اگر بدنبال UTM مناسب می باشید محصولات cyberoam بسیار کاربری و دارای امکانات متعدد می باشند ،لطفا مستند محصول را مطالعه فرمائید .
یکی از وظایف مدیران شبکه حفظ امنیت و ارائه راهکارهای ساده برای استقرار شرایط امن در شبکه می باشد و از آنجا که بیشترین آسیب در حملات امنیتی متوجه سرورهای یک سازمان می باشد ؛بنابراین مدیران شبکه باید الزامات و قواعدی را رعایت کنند تا نفوذ و اختلال و یا دسترسی به سرورها به حداقل برسد ،به مجموعه این الزامات
Server hardening
یا مستحکم سازی سرورها گفته می شود.
ولی از آنجا که هر سرور بسته به نوع سرویسی که ارائه می دهد مکانیزم های مستحکم سازی متفاوتی دارد بنابراین مدیران شبکه باید چک لیستی از حداقل های الزامات را داشته و سعی در عملی سازی آن بکنند.در پستهای بعدی سعی خواهم کرد که برای هر سرویس مشهور در شبکه چک لیستی ارایه داده تا به عنوان یک baseline شما دوستان بتوانید hardening سرورهای خود را انجام دهید .بدیهی است چک لیستهای ارائه شده حاوی حداقلهای الزامات است واین به معنی کفایت امر hardening نمی باشد.
و این هم یادمون نره که امنیت نسبی است.
Server hardening
یا مستحکم سازی سرورها گفته می شود.
ولی از آنجا که هر سرور بسته به نوع سرویسی که ارائه می دهد مکانیزم های مستحکم سازی متفاوتی دارد بنابراین مدیران شبکه باید چک لیستی از حداقل های الزامات را داشته و سعی در عملی سازