdf" target="_blank" title="Chkrootkit PDF">This PDF</a> explains adding chkrootkit to your auditing arsenal.</li>
<li><a href="http://sourceforge.net/projects/tripwire/" title="Tripwire" target="_blank"><strong>Tripwire</strong><br />
</a>Tripwire is a security and data integrity tool useful for monitoring and alerting on specific file change(s) on a range of systems.  Basically, tripwire has the ability to alert you when files have been modified on your system.<br />
A comprehensive guide to implementing tripwire can be found <a href="http://sourceforge.net/docman/display_doc.php?docid=2078&amp;group_id=3130" target="_blank" title="Implementing Tripwire">here</a>.<br />
<a href="http://www.alwanza.com/howto/linux/tripwire.html" target="_blank" title="Setting up Tripwire">This</a> is a nice howto on setting up tripwire.</li>
<li><a href="http://rkhunter.sourceforge.net/" title="Root Kit Hunter" target="_blank"><strong>Rootkit Hunter</strong><br />
</a>Rootkit Hunter is a great tool for analyzing and monitoring the security of your systems.  Like Chkrootkit, this tool also checks for rootkits that may be hiding on your machine, as well as other tools on your system that may be potentially dangerous.<br />
A detailed guide on downloading and installing Rootkit Hunter can be found <a href="http://wiki.linuxquestions.org/wiki/Rootkit_Hunter" target="_blank" title="Rootkit Hunter">here</a>.</li>
<li><a href="http://www.kismetwireless.net/" title="Kismet" target="_blank"><strong>Kismet</strong><br />
</a>From the website: &#8220;Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system.&#8221;  If you have a wireless network, or travel with a laptop, this security tool is a must have.<br />
<a href="http://www.kismetwireless.net/documentation.shtml#readme" target="_blank" title="Kismet Readme">This</a> Kismet readme covers just about all you need to know.<br />
There is also a lot of useful information located within the <a href="http://www.kismetwireless.net/Forum/General/" target="_blank" title="Kismet Forum">Kismet forums</a>.<a href="http://snort.org/" title="Snort" target="_blank"><br />
</a></li>
<li><strong><a href="http://www.shorewall.net/" target="_blank" title="Shorewall Firewall">Shorewall</a></strong><br />
Shorewall is a very powerful and flexible firewall that utilizes iptables and Netfilter.  Very flexible configuration allows the firewall to be used in a wide variety of firewall/gateway/router and VPN environments.<br />
The Shorewall Installation document can be found <a href="http://www.shorewall.net/Install.htm" target="_blank" title="Shorewall Install Doc">here</a>.<br />
<a href="http://www.shorewall.net/shorewall_quickstart_guide.htm" target="_blank" title="Shorewall Quick Start Guide">Here</a> is a quick start guide to using Shorewall.<br />
Shorewall Features can be found <a href="http://www.shorewall.net/shorewall_features.htm" target="_blank" title="Shorewall Features">here</a>.</li>
<li><strong><a href="http://www.wireshark.org/" title="Wireshark" target="_blank">Ethereal (Now called Wireshark)</a></strong><br />
Wireshark is a very popular network protocol anyalizer that has a varaiety of security features including a packet browser, live capture and offline analysis and more.  Basically, Wireshark captures packets going across the network and displays them to you with as much detail possible.  From the users guide: &#8220;You could think of a network packet analyzer as a measuring device used to  	examine what&#8217;s going on inside a network cable, just like a voltmeter is  	used by an electrician to examine what&#8217;s going on inside an electric cable  	(but at a higher level, of course).&#8221;<br />
<a href="http://www.wireshark.org/docs/wsug_html/" title="Wireshark Users Guide" target="_blank">Here</a> is the Wireshark users guide.<br />
The Wireshark wiki is <a href="http://wiki.wireshark.org/" target="_blank" title="Wireshark Wiki">here</a>.</p>
<ul><strong> </strong></ul>
</li>
<p><strong><strong> </strong></strong></ul>
<p>Now that you&#8217;ve gotten a glimpse at ten of the best Linux security tools, it is up to you to install them and put them to use in your network environment.<br />
<!--adsense#square--></p>
<p><!--adsense#square--></p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=76&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d76').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d76" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;submitHeadline=The+Best+Linux+Security+Tools&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;title=The+Best+Linux+Security+Tools" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;title=The+Best+Linux+Security+Tools" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;title=The+Best+Linux+Security+Tools" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;bm_description=The+Best+Linux+Security+Tools" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;T=The+Best+Linux+Security+Tools" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;title=The+Best+Linux+Security+Tools" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;title=The+Best+Linux+Security+Tools" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+The+Best+Linux+Security+Tools+@+http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F03%2Fthe-best-linux-security-tools%2F&amp;t=The+Best+Linux+Security+Tools" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d76').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2007/01/03/the-best-linux-security-tools/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>WordPress Exploit</title>
		<link>http://www.foogazi.com/2007/01/02/wordpress-exploit/</link>
		<comments>http://www.foogazi.com/2007/01/02/wordpress-exploit/#comments</comments>
		<pubDate>Tue, 02 Jan 2007 19:51:54 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=73</guid>
		<description><![CDATA[David Kierznowski has uncovered an exploit in the popular WordPress blogging software that everyone should be aware of. Popular security website Security Focus has the issue documented, and it is suggested that you upgrade your template.php file as soon as possible to avoid becoming a victim. The WordPress team has issued an updated release, version [...]]]></description>
			<content:encoded><![CDATA[<p><!--adsense#right--></p>
<p>David Kierznowski has uncovered an <a href="http://michaeldaw.org/md-hacks/wordpress-templatephp-exploit/" target="_blank" title="Wordpress Template PHP Exploit">exploit</a> in the popular WordPress blogging software that everyone should be aware of. Popular security website Security Focus has the issue <a href="http://www.securityfocus.com/bid/21782/info" target="_blank" title="Wordpress Template PHP Exploit">documented</a>, and it is suggested that you upgrade your template.php file as soon as possible to avoid becoming a victim.</p>
<p>The WordPress team has issued an updated release, version 2.0.6 that contains a fix.</p>
<p>Simply put, to fix the wordpress exploit, visit the <a href="http://trac.wordpress.org/changeset/4665" title="How to fix the wordpress exploit" target="_blank">wordpress site</a> and edit line 114 in your template.php file.</p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=73&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d73').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d73" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;submitHeadline=WordPress+Exploit&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;title=WordPress+Exploit" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;title=WordPress+Exploit" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;title=WordPress+Exploit" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;bm_description=WordPress+Exploit" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;T=WordPress+Exploit" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;title=WordPress+Exploit" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;title=WordPress+Exploit" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+WordPress+Exploit+@+http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2007%2F01%2F02%2Fwordpress-exploit%2F&amp;t=WordPress+Exploit" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d73').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2007/01/02/wordpress-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Create stronger passwords</title>
		<link>http://www.foogazi.com/2006/12/26/create-stronger-passwords/</link>
		<comments>http://www.foogazi.com/2006/12/26/create-stronger-passwords/#comments</comments>
		<pubDate>Tue, 26 Dec 2006 18:54:03 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=70</guid>
		<description><![CDATA[Safepasswd is a website dedicated to helping you choose a safe and secure password. The secure passwords are automatically generated for you, allowing you the following options: easy to remember, letters only, numbers only, letters and numbers, all characters, and hex. This is a great tool for both administrators and standard computer users, as it [...]]]></description>
			<content:encoded><![CDATA[<p><!--adsense#square--></p>
<p><a href="http://www.safepasswd.com/" title="Safepasswd" target="_blank">Safepasswd</a> is a website dedicated to helping you choose a safe and secure password. The secure passwords are automatically generated for you, allowing you the following options: easy to remember, letters only, numbers only, letters and numbers, all characters, and hex. This is a great tool for both administrators and standard computer users, as it practices the need to <strong>create stronger passwords</strong>.</p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=70&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d70').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d70" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;submitHeadline=Create+stronger+passwords&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;title=Create+stronger+passwords" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;title=Create+stronger+passwords" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;title=Create+stronger+passwords" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;bm_description=Create+stronger+passwords" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;T=Create+stronger+passwords" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;title=Create+stronger+passwords" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;title=Create+stronger+passwords" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Create+stronger+passwords+@+http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F26%2Fcreate-stronger-passwords%2F&amp;t=Create+stronger+passwords" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d70').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2006/12/26/create-stronger-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Management Concerns with IE and Firefox</title>
		<link>http://www.foogazi.com/2006/12/12/password-management-concerns-with-ie-and-firefox/</link>
		<comments>http://www.foogazi.com/2006/12/12/password-management-concerns-with-ie-and-firefox/#comments</comments>
		<pubDate>Tue, 12 Dec 2006 17:09:26 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=62</guid>
		<description><![CDATA[SecurityFocus&#8217; Mikhael Felker has written part two of his analysis of the security mechanisms, risks, attacks, and defenses of the two most commonly used password management systems: those found in Internet Explorer and Firefox. Felker outlines the following areas of discussion: Password storage mechanisms: The means of safeguarding usernames and passwords on the local file [...]]]></description>
			<content:encoded><![CDATA[<p><!--adsense--></p>
<p>SecurityFocus&#8217; <span class="author"><a href="mailto:mikhael@ieee.org">Mikhael Felker</a></span> has written <a href="http://www.securityfocus.com/infocus/1883" target="_blank" title="Password Management Concerns with IE and Firefox">part two</a> of his <span class="body">analysis of the security mechanisms, risks, attacks, and defenses of the two most commonly used password management systems: those found in Internet Explorer and Firefox.<span id="more-62"></span>  Felker outlines the following areas of discussion: </span></p>
<p><span class="body"></span></p>
<ul>
<li><strong>Password storage mechanisms:</strong> The means of    safeguarding usernames and passwords on the local file    system through encryption (addressed in part 1).</li>
<li><strong>Attacks on Password Managers:</strong> The methods of    subverting or bypassing safeguards (partially address    in part 1; continued now in part 2)</li>
<li><strong>False sense of security:</strong> Users employing    password managers without any awareness of the risk    factors.</li>
<li><strong>Usability:</strong> Features that enhance or deter    the usability of security features.</li>
<li><strong>Mitigation and Countermeasures:</strong> Actions that    can be taken by users and corporations to reduce the    risk.</li>
</ul>
<p>This article is a great read. Storing passwords in web browsers is common amongst users, and it is important to understand the risks involved. So get to reading.</p>
<p><a href="http://www.securityfocus.com/infocus/1882" target="_blank" title="Password Management Concerns with IE and Firefox, Part One"><span class="headline">Password Management Concerns with IE and Firefox, Part One</span></a></p>
<p><a href="http://www.securityfocus.com/infocus/1883" target="_blank" title="Password Management Concerns with IE and Firefox, Part Two"><span class="headline">Password Management Concerns with IE and Firefox, </span><span class="body">Part Two</span></a></p>
<p><span class="body"><!--adsense#square--><br />
</span></p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=62&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d62').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d62" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;submitHeadline=Password+Management+Concerns+with+IE+and+Firefox&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;title=Password+Management+Concerns+with+IE+and+Firefox" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;title=Password+Management+Concerns+with+IE+and+Firefox" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;title=Password+Management+Concerns+with+IE+and+Firefox" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;bm_description=Password+Management+Concerns+with+IE+and+Firefox" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;T=Password+Management+Concerns+with+IE+and+Firefox" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;title=Password+Management+Concerns+with+IE+and+Firefox" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;title=Password+Management+Concerns+with+IE+and+Firefox" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Password+Management+Concerns+with+IE+and+Firefox+@+http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F12%2F12%2Fpassword-management-concerns-with-ie-and-firefox%2F&amp;t=Password+Management+Concerns+with+IE+and+Firefox" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d62').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2006/12/12/password-management-concerns-with-ie-and-firefox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Modify SSH Config To Maximize Security</title>
		<link>http://www.foogazi.com/2006/11/29/modify-ssh-to-maximize-security/</link>
		<comments>http://www.foogazi.com/2006/11/29/modify-ssh-to-maximize-security/#comments</comments>
		<pubDate>Wed, 29 Nov 2006 19:26:45 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[configurations]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=52</guid>
		<description><![CDATA[SSH is a powerful remote logging protocol that took the place of telnet back in the mid-to-late 90&#8242;s. With so many people using SSH as an every day tool, it is important for server administrators to understand some ways of making the secure shell a bit more&#8230; well&#8230; secure. In this article you will learn [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Secure_Shell" title="SSH" target="_blank">SSH</a> is a powerful remote logging protocol that took the place of <a href="http://en.wikipedia.org/wiki/TELNET" title="Telnet" target="_blank">telnet</a> back in the mid-to-late 90&#8242;s. With so many people using SSH as an every day tool, it is important for server administrators to understand some ways of making the secure shell a bit more&#8230; well&#8230; <em>secure</em>.  In this article you will learn how a few simple configuration modifications to <strong>sshd_config</strong> on your SSH server can improve the security of your SSH daemon and allow you to sleep better at night&#8230;</p>
<p><span id="more-52"></span></p>
<p><!--adsense#square--></p>
<p>First, lets take a look at a default SSH Config file<strong>: sshd_config</strong>:</p>
<blockquote><p>#       $OpenBSD: sshd_config,v 1.74 2006/07/19 13:07:10 dtucker Exp $<br />
# This is the sshd server system-wide configuration file.<br />
# See sshd_config(5) for more information.<br />
# The strategy used for options in the default sshd_config<br />
# shipped with OpenSSH is to specify options<br />
# with their default value where possible, but leave them<br />
# commented.  Uncommented options change a default value.<br />
#<br />
#Port 22<br />
#Protocol 2,1<br />
#AddressFamily any<br />
