Let's dive headfirst into how Kali Linux, a popular open-source Linux distro, can amp up your network's security. It's all about the big and small ways this toolkit makes your life easier and your network tougher against the baddies. . One of the first gems is about Kali's built-in tools: "These tools range from information gathering to maintaining access to your system, from reverse engineering to hardware hacking." Translation? Kali's got your back on various fronts. Now, it's no secret that staying secure is like a never-ending game of cat and mouse. The article serves up this thought: "If you do not know how a system can be attacked, how can you stop those attacks from happening?". Echoing this, shouldn't we step up our understanding of network vulnerabilities? Interestingly, there's a mention of using Kali Linux as part of a Raspberry Pi setup, turning it into a portable, power-packed intrusion detection system. How cool is that? And what could the broader impact be if more folks adopted this approach? In the universe of network security, the article stirs up cheers for Kali Linux while also nudging us to reflect on our network safety smarts. Well worth a read for any tech-head keen on diving deeper. . Kali Linux is a specialized OS designed for penetration testing and security auditing, enhancing network security while raising vulnerability awareness for info systems.. Kali Linux, Network Security, Penetration Testing. . Brittany Day
BlackArch Linux has released BlackArch 2020.12.01 with over 100 new hacking tools, bringing the total count of hacking tools offered by the distro to 2,608. . As we’re heading toward the end of 2020, BlackArch team has released its second and last new snapshot of this year as BlackArch 2020.12.01. The latest version includes Linux kernel 5.9.11 , updated system packages, config files, and tools. It has also added more than 100 new hacking tools, which lead to the total count of tools in BlackArch to 2608. The link for this article located at Fossbytes is no longer available. . Kali Linux 2022.05 releases an additional 150 cybersecurity utilities, bringing its total to an impressive 3,204 tools.. BlackArch Linux, Hacking Tools, Open Source Security. . LinuxSecurity.com Team
After many, many years of 0.9 status, the OpenSSL team has finally released a beta of version 1.0 of their software: Please download and test them as soon as possible. This new OpenSSL version incorporates 107 documented changes and bugfixes to the toolkit. Click-through to read the rest of the announcement! . OpenSSL version 1.0.0 Beta 1 =========================== OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org:443/ OpenSSL is currently in a release cycle. The first beta is now released. The beta release is available for download via HTTP and FTP from the following master locations (the various FTP mirrors you can find under o o The file names of the beta are: o openssl-1.0.0-beta1.tar.gz MD5 checksum: 49f265d9dd8dc011788b34768f63313e SHA1 checksum: 89b4490b6091b496042b5fe9a2c8a9015326e446 The checksums were calculated using the following command: openssl md5 < openssl-1.0.0-beta1.tar.gz openssl sha1 < openssl-1.0.0-beta1.tar.gz Please download and test them as soon as possible. This new OpenSSL version incorporates 107 documented changes and bugfixes to the toolkit (for a complete list see ). Reports and patches should be sent to
The Cryptographic Module Validation Program (CMVP), a joint effort of the US and Canadian governments, approved the validation of the OpenSSL open source security toolkit for implementation of the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols on Friday. . OpenSSL is already in use by companies and organizations around the world. However, validation that the toolkit meets the Federal Information Processing Standard (FIPS) 140-2 regulations means that US and Canadian government agencies that handle sensitive data can use the free, open source security software. The CMVP is run by the US National Institute for Standards and Technology (NIST) and Canada's Communications Security Establishment (CSE) to provide testing of cryptographic modules in accredited labs, which makes sure that security software does what it is designed to do every time it's used, based on the FIPS standards. While not yet officially validated, CMVP Director Randy Easter said validation of the open source software "is a done deal." OpenSSL is now in the finalization stage of the CMVP pre-validation process. Although a certificate must be printed and signed by representatives of both NIST and CSE, Easter said the certificate could be signed, and the validation official, as early as next week. The link for this article located at NewsForge is no longer available. . OpenSSL is already in use by companies and organizations around the world. However, validation that . cryptographic, module, validation, program, (cmvp), joint, effort, canadian, government. . LinuxSecurity.com Team
Cryptography firm Certicom has announced a cross-platform security toolkit for future mobile phone handsets. The Certicom Security Architecture for Mobility will provide a common programming interface for developers to access . . .. Cryptography firm Certicom has announced a cross-platform security toolkit for future mobile phone handsets. The Certicom Security Architecture for Mobility will provide a common programming interface for developers to access functions such as encryption across various mobile chipsets and operating systems, according to the firm. The move should speed development of handsets with better security. Certicom's Security Architecture for Mobility (CSA) builds on the company's Security Builder Middleware, a hardware abstraction layer that is optimised to work with a specific chipset or hardware platform. The first supported hardware will be Intel's Wireless Trusted Platform, which consists of security functions that are built into Intel's PXA270 series of XScale mobile chips. CSA will support this from the fourth quarter of this year, and support for other mobile platforms will follow. "Pressure for greater security is coming from enterprise customers. [Security] used to be seen as an add-on to IT systems, but lately it has been regarded as something that has to be embedded from the beginning," commented Certicom's vice-president of marketing, Roy Pereira. CSA has resulted from Certicom's collaboration with Intel on security for a major handset vendor, Pereira said. He declined to name the vendor, for commercial reasons. Handset vendors are focused on applications, not cryptography, Certicom said, and its middleware layer lets them easily build in cryptography support, shortening the development time and giving handset makers a common interface for encryption functions no matter what the underlying chipset is. The link for this article located at Daniel Robinson, IT Week is no longer available. . Certicom's latest multi-platform security framework strives to bolster mobile devicesafety and streamline the development process.. Certicom Security, Mobile Encryption, Toolkit, Developer Interface, Security Solutions. . LinuxSecurity.com Team
Jascha submits , L.A.S. Linux is a 'live CD' distribution of Linux which allows the applications to be run from the CD without the need for installing anything on the computer. The focus of L.A.S. is create a bootable toolkit for information security professionals and systems administrators. . . . . Jascha submits , L.A.S. Linux is a 'live CD' distribution of Linux which allows the applications to be run from the CD without the need for installing anything on the computer. The focus of L.A.S. is create a bootable toolkit for information security professionals and systems administrators. The advantage of L.A.S. is that it has a very small footprint. This small footprint maks it able to fit on a 185MB mini-CD. The goal of L.A.S. Linux is to provide a well-rounded tool in a small package. Despite its small size, L.A.S. contains over 100 security tools including basic desktop applications. Utilizing the FluxBox window manager, which is a lightweight desktop environment, allows for multiple desktop enviroments. L.A.S. has an array or forensic, penetration testing, intrusion detection, sniffers, and administrative utilities. Changes in this latest version of L.A.S. include the addition of Ettercap-GTK, Clam Anti-Virus, MiniCOM, SpikeProxy, MRTG, and many of the Cisco-centric Open Source Exchange tools. The link for this article located at Jascha / LocalAreaSecurity.com is no longer available. . Explore L.A.S. Unix, a nimble live disc designed for cybersecurity experts, packed with utilities for assessment and management.. Live CD, Security Toolkit, Penetration Testing, Lightweight Environment, Forensic Tools. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.