Mostrando entradas con la etiqueta Security Distros. Mostrar todas las entradas
Mostrando entradas con la etiqueta Security Distros. Mostrar todas las entradas

sábado, 26 de agosto de 2023

The Most Secure Linux Distros 2023 (Tested & Compared)




This is a list of extra-safe Linux distributions that guarantee your privacy and security both for your files and on the internet.

  • Kali Linux — Best Overall with Support for Ethical Hacking
  • BlackArch Linux — Best Arch-Based Penetration Testing Linux Distro
  • Qubes OS — Best for Compartmentalizing Applications
  • Alpine Linux — Best Lightweight Security-Oriented Linux Distro
  • Tails Linux — Best for Anonymity and Bypassing Internet Censorship



Fuente: linuxhaxor.net

martes, 13 de septiembre de 2022

Top 10 Best Linux Distro Operating Systems For Ethical Hacking & Penetration Testing – Septembe 2022

There are different OS for Hacking and Penetration Testing with Linux distro is dedicatedly developed for Security Researchers or Ethical Hackers to perform various operations in security industries with a variety of hacking tools that prebuilt with OS. Linux is an open source it gives you the freedom to choose your own operating system.
 
Top 10 Best OS for Hacking & Penetration Testing
1- Kali Linux
2- Parrot Security OS
3- BackBox Linux
4- BlackArch Linux
5- Pentoo
6- Samurai Web Testing Framework (Samurai-WTF)
7- Network Security Toolkit (NST)
8- WifiSlax
9- Bugtraq
10- Cyborg Hawk




Fuente: gbhackers.com/

martes, 15 de febrero de 2022

Kali Linux 2022.1 Release

Kali Linux 2022.1 Release (Visual Updates, Kali Everything ISOs, Legacy SSH)

The summary of the changelog since the 2021.4 release from December 2021 is: 

  •  Visual Refresh - Updated wallpapers and GRUB theme 
  • Shell Prompt Changes - Visual improvements to improve readability when copying code 
  • Refreshed Browser Landing Page - Firefox and Chromium homepage has had a makeover to help you access everything 
  • Kali you need Kali Everything Image - An all-packages-in-one solution now available to download 
  • Kali-Tweaks Meets SSH - Connect to old SSH servers using legacy SSH protocols and ciphers 
  • VMware i3 Improvements - Host-guest features properly work now on i3 
  • Accessibility Features - Speech synthesis is back in the Kali installer 
  • New Tools - Various new tools added, many from ProjectDiscovery!

miércoles, 5 de enero de 2022

AWS Distro for OpenTelemetry

 AWS Distro for OpenTelemetry is a secure, production-ready, AWS-supported distribution of the OpenTelemetry project 



Part of the Cloud Native Computing Foundation, OpenTelemetry provides open source APIs, libraries, and agents to collect distributed traces and metrics for application monitoring. With AWS Distro for OpenTelemetry, you can instrument your applications just once to send correlated metrics and traces to multiple AWS and Partner monitoring solutions. Use auto-instrumentation agents to collect traces without changing your code. 

AWS Distro for OpenTelemetry also collects metadata from your AWS resources and managed services, so you can correlate application performance data with underlying infrastructure data, reducing the mean time to problem resolution. Use AWS Distro for OpenTelemetry to instrument your applications running on Amazon Elastic Compute Cloud (EC2), Amazon Elastic Container Service (ECS), and Amazon Elastic Kubernetes Service (EKS) on EC2, AWS Fargate, and AWS Lambda, as well as on-premises.


Download




miércoles, 2 de junio de 2021

Kali Linux 2021.2 released (Nuevas Herramientas y temas)

 

This release welcomes a mixture of new items as well as enhancements of existing features, and is ready to be downloaded (from our updated page) or upgraded if you have an existing Kali Linux installation.

A quick summary of the changelog since the 2021.1 release from February 2021 is:

 

 

martes, 31 de marzo de 2020

Parrot OS (Distro para hacking ético)


Parrot OS es una distro de hacking ético basada en Debian enfocada principalmente a todo lo relacionado con la seguridad informática. 