#ListenAddress 0.0.0.0<br />
#ListenAddress ::<br />
# HostKey for protocol version 1<br />
#HostKey /etc/ssh/ssh_host_key<br />
# HostKeys for protocol version 2<br />
#HostKey /etc/ssh/ssh_host_rsa_key<br />
#HostKey /etc/ssh/ssh_host_dsa_key<br />
# Lifetime and size of ephemeral version 1 server key<br />
#KeyRegenerationInterval 1h<br />
#ServerKeyBits 768<br />
# Logging<br />
# obsoletes QuietMode and FascistLogging<br />
#SyslogFacility AUTH<br />
#LogLevel INFO<br />
# Authentication:<br />
#LoginGraceTime 2m<br />
#PermitRootLogin yes<br />
#StrictModes yes<br />
#MaxAuthTries 6<br />
#RSAAuthentication yes<br />
#PubkeyAuthentication yes<br />
#AuthorizedKeysFile     .ssh/authorized_keys<br />
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts<br />
#RhostsRSAAuthentication no<br />
# similar for protocol version 2<br />
#HostbasedAuthentication no<br />
# Change to yes if you don&#8217;t trust ~/.ssh/known_hosts for<br />
# RhostsRSAAuthentication and HostbasedAuthentication<br />
#IgnoreUserKnownHosts no<br />
# Don&#8217;t read the user&#8217;s ~/.rhosts and ~/.shosts files<br />
#IgnoreRhosts yes<br />
# To disable tunneled clear text passwords, change to no here!<br />
#PasswordAuthentication yes<br />
#PermitEmptyPasswords no<br />
# Change to no to disable s/key passwords<br />
#ChallengeResponseAuthentication yes<br />
# Kerberos options<br />
#KerberosAuthentication no<br />
#KerberosOrLocalPasswd yes<br />
#KerberosTicketCleanup yes<br />
#KerberosGetAFSToken no<br />
# GSSAPI options<br />
#GSSAPIAuthentication no<br />
#GSSAPICleanupCredentials yes<br />
# Set this to &#8216;yes&#8217; to enable PAM authentication, account processing,<br />
# and session processing. If this is enabled, PAM authentication will<br />
# be allowed through the ChallengeResponseAuthentication and<br />
# PasswordAuthentication.  Depending on your PAM configuration,<br />
# PAM authentication via ChallengeResponseAuthentication may bypass<br />
# the setting of &#8220;PermitRootLogin without-password&#8221;.<br />
# If you just want the PAM account and session checks to run without<br />
# PAM authentication, then enable this but set PasswordAuthentication<br />
# and ChallengeResponseAuthentication to &#8216;no&#8217;.<br />
#UsePAM no<br />
#AllowTcpForwarding yes<br />
#GatewayPorts no<br />
#X11Forwarding no<br />
#X11DisplayOffset 10<br />
#X11UseLocalhost yes<br />
#PrintMotd yes<br />
#PrintLastLog yes<br />
#TCPKeepAlive yes<br />
#UseLogin no<br />
#UsePrivilegeSeparation yes<br />
#PermitUserEnvironment no<br />
#Compression delayed<br />
#ClientAliveInterval 0<br />
#ClientAliveCountMax 3<br />
#UseDNS yes<br />
#PidFile /var/run/sshd.pid<br />
#MaxStartups 10<br />
#PermitTunnel no<br />
# no default banner path<br />
#Banner /some/path<br />
# override default of no subsystems<br />
Subsystem       sftp    /usr/libexec/sftp-server<br />
# Example of overriding settings on a per-user basis<br />
#Match User anoncvs<br />
#       AllowTcpForwarding no<br />
#       ForceCommand cvs server</p></blockquote>
<p>As we can see, by default most of the configuration options are commented out, meaning that SSH is taking the default values. To maximize SSH security, we are going to modify the following lines:</p>
<blockquote><p>#Port 22</p>
<p>#Protocol 2,1</p>
<p>#PermitRootLogin yes</p>
<p>#PermitEmptyPasswords no</p>
<p>#MaxAuthTries 6</p>
<p>#AllowUsers</p></blockquote>
<p>The six lines pulled out from the <strong>sshd_config</strong> are the lines that I feel are the most important and basic modifications that should be made to the configuration. Here is what they should be changed to (remember to uncomment them):</p>
<blockquote><p><em>Port 60</em> (pick any port, 60 is just an example)</p></blockquote>
<p>Running the SSH daemon on a port other than the default port of 22 will minimize your servers vulnerability of being scanned automatically by <a href="http://en.wikipedia.org/wiki/Botnet" target="_blank" title="Botnet">botnets</a> that search and automate login and password attempts on SSH servers. Keep in mind that after you change the port number on your SSH server, you will need to specify the port whenever you are connecting to the server.</p>
<blockquote><p><em>Protocol 2</em></p></blockquote>
<p>The SSH protocol 1 is very outdated and nobody should be running it. Protocol 1 had some security issues, so it is pretty mindless to even allow it in your configuration.</p>
<blockquote><p><em>PermitRootLogin no </em></p></blockquote>
<p>Logging into your SSH server as the root user should not be necessary. The best practice is to log in as a normal user and in the event of needing root privileges you can use the <em>su</em> command to switch to the root user.</p>
<blockquote><p><em>PermitEmptyPasswords no</em></p></blockquote>
<p>You do not want to allow user accounts that have empty passwords to log into your Linux server via SSH.</p>
<blockquote><p><em>MaxAuthTries 3</em></p></blockquote>
<p>Setting the <em>MaxAuthTries</em> to a low number will minimize the risk of your SSH server being attacked in a brute force type of way. Automated attacks will disconnect after a third password failure. Though they may reconnect, it can slow the process down and will definitely minimize the potential breach by way of brute force password attempts.</p>
<blockquote><p><em>AllowUsers adamk tom sam john jane mark</em></p></blockquote>
<p>Setting <em>AllowUsers</em> in the configuration file greatly reduces the risk of automated brute force attacks. If you specify that only certain users are allowed to log into the machine via SSH then you have less to worry about in that aspect. List out all of the user names that are allowed to connect to the SSH server and separate them with spaces.</p>
<p><strong>Conclusion:</strong></p>
<p>We&#8217;ve looked at six different configuration modifications that will improve our Secure Shell (SSH) server.</p>
<ol>
<li>Running SSH daemon on a different port.</li>
<li>Allowing only users running protocol 2 to connect to the server</li>
<li>Denying root logins over SSH</li>
<li>Denying users with empty passwords to connect</li>
<li>Permitting a limited number of authorization retries.</li>
<li>Allowing only certain specified users to log in.</li>
</ol>
<p>With these settings in place, and our SSH server restarted in order to take these configuration changes into effect, we are one step closer to a safer and more secure server.</p>
<p><center><!--adsense#square--></center></p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=52&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d52').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d52" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;submitHeadline=Modify+SSH+Config+To+Maximize+Security&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;title=Modify+SSH+Config+To+Maximize+Security" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;title=Modify+SSH+Config+To+Maximize+Security" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;title=Modify+SSH+Config+To+Maximize+Security" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;bm_description=Modify+SSH+Config+To+Maximize+Security" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;T=Modify+SSH+Config+To+Maximize+Security" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;title=Modify+SSH+Config+To+Maximize+Security" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;title=Modify+SSH+Config+To+Maximize+Security" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Modify+SSH+Config+To+Maximize+Security+@+http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F29%2Fmodify-ssh-to-maximize-security%2F&amp;t=Modify+SSH+Config+To+Maximize+Security" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d52').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2006/11/29/modify-ssh-to-maximize-security/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Prevent users from logging into your system</title>
		<link>http://www.foogazi.com/2006/11/28/prevent-certain-users-from-logging-into-your-system/</link>
		<comments>http://www.foogazi.com/2006/11/28/prevent-certain-users-from-logging-into-your-system/#comments</comments>
		<pubDate>Tue, 28 Nov 2006 21:02:55 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[HowTo]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ftp]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=51</guid>
		<description><![CDATA[If you are a system administrator who allows remote access to your server or desktop, you may want to disable certain users from logging into the system both remotely and locally. This article will explain how to prevent certain users from logging into your Linux machine via SSH (OpenSSH_4.4p1) and FTP (vsftpd 2.0.5). First we [...]]]></description>
			<content:encoded><![CDATA[<p>If you are a system administrator who allows remote access to your server or desktop, you may want to disable certain users from logging into the system both remotely and locally. This article will explain how to prevent certain users from logging into your Linux machine via SSH (OpenSSH_4.4p1) and FTP (vsftpd 2.0.5).</p>
<p><center><!--adsense#square--></center>First we must understand that in most cases there are two different ways an allowed user may be logging into your Linux server.<span id="more-51"></span></p>
<ol>
<li>Secure Shell (SSH)</li>
<li>File Transfer (FTP)</li>
</ol>
<p><strong>Preventing access to the SSH server:</strong></p>
<p>The best and most secure practice of running an SSH server is to tighten the hatches as much as possible. In this example, I will show you how to edit your <em>sshd_config</em> file and allow only certain users (except <em>&#8220;joe&#8221;</em>) to access the system via SSH.  Now, lets say that you want to prevent the user <em>&#8220;joe&#8221; </em>from logging into SSH, but you still want him to be able to access the machine via FTP.  Here is what you would do:</p>
<ul>
<li>Open <em>/etc/ssh/sshd_config </em>in your favorite text editor.
<ul>
<li><em>vim /etc/ssh/sshd</em></li>
</ul>
</li>
<li>Add a line that says <em>AllowUsers</em>
<ul>
<li><em>AllowUsers adamk tim sean jacob dave<br />
</em></li>
</ul>
<ul>
<li>Note that <em>joe</em> is not included here.</li>
<li>Save the <em>sshd_config</em> file.</li>
<li>Restart your <em>sshd </em>daemon.</li>
</ul>
</li>
</ul>
<p>Another (quick) way to do this in one simple command is:</p>
<ul>
<li>
<ul>
<li><em>echo &#8220;AllowUsers adamk tim sean jacob dave&#8221; &gt;&gt; /etc/sshd/sshd_config</em></li>
</ul>
</li>
</ul>
<p>This modification to <em>/etc/sshd/sshd_config </em>will allow Joe to access your system via FTP only.</p>
<p><!--adsense--></p>
<p><strong>Preventing access to the FTP server:</strong></p>
<p>Now lets look at how to prevent the user <em>&#8220;joe&#8221;</em> from logging into your server via FTP.  Here is what you would do:</p>
<p><strong><strong> </strong></strong></p>
<ul><strong><strong> 	</strong></strong></p>
<li>Open <em>/etc/ftpusers</em> in your favorite text editor.
<ul>
<li><em>vim /etc/ftpusers</em></li>
</ul>
</li>
</ul>
<ul>
<li>Add &#8220;joe&#8221; to the bottom of the file.
<ul>
<li>Save the file.</li>
<li>Joe will now be unable to login via FTP to your machine.</li>
</ul>
</li>
</ul>
<p><strong>Completely disable a users access:</strong></p>
<p>To completely disable the user &#8220;joe&#8221; from accessing the system here is what you would do:</p>
<ul>
<li>Open <em>/etc/passwd </em>in your favorite text editor.
<ul>
<li><em>vim /etc/passwd</em></li>
</ul>
</li>
</ul>
<ul>
<li>Locate the line that starts with &#8220;joe&#8221;.
