Preparation to Crest CRT +host build review



  • Download  hacking lab Bazooka http://media.hacking-lab.com/  and http://media.hacking-lab.com/img/LiveCD-Tipps.pdf
  • Lamp Security CTF8 https://sourceforge.net/projects/lampsecurity/files/CaptureTheFlag/CTF8/
  • map unix to windows commands http://www.lemoda.net/windows/windows2unix/windows2unix.html
  • useful resources: http://www.computersecuritystudent.com/HOME/index.html 
  • password policy with  chage http://www.thegeekstuff.com/2009/04/chage-linux-password-expiration-and-aging/ http://www.tutorialspoint.com/unix_commands/chage.htm
  • harden  linux security http://www.puschitz.com/SecuringLinux.shtml http://www.dummies.com/how-to/content/linux-security.html http://www.puschitz.com/SecuringLinux.shtml http://www.cyberciti.biz/tips/linux-security.html http://www.tecmint.com/linux-server-hardening-security-tips/ 
  • Hack proofing oracle http://www.blackhat.com/presentations/win-usa-02/litchfield-winsec02.pdf
  • oracle ports https://blogs.oracle.com/oem/entry/planning_your_oracle_entperprise_manager
  • How to list all users with root privs http://serverfault.com/questions/208347/how-do-i-list-all-users-with-root 
  • automate host build review 
    • http://blog.cyberis.co.uk/2012/07/expect-scripts-to-perform-build-reviews.html 
    • http://expect.sourceforge.net/
    • Generic unix host review script https://github.com/cyberisltd/NixAudit/blob/master/linux_audit.sh
    • Solaris host review https://github.com/cyberisltd/NixAudit/blob/master/solaris_audit.sh 
    • lynis https://cisofy.com/lynis/ 
    • Gladius and responder https://www.praetorian.com/blog/gladius-automatic-responder-cracking