Esta distro ha sido diseñada desde cero para plantar cara a otras alternativas, como Kali Linux o BlackArch, centrándose en ofrecer a sus usuarios un completo ecosistema de pruebas de penetración, evaluación y análisis de vulnerabilidades, así como para análisis forense de sistemas, preservación del anonimato y practicar con la criptografía y el cifrado.

image



We are the Parrot Project
Parrot is a worldwide community of developers and security specialists that work together to build a shared framework of tools to make their job easier, standardized and more reliable and secure.

Secure

Always updated, frequently released with many hardening and sandboxing options abailable. Everything is under your complete control.

Free (as in freedom)

Feel free to get the system, share with anyone, read the source code and change it as you want! this system is made to respect your freedom, and it ever will be.

Lightweight

We care about resources consumption, and the system has proven to be extremely lightweight and run surprisingly fast even on very old hardware or with very limited resources.

Portable and universal

Our tools are designed to be compatible with as many devices as possible via containerization technologies like Docker or Podman. Feel free to use the Parrot tools on Windows, Mac OS or any other Linux distribution without changing your habits.




miércoles, 29 de enero de 2020

Kali Linux 2020.1 released (New tools)

Offensive Security have released Kali Linux 2020.1

Kali Menu

The following is a brief feature summary for this release:


miércoles, 8 de enero de 2020

OSINTUX (Distribución Linux OSINT)

OSINTUX es una distribución Linux en castellano, con base en Ubuntu LTS y distribuida bajo licencia "GNU General Public License v3" destinada a labores de inteligencia en fuentes abiertas (OSINT). El proyecto nació como consecuencia del trabajo fin de Máster del I Máster de Ciberseguridad, organizado por Eleven Paths (Télefonica), el Campus Internacional de Ciberseguridad, y la UCAM.

Volver a la página principal








miércoles, 20 de noviembre de 2019

Las 15 mejores distribuciones de Linux centradas en la seguridad del año 2019

Top 15 Best Security-Centric Linux Distributions of 2019
Being anonymous on the Internet is not particularly the same as surging the web safely, however, they both involve keeping oneself and one’s data private and away from the prying eyes of entities that may otherwise take advantage of system vulnerabilities in order to harm targeted parties.
There is also the risk of surveillance from the NSA and several other top-level organizations and this is why it is good that developers have taken it upon themselves to build privacy-dedicated distros that host an aggregate of tools that enable users to achieve both online autonomy and privacy.
In as much as these privacy-centric Linux distros are targetted at a niche in the Linux community, many of them are robust enough to be used for general-purpose computing and many more can be tweaked to support requirements for virtually any specific user base.
A common factor across almost all privacy-centric Linux distros is their relationship with Tor given that many of them come with Tor’s solid anonymity network service built-in and this, in turn, gives users an environment for them to live in safely without any data logs whatsoever, unlike most VPN providers that will still log your real IP address while still being able to see whatever data you may be transmitting at the point of exit of VPN servers.
However, VPN still has a sheer amount of advantages over the former which makes it somewhat superior in a way (depending on your use case) – particularly, when you put P2P file-sharing, and general Internet speed into consideration, VPN wins here (more on that later).
The Tor network secures all network traffic that goes through it by bouncing the data off several random nodes in order to reduce the traffic’s traceability chances. Mind you, during this process, every piece of data is re-encrypted several times as it passes through the randomly selected nodes before finally reaching its destination as illustrated in the images below.
Tor Network
Tor Network
Now that you have a basic understanding of how Tor works to the advantage of its users, here is our list of the 15 Best Security-Centric Linux Distributions of this year.

1. Qubes OS

Qubes OS is a security-oriented Fedora-based distro that ensures security by implementing security by compartmentalization. This happens by running every instance of running programs in an isolated virtual environment and then deleting all of its data when the program is closed.
QubesOS Linux Distribution
QubesOS Linux Distribution
Qubes OS uses the RPM package manager and is capable of working with any desktop environment of choice without requiring a lot of computer resources. Cited by Edward Snowden as the “best OS available today“, it is definitely a good choice if you want to make sure that your identity and data are yours alone whether online or offline.

2. TAILS: The Amnesiac Incognito Live System

Tails is a security-centric Debian-based distro designed to protect users’ identity online and keep them anonymous. Its name stands for The Amnesiac Incognito Live System and it is built to force all incoming and outgoing traffic through the Tor network while blocking all traceable connections.
It uses Gnome as its default desktop environment and being a live DVD/USB, can be conveniently run from a pen drive when it stores all its data in the RAM. It ships with open-source tools that are specially meant for privacy-specific reasons such as MAC address spoofing and windows camouflage, to mention a couple.