<ul>
<li><em>joe:x:1000:100:Joe,,,:/home/joe:/bin/bash</em></li>
</ul>
</li>
</ul>
<ul>
<li>Change the &#8220;x&#8221; to a &#8220;*&#8221;
<ul>
<li><em>joe:*:1000:100:Joe,,,:/home/joe:/bin/bash</em></li>
</ul>
</li>
</ul>
<ul>
<li>Save the file.</li>
<li>Joe is now <em>locked</em> out of the machine.</li>
</ul>
<p>Another (quick) way to lock a users access is:</p>
<ul>
<li><em>passwd -l joe</em></li>
</ul>
<p><strong>Conclusion:</strong></p>
<p>It is important to be able to quickly lock a user out of your system at any given time. Knowing these three different ways of preventing access to FTP and SSH for a certain user is crucial to your system administration knowledge and I hope that you use this knowledge to better secure your system.</p>
<p><!--adsense#square--></p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=51&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d51').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d51" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;submitHeadline=Prevent+users+from+logging+into+your+system&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;title=Prevent+users+from+logging+into+your+system" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;title=Prevent+users+from+logging+into+your+system" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;title=Prevent+users+from+logging+into+your+system" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;bm_description=Prevent+users+from+logging+into+your+system" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;T=Prevent+users+from+logging+into+your+system" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;title=Prevent+users+from+logging+into+your+system" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;title=Prevent+users+from+logging+into+your+system" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Prevent+users+from+logging+into+your+system+@+http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F28%2Fprevent-certain-users-from-logging-into-your-system%2F&amp;t=Prevent+users+from+logging+into+your+system" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d51').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2006/11/28/prevent-certain-users-from-logging-into-your-system/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A Quick Guide To Securing Your System From Physical Attacks</title>
		<link>http://www.foogazi.com/2006/11/14/a-quick-guide-to-securing-your-system-from-physical-attacks/</link>
		<comments>http://www.foogazi.com/2006/11/14/a-quick-guide-to-securing-your-system-from-physical-attacks/#comments</comments>
		<pubDate>Tue, 14 Nov 2006 19:34:21 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[sysadmin]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=42</guid>
		<description><![CDATA[So, your network is behind a firewall, and your system is hardened? Have you took a moment to think about the actual physical security of your network and machines? Though an unlikely risk in a home based environment, it is important to consider physical attacks as a factor to prevent. In this article, I will [...]]]></description>
			<content:encoded><![CDATA[<p>So, your network is behind a firewall, and your system is hardened? Have you took a moment to think about the actual physical security of your network and machines? Though an unlikely risk in a home based environment, it is important to consider physical attacks as a factor to prevent. In this article, I will go over two easy to do tasks that will move your system(s) another step closer to physical security.<span id="more-42"></span></p>
<p><strong>Password Your BIOS:</strong></p>
<p>Just about every BIOS these days has an option to set a password in order to boot the system. You will need to reboot your computer and boot into your BIOS, then find the option related to passwords. Setting a password on your BIOS will ensure that anyone booting your machine will not be able to load your operating system without supplying the proper password upon initial boot of the machine. Setting a password on your BIOS will also prevent someone from throwing in a bootable CD-ROM or floppy disk and loading something like a live CD or password cracker.</p>
<p><!--adsense--></p>
<p><strong>Password Your Boot Manager:</strong></p>
<p>Another measure of security to take is to password your boot manager, if you have one. A boot manager is usually loaded after the BIOS and is present on systems that have a dual-boot setup. Such systems like those running Linux and Windows, or more than one operating system. Without the adequate security precautions and passwords in place, someone with physical access to your machine will have the ability to boot your kernel into single user mode, or with root privileges with a few extra parameters at the boot manager prompt. So with that said, I will explain how to password <em>LILO </em>and <em>GRUB</em>, as they are the two most popular boot managers to date.</p>
<p><u>Passwording LILO</u>:</p>
<p>There are two different ways you can tell LILO to prompt for a password.</p>
<ol>
<li>Always</li>
<li>If someone tries to pass special kernel parameters at boot</li>
</ol>
<p>If you want LILO to always prompt for a password before loading your kernel image, you will want to make the following changes to your /etc/lilo.conf configuration file:</p>
<p>Under the global options area, add:</p>
<p><em>password=passwordhere<br />
mandatory</em><br />
Obviously, replace <em>passwordhere</em> with something more suitable.</p>
<p>Save the /etc/lilo.conf configuration file and execute LILO in order to reinstall the configuration changes:</p>
<p><em>/sbin/lilo</em></p>
<p>If you want LILO to only prompt for a password if someone tries to pass kernel parameters at the boot prompt, add the following lines instead:</p>
<p><em>password=passwordhere<br />
restricted</em></p>
<p>Again, be sure to replace <em>passwordhere</em> with something more suitable.</p>
<p>Save the /etc/lilo.conf configuration file and execute LILO in order to reinstall the configuration changes:</p>
<p><em>/sbin/lilo</em></p>
<p><!--adsense--></p>
<p><u>Passwording GRUB</u>:</p>
