Vendors/Products - Page 42
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.
SafeNet is shipping an "integrated IPSec VPN platform" software said to support VPN connections from next-generation mobile devices. QuickSec 4.1 Server and Client Toolkits helps developers incorporate the most current IPSec security standards, such as MobIKE, into carrier-grade security gateways, network routers, mobile VPN devices, and desktop VPN clients, according to the company.
I first touched a BSD box in around 1994, thanks to the donation of a BSD/OS system and SLIP connection from UUNet to my high school. It was love at first sight! Discovering FreeBSD not long after, I've been a regular FreeBSD user since around 1995, although I only became involved in FreeBSD development in 1999, gaining a "commit bit" to help maintain the FreeBSD portions of the Coda distributed file system, a project I had worked on while at Carnegie Mellon University. My undergraduate degree is in Logic and Computation, from CMU's philosophy department, along with a double major in Computer Science, but it became clear that my greatest interest lay in operating systems and security. After working on file system ACLs and mandatory access control for FreeBSD, I started the TrustedBSD Project in 2000, with the goal of bringing more advanced security features to the platform. In 2001, while working at Network Associates Laboratories (NAI Labs, and later McAfee Research), I proposed and became Principal Investigator on a research project as part of DARPA's CHATS research program, which was investigating security and open source. This project included sponsoring and developing UFS2, OpenPAM, the TrustedBSD MAC Framework, NSS support, PAE support, several network stack hardening projects (including syncache and syncookies for FreeBSD), GEOM, and GBDE.
You may not always be able to protect your laptop from a thief, but you can keep the data it contains safe. Two new products -- PGP Corp.'s PGP Whole Disk Encryption 9.5 and SecurStar GmbH's DriveCrypt Plus Pack 3.5 -- promise to protect your data, so that even if your computer falls into the wrong hands, its contents will remain unreadable. Both applications are easy to use and offer an impressive suite of tools, but most users will appreciate the more practical features and lower price tag of PGP's product. Both PGP and DriveCrypt offer on-the-fly, full-disk encryption, which means that they scramble all the data on your hard drive the moment you save it to disk. Both use the AES-256 algorithm, a fast, well-established and trusted mechanism for encrypting data.
OpenSSH 4.5 has just been released. It will be available from the mirrors listed at http://www.openssh.com/ shortly. OpenSSH is a 100% complete SSH protocol version 1.3, 1.5 and 2.0 implementation and includes sftp client and server support.
Guardian Digital is pleased to announce the release of EnGarde Secure Community 3.0.10 (Version 3.0, Release 10). This release includes our new SELinux Control Console and our new context-sensitive Guardian Digital help system, along with bug fixes and upgrades to major applications including Apache, Postfix, and Snort. For details, see our new Community News and Upgrade page at: /modules/index/releases/3.0.10.cgi
The Atlanta-based software maker introduced several new add-ons to DevInspect 3.0, which promises to help Web applications designers locate potential flaws in their work using so-called black box testing tools in combination with source code inspection technology. By identifying and verifying exploitable security defects using the automated black box system, and scouring program source code for more common errors, the company maintains that the product provides customers with a hybrid technique for eliminating potential glitches in Web-based systems. The product also seeks to facilitate more effective communication related to vulnerability reporting and remediation between IT security specialists and software developers.
The Kanguru Bio Slider II is a USB 2.0 secure flash drive made complete with the most up-to-date biometric fingerprint technology. The drive offers a low maintenance, effortless approach to protecting and storing your data.
Seagate Technology will soon begin shipping its first hard drives with special encryption chips that will make it impossible to read data off the disk -- or even boot up a PC -- without some form of authentication Relevant Products/Services. The world's largest hard drive maker said its new DriveTrust Technology, which is designed to encrypt data stored on the hard drive automatically, will require users to have a key, or password, before being able to access the drive. The new Momentus 5400 FDE.2 (Full Disk Encryption 2), geared to notebook Relevant Products/Services computers, will come in several capacities, including 80 GB, 120 GB, and 160 GB. Seagate said it expects to ship the drives early next year.