3. BlackArch Linux

BlackArch Linux is a lightweight Arch Linux-based distribution targetted at penetration testers, security experts, and security researchers. It offers users all the features that Arch Linux has to offer combined with a ton of cybersecurity tools numbering 2000+ that can be installed either individually or in groups.
Compared to other distros on this listed, BlackArch Linux is a relatively new project yet, it has been able to stand out as a reliable OS in the community of security experts. It ships with the user option to choose any of these desktop environments: Awesome, Blackbox, Fluxbox, or spectrwm, and as expected, it is available as a live DVD image and can be run from the convenience of a pen drive.

4. Kali Linux

Kali Linux (formerly BackTrack) is a free advanced Debian-based penetration testing Linux distribution designed for security experts, ethical hacking, network security assessments, and digital forensics.
Kali Linux Distribution
Kali Linux Distribution
It is built to run smoothly on both 32 and 64-bit architectures and right out of the box it comes with a bundle of penetration testing tools that make it one of the most sort-after distros by security-conscious computer users.
There is a lot more that can be said about Kali Linux (as is the case with every other Operating System in this list) but I will leave the deeper digging for you to do.

5. JonDo/Tor-Secure-Live-DVD

JonDo Live-DVD is more or less a commercial anonymity solution that works in a similar fashion as the Tor given the fact that it also routes its packets via specified “mixed servers” – JonDonym – (nodes in the case of Tor) having them re-encrypted each time.
It’s a viable alternative to TAILS especially if you are looking for something with a less restrictive UI (while still a live system) and a close to average user experience.
The distro is based on Debian and also includes an assortment of privacy tools and other commonly used applications.
JonDo Live-DVD is, however, a premium service (for commercial use) which explains why it is targeted at the commercial space. Like Tails, it doesn’t support any native way of saving files and it goes an extra mind to claim to offer users better computing speed.

6. Whonix

7. Discreete Linux

8. IprediaOS

9. Parrot Security OS

10. Subgraph OS

11. Heads OS

12. Alpine Linux

13. PureOS

14. Linux Kodachi

15. TENS




Fuente: www.tecmint.com


sábado, 1 de junio de 2019

Pentesting OS BlackArch (Released with 2200 Hacking Tools)




BlackArch Linux is an Arch Linux-based penetration testing distribution for penetration testers and security researchers. 

The repository contains 2214 tools. You can install tools individually or in groups. BlackArch Linux is compatible with existing Arch installs.



viernes, 12 de octubre de 2018

24 best free security tools (CSO)

Check out these 24 free, standout software tools that will make your daily security work easier. 

Who doesn't love free software? Infosec professionals are fortunate to have many good free tools for a range of tasks. The following list of two dozen tools include everything from password crackers to vulnerability management systems to networks analyzers. Whatever your security role is, you'll find something useful here.


Maltego

Paterva develops this forensics and open-source intelligence app, designed to deliver a clear threat picture for the user's environment. It will demonstrate the complexity and severity of single points of failure as well as trust relationships that exist within the scope of one's infrastructure. It pulls in information posted all over the Internet, whether it's the current configuration of a router on the edge of the company network or the current whereabouts of your company's vice president. The commercial license does have a price tag, but the community edition is free with some restrictions.

OWASP Zed Attack Proxy (ZAP)

The Zed Attack Proxy (ZAP) is a user-friendly penetration testing tool that finds vulnerabilities in web apps. It provides automated scanners and a set of tools for those who wish to find vulnerabilities manually. It's designed to be used by practitioners with a wide range of security experience, and is ideal for functional testers who are new to pen testing, or for developers: There’s even an official ZAP plugin for the Jenkins continuous integration and delivery application.

Samurai Web Testing Framework 


The Samurai Web Testing Framework is a virtual machine packed with some of the other items you'll see in this slideshow, and functions as a web pen-testing environment. You can download a ZIP file containing a VMware image with a host of free and open source tools to test and attack websites. 