<p>If you use GRUB instead of LILO, here is what you&#8217;ll want to do in order to set a password.</p>
<p>As the root user, run:</p>
<p><em>grub-md5-crypt<br />
Password:<br />
Retype Password:<br />
</em>$1$bCOp17$HFxXT4G56tOIc9Xq2s/CE.<em><br />
</em></p>
<p>You will be prompted twice for a password. Then you will receive a long output of characters, which is your hash. Take that output and copy/paste it into your grub.conf (usually located in /boot/grub/) like so:</p>
<p><em>password &#8211;md5 $1$bCOp17$HFxXT4G56tOIc9Xq2s/CE.</em></p>
<p>A lot of people may think that taking precautions for physical security is a bit dramatic and should be done by the paranoid only. I disagree. Practicing good security is essential to ensuring your computers are safe no matter what the case may be. Do you lock your doors when you go to sleep? If you find the answer to be pretty logical, then chances are you&#8217;ll agree that a BIOS password along with a boot loader password is essential for protecting your machines from physical attacks.</p>
<p><!--adsense#square--></p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=42&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d42').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d42" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;submitHeadline=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;title=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;title=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;title=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;bm_description=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;T=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;title=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;title=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks+@+http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F14%2Fa-quick-guide-to-securing-your-system-from-physical-attacks%2F&amp;t=A+Quick+Guide+To+Securing+Your+System+From+Physical+Attacks" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d42').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2006/11/14/a-quick-guide-to-securing-your-system-from-physical-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Staying Secure with Nessus Vulnerability Scanner</title>
		<link>http://www.foogazi.com/2006/11/06/staying-secure-with-nessus/</link>
		<comments>http://www.foogazi.com/2006/11/06/staying-secure-with-nessus/#comments</comments>
		<pubDate>Mon, 06 Nov 2006 20:42:42 +0000</pubDate>
		<dc:creator>ack</dc:creator>
				<category><![CDATA[HowTo]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.inguin.com/wordpress/?p=37</guid>
		<description><![CDATA[This is a simple walk through guide to installing nessus, configuring nessus, and running the popular Nessus Vulnerability Scanner on Linux. From the Nessus website: Nessus is the world&#8217;s most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the world&#8217;s largest organizations are realizing significant cost savings by using Nessus to audit [...]]]></description>
			<content:encoded><![CDATA[<p><!--adsense#right-->This is a simple walk through guide to installing nessus, configuring nessus, and running the popular <a href="http://www.nessus.org/" title="http://www.nessus.org/" target="_blank">Nessus Vulnerability Scanner</a> on Linux.  From the Nessus website: <em> Nessus is the world&#8217;s most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the world&#8217;s largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications. </em><span id="more-37"></span>I use Nessus on a weekly basis to scan my servers and desktop machines, both Windows and Linux, for vulnerabilities. It has proved to be a vital tool for me personally and professionally, while not costing me a dime.</p>
<p>The distribution used in this document is <a href="http://www.slackware.com" target="_blank" title="Slackware 11">Slackware 11.0</a> on a custom 2.6.18.1 kernel. While it is possible and sometimes needed to install Nessusd on a &#8216;server&#8217; and NessusClient on a &#8216;workstation&#8217;, in this document, we go over installing Nessusd and NessusClient both on the same machine.</p>
<p><strong>Installing</strong> <strong>Nessus 2.2.9:</strong></p>
<p>For the most part, you will want to refer to the Nessus installation documents provided on the Nessus <a href="http://www.nessus.org/" title="http://www.nessus.org/" target="_blank">website</a>. However, the easiest way to get Nessus installed is to download the installer that is suitable for all Unix systems. Visit the Nessus website and download the file. Once downloaded, execute it by typing:</p>
<blockquote><p>root@foo:~# sh nessus-installer-2.2.9.sh</p></blockquote>
<p>After completing the installation, you will want to create a certificate as well as add a nessusd user.</p>
<blockquote><p>adam@foo:~$ nessus-mkcert</p>
<p>follow on screen instructions</p>
<p>adam@foo:~$ nessus-adduser</p>
<p>follow on screen instructions</p></blockquote>
<p>Now all we need to do is start the nessus daemon.</p>
<blockquote><p>adam@foo:~# nessusd -D</p></blockquote>
<p><strong>Installing the Nessus GUI Client:</strong></p>
<p><!--adsense--></p>
<p>Since I find it easier to use the Nessus Client, we will go over that installation as well. First, go to Downloads area on the Nessus website and select the NessusClient 1.0.1 (a GUI for Nessusd). After downloading, install it by executing:</p>
<blockquote><p>adam@foo:~/source/NessusClient-1.0.1$ ./configure &amp;&amp; make</p>
<p>adam@foo:~/source/NessusClient-1.0.1$ su<br />
Password:<br />
root@foo:~/source/NessusClient-1.0.1$ make install</p></blockquote>
<p>Now execute NessusClient</p>
<blockquote><p>adam@foo:~$ /usr/local/bin/NessusClient</p></blockquote>
<p>Now you should see a pretty GUI.</p>
<p><a href="http://www.foogazi.com/images/nessus/main-gui.jpg" title="NessusClient GUI (Click to Enlarge)" target="_blank"><img src="http://www.foogazi.com/images/nessus/main-gui.jpg" title="NessusClient GUI" alt="NessusClient GUI" height="272" width="439" /></a></p>
<p><!--adsense--></p>
<p><strong>Scanning a Host for Vulnerabilities:</strong></p>
<p>For the purposes of this document, we will run a simple scan on our localhost with all the default configuration settings. Feel free to tinker with the settings to produce maximum results on your scans.</p>
<p>In order to scan a host for vulnerabilities, we must tell NessusClient that we want to create a new task and a new scope. Click <em>Task</em> &gt; <em>New</em> and give your task a name of <em>localscan</em>.</p>
<p>We then need to tell NessusClient to connect to our nessus server daemon, which in this case will be localhost.  Click on <em>File </em>&gt;<em> Connect</em>, your screen should look something like this:</p>
<p><img src="http://www.foogazi.com/images/nessus/connect-settings.jpg" alt="NessusClient GUI Connect Settings" title="NessusClient GUI Connect Settings" /></p>
<p>Once all settings are correct, click <em>OK</em> and NessusClient will connect to the nessus daemon. During connect, you should see a window telling you that Nessus is loading all the plugins.</p>
<p>Next, in the <em>Options</em> menu, navigate to the <em>Target Selection</em> area and make sure localhost is added.  You can add more hosts by separating them with a comma.  Click to enlarge.<br />
<strong><a href="http://www.foogazi.com/images/nessus/target-selection.jpg" target="_blank" title="Click to Enlarge"><img src="http://www.foogazi.com/images/nessus/target-selection.jpg" alt="NessusClient GUI Target Selection (Click to Enlarge)" title="NessusClient GUI Target Selection (Click to Enlarge)" height="292" width="446" /></a></strong></p>
<p><!--more--></p>
<p>Now all we need to do is tell the NessusClient to execute the scan by clicking on <em>Scope</em> &gt; <em>Execute</em>.  This will bring up a window that shows the status of the scan.</p>
<p><a href="http://www.foogazi.com/images/nessus/execute.jpg" target="_blank" title="Click to Enlarge"><img src="http://www.foogazi.com/images/nessus/execute.jpg" alt="NessusClient GUI Execute (Click to Enlarge)" title="NessusClient GUI Execute (Click to Enlarge)" height="293" width="377" /></a></p>
<p>Once the scan is complete, Nessus will generate a report file that lists everything found during the scan along with the severity of each issue. Read through each item found and follow any solution instructions given.</p>
<p><!--adsense--></p>
<p><strong><a href="http://www.foogazi.com/images/nessus/reports.jpg" target="_blank" title="Click to Enlarge"><img src="http://www.foogazi.com/images/nessus/reports.jpg" title="NessusClient GUI Reports (Click to Enlarge)" alt="NessusClient GUI Reports (Click to Enlarge)" height="304" width="463" /></a></strong></p>
<p>Thats all!  I would recommend reading through the documentation on the <a href="http://www.nessus.org/documentation/" title="http://www.nessus.org/documentation/" target="_blank">http://www.nessus.org/documentation/</a> website and adjusting the settings to fit your needs further.</p>
<p>Good luck and happy auditing!</p>
<p><!--adsense#square--></p>
<img src="http://www.foogazi.com/?ak_action=api_record_view&id=37&type=feed" alt="" /><!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d37').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Bookmark This Page:</em></strong></a>
<br />
<div class="d37" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://buzz.yahoo.com/submit?submitUrl=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;submitHeadline=Staying+Secure+with+Nessus+Vulnerability+Scanner&amp;submitSummary=" rel="nofollow" title="Add to&nbsp;Buzz"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/buzz.png" title="Add to&nbsp;Buzz" alt="Add to&nbsp;Buzz" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;title=Staying+Secure+with+Nessus+Vulnerability+Scanner" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;title=Staying+Secure+with+Nessus+Vulnerability+Scanner" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;title=Staying+Secure+with+Nessus+Vulnerability+Scanner" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;bm_description=Staying+Secure+with+Nessus+Vulnerability+Scanner" rel="nofollow" title="Add to&nbsp;Mister Wong"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/misterwong.png" title="Add to&nbsp;Mister Wong" alt="Add to&nbsp;Mister Wong" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.netscape.com/submit/?U=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;T=Staying+Secure+with+Nessus+Vulnerability+Scanner" rel="nofollow" title="Add to&nbsp;Netscape"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/netscape.png" title="Add to&nbsp;Netscape" alt="Add to&nbsp;Netscape" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;title=Staying+Secure+with+Nessus+Vulnerability+Scanner" rel="nofollow" title="Add to&nbsp;reddit"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/reddit.png" title="Add to&nbsp;reddit" alt="Add to&nbsp;reddit" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;title=Staying+Secure+with+Nessus+Vulnerability+Scanner" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F" rel="nofollow" title="Add to&nbsp;Technorati"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/technorati.png" title="Add to&nbsp;Technorati" alt="Add to&nbsp;Technorati" /></a>
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://tipd.com/submit.php?url=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F" rel="nofollow" title="Add to&nbsp;Tip'd"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/tipd.png" title="Add to&nbsp;Tip'd" alt="Add to&nbsp;Tip'd" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Staying+Secure+with+Nessus+Vulnerability+Scanner+@+http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.foogazi.com%2F2006%2F11%2F06%2Fstaying-secure-with-nessus%2F&amp;t=Staying+Secure+with+Nessus+Vulnerability+Scanner" rel="nofollow" title="Add to&nbsp;Yahoo My Web"><img class="social_img" src="http://www.foogazi.com/wp-content/plugins/social-bookmarks/images/yahoo.png" title="Add to&nbsp;Yahoo My Web" alt="Add to&nbsp;Yahoo My Web" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d37').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.foogazi.com/2006/11/06/staying-secure-with-nessus/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