Beyond displaying an extensive slate of existing Linux products, vendors at this week's InfoSecurity show pointed to possible future offerings ranging from a Linux client for a CD-ROM encryption system to a Linux-enabled all-in-one device for securing both physical access and video surveillance. In a sign of the growing convergence between information security and physical security, the InfoSecurity conference was combined this year with the East coast edition of the ISC show, another perennial event at New York City's Javits Center. Conference sessions tended to skirt matters specific to OS and interoperability, focusing instead on convergence issues such as organizational restructurings and information sharing, as well as on what general types of tools to deploy against the latest nuances in bots, pharming, and other cyberattacks.
A security flaw in the binary NVidia graphics drivers used by many Linux systems could allow an attacker to compromise, through a malicious Web page, any computer using the company's driver, security firm Rapid7 stated on Monday. The NVidia Binary Graphics Driver for Linux remains vulnerable, the company said in an advisory. However, the flaw has been publicly reported and may have been known about as early as December 2004, prompting the company to report the issue publicly.
I am a web application security specialist and have been referred to as a web application firewall guy. In truth, I have many diverse interests (most of them related to technology) but I tend to deal with only one at a time. We live in exciting times when there is so much to do; wherever you look there is room for improvement. My background is in software development and I have spent significant time architecting software systems. However, over the last couple of years I became focused exclusively on security. Today I am probably best known for my work on ModSecurity, which is an open source web application firewall, and my book, Apache Security, which was published by O'Reilly in 2005.
Breach Security announced the release of the ModSecurity version 2.0 open source Web application firewall. ModSecurity version 2.0 provides greater flexibility, enhanced attack detection, and support for XML and Web Services. At the same time, Breach Security is releasing the ModSecurity Console for monitoring multiple sensors and ModSecurity Core Rules that together provide easy-to-deploy baseline Web application security.
The GNU telephony project reports that GPL-licensed implementations of two key security protocols are available for use in Linux-based VoIP (voice-over-IP) devices and softphones. Additionally, a GPL-licensed softphone based on the new implementations is already available for download, testing, and use. The two new security protocol implementations include: SRTP ZRTP
Running on almost twenty different architectures, and easily portable to others, NetBSD gained its reputation as the most portable operating system on the planet. While that may indicate high quality code, the ever demanding networked world cares about more than just that. Over the past year, NetBSD evolved quite a bit in various areas. This paper, however, will focus on those aspects relating to security. This paper was written and structured to present a full overview of the recent security enhancements in NetBSD in an easily readable and balanced form that will satisfy new, intermediate, and experienced users. References were sprinkled across the text to provide more information to those who want more detail, while preserving the continuity.
A U.K. company hopes a cell phone security system it has developed will halt a spiraling rise in phone theft. The system sets off a high pitch scream, permanently locks the handset and wipes all data if reported stolen.
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.9 (Version 3.0, Release 9). This release includes several bug fixes and feature enhancements to the Guardian Digital WebTool and the SELinux policy, several updated packages, and a couple of new packages available for installation.
Microsoft gives away a security firewall with its latest operating system. Many high-speed Internet service providers offer free anti-virus protection for subscribers. And several Web sites distribute free toolbars to warn of Web scams. AOL even recently made a package of basic security tools
NX short form for NoMachine's X protocol is a compression technology developed by NoMachine which allows one to run complete remote desktop sessions (be it Linux or Windows) even at dial up internet connection speeds. One of the advantages of using NX technology over VNC is that NX uses SSH on port 22 for connection between the client and the server. Which means all the communication takes place encrypted through industry standard SSL public key cryptography.
Mozilla Corp. has hired a former Microsoft security strategist to help secure its open-source software, particularly its Firefox browser. Window Snyder, whose hiring was announced last week, takes the title of "Chief Security Something" -- that's a working title, and not all that unusual for a company headed by someone who once held the title of "Chief Lizard Wrangler" -- said she has big plans for the group's development efforts.
Mozilla on Sept. 14 reissued the popular open-source Firefox Web browser, and its email counterpart, Thunderbird, with new security and stability fixes. Each of the open-source apps rolls to version 1.5.0.7. Firefox 1.5.0.7 comes with fixes for half-a-dozen minor security vulnerabilities. The first of these is a patch that will prevent possible attacks from opening a previously blocked popup that was using an XSS (cross-site scripting) attack.