KALI (BackTrack) 

Kali Linux is the Linux-based pen-testing toolbox previously known as BackTrack. Security professionals use it to perform assessments in a purely native environment dedicated to hacking. Users have easy access to a variety of tools ranging from port scanners to password crackers. You can download ISOs of Kali to install on 32-bit or 64-bit x86 systems, or on ARM processors. It’s also available as a VM image for VMware or Hyper-V. Kali’s tools are grouped into the following categories: information gathering; vulnerability analysis; wireless attacks; web applications; exploitation tools; stress testing; forensics; sniffing and spoofing; password attacks; maintaining access; reverse engineering; reporting, and hardware hacking.

Cain &Abel 

If you desperately need to access an old Windows system to which no one can remember the password, or even who set the box up, you might find Cain &Abel useful. It’s a password recovery tool for Microsoft operating systems through Windows XP (remember that?) and hasn’t been updated since 2014. It allows for easy recovery of various kinds of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols. It covers some security aspects/weakness present in protocol standards, authentication methods and caching mechanisms. Its main purpose is the simplified recovery of passwords and credentials from various sources.

Fierce Domain Scan 

Another venerable tool, Fierce Domain Scan was last updated by developer Robert Hansen (RSnake) back in 2007. As he described on his ha.ckers blog, it "was born out of personal frustration after performing a web application security audit. Fierce pinpoints likely targets inside and outside a corporate network by looking at DNS entries. It is essentially a reconnaissance tool, a Perl script built to scan domains within minutes, using a variety of tactics. Although Hansen has shut down his blog, Fierce lives on in this Github repository. Because the underlying principles of DNS haven’t changed in the last decade, Fierce still works.

The Harvester

The Harvester is an open-source intelligence tool (OSINT) used to obtain subdomain names, email addresses and user names relating to a domain, drawing on public sources such as Google and LinkedIn. A favorite among pen testers, it lets the user conduct passive reconnaissance and build target profiles that include a list of user names and email addresses -- or research the exposure of their own domain.

Hping

Hping is a command-line tool that can be used to assemble and analyze custom TCP/IP packets. It can be used for firewall testing, port scanning, network testing using different protocols, OS fingerprinting and as an advanced traceroute. It runs on Linux, FreeBSD, NetBSD, OpenBSD, Solaris, MacOs X, and Windows. It hasn’t been updated in years but then, neither has TCP/IP.

John the Ripper

John the Ripper is a password cracker available for many flavors of Unix, Windows, DOS, BeOS, and OpenVMS -- although you’ll likely have to compile the free version yourself. It's mainly used to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix systems, supported out of the box are Windows LM hashes, plus lots of other hashes and ciphers in the community-enhanced version. An enhanced community version includes support for GPUs to accelerate the search.

Nessus

Nessus is one of the world’s most popular vulnerability and configuration assessment tools. It started life as an open-source project, but developer Tenable switched to a proprietary license way back in version 3. As of May 2018 it’s up to version 7.1. Despite that, Nessus is still free for personal use on home networks, where it will scan up to 16 IP addresses. According to the Tenable website, Nessus features high-speed discovery, configuration auditing, asset profiling, sensitive data discovery, patch management integration and vulnerability analysis. 

NMap

Nmap is an open-source tool for network exploration and security auditing, and its developers are still updating it, over 20 years after its launch. It's built to rapidly scan large networks, though it also works against single hosts. According to the NMap website, the scanner uses raw IP packets to determine what hosts are available on the network, which services those hosts are offering, what operating systems they are running, what types of packet filters/firewalls are in use, and dozens of other characteristics. It’s not just for security audits: it can also be used for network inventory, managing service upgrade schedules or -- if you believe its appearances in various Hollywood films -- for hacking brains and tracking superheros. A versatile tool indeed.

OpenVPN

OpenVPN is an open source SSL VPN tool that works in a wide range of configurations, including remote access, site-to-site VPNs, Wi-Fi security, and enterprise-scale remote access solutions. It offers load balancing, failover, and fine-grained access controls. A packaged installer is available for Windows machines, and the code can also run on OpenBSD, FreeBSD, NetBSD, Mac OS X, and Solaris.

Ophcrack

Ophcrack is a free tool for cracking Windows passwords using rainbow tables. It runs on multiple platforms and has a graphical user interface showing real-time graphs to analyze the passwords. It can crack passwords using LM (Windows XP) and NTLM (Vista, 7) hashes using the free rainbow tables available on the site. It also has a brute-force module for simple password and can even dump and load hashes from an encrypted Security Account Manager (SAM) recovered from a Windows partition.

Python Security

The OWASP Python Security Project set out to create a hardened version of Python allowing developers to build applications for use in high-risk environments, and ended up building the largest collection of information about security in the Python programming language. The team focused on two areas: the functional and structural analysis of python applications and open-source code, and on a black-box analysis of the Python interpreter. The project website has a wiki listing all the security concerns they identified.

Wireshark 

Wireshark is a network protocol analyzer that lets users capture and interactively browse traffic running on a computer network. In its more than 20-year development history, it has acquired a long list of features including live capture and offline analysis, and deep inspection of hundreds of protocols, with more being added all the time. It’s multi-platform, running on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD and others. Among its more esoteric features it can analyse VOIP traffic; decrypt SSL/TLS, WEP and WPA/WPA2 traffic, and read traffic carried over USB, Bluetooth and even Frame Relay (remember that?)

ModSecurity 

ModSecurity is a web application monitoring, logging and access control toolkit developed by Trustwave's SpiderLabs Team. It can perform full HTTP transaction logging, capturing complete requests and responses; conduct continuous security assessments; and harden web applications. You can embed it in your Apache 2.x installation or deploy it as a reverse proxy to protect any web server.

ThreadFix 

ThreadFix is a software vulnerability aggregation and vulnerability management system from Denim Group. It matches and merges report results from dynamic, static, and interactive application scanners. It can interact with software defect tracking systems to help developers focus on the most serious problems. The community edition is open source; Denim Group also offers a paid version of ThreadFix with enhanced features.

Burp Suite 

Burp Suite is a Web app security testing platform. Its various tools support the entire testing process, from initial mapping and analysis of an application's attack surface, through to finding and exploiting security vulnerabilities. Tools within the suite include a proxy server, web spider, intruder and a so-called repeater, with which requests can be automated. Portswigger offers a free edition that’s lacking the web vulnerability scanner and some of the advanced manual tools.

Metasploit 

HD Moore created the Metasploit Project in 2003 to provide the security community with a public resource for exploit development. This project resulted in the Metasploit Framework, an open source platform for writing security tools and exploits. In 2009, Rapid7, a vulnerability management solution company, acquired the Metasploit Project. Prior to the acquisition, all development of the framework occurred in the developer's spare time, eating up most weekends and nights. Rapid7 agreed to fund a full-time development team and keep the source code under the three-clause BSD license that is still in use today.

Aircrack-ng 

What Wireshark does for Ethernet, Aircrack-ng does for Wi-Fi. In fact, it’s a complete suite of tools for monitoring packets, testing hardware, cracking passwords and launching attacks on Wi-Fi networks. Version 1.2, released in April 2018, brings big improvements in speed and security and extends the range of hardware Aircrack-ng can work with.

TAILS 

The Amnesiac Incognito Live System (TAILS for short) is a live Linux operating system that you can run from a DVD or USB stick. It’s amnesiac because it doesn’t keep track of your activities from one session to the next, and incognito because it uses Tor for all internet communications. It’s possible to reveal your identity to someone monitoring your Tor connection if you log in to, say, your social networking account, but if you don’t do anything stupid like that, TAILS can go a long way to keeping your online activity secret.

Qubes OS 

Qubes OS modestly describes itself as “a reasonably secure operating system.” It uses the Xen hypervisor to compartmentalize functions in different virtual machines or “qubes”. This allows different activities to be isolated in different qubes. How far you go with this is up to you. If you’re only slightly worried, you might perform your internet banking in one qube, and all your other online activities in another. If you’re really concerned, you might create a new, disposable qube for every email attachment you open, providing some level of assurance that a malicious attachment can’t take over your whole machine. It’s a free download, but you’ll need a 64-bit Intel or AMD machine with 4GB of RAM and 32GB of disk space.


Signal 

Signal is a messaging and voice-and-video-calling app offering end-to-end encryption: That means that even its developers can’t intercept or decrypt your conversations. It’s free for use on Android, iOS or desktop machines running macOS, Linux or Windows. It offers functions such as disappearing messages (that vanish a sender-selectable time after they are read), encrypted group chats, and picture messaging. The Electronic Frontier Foundation suggests using Signal as part of its “Surveillance Self Defense” guide.


Fuente:cso.com.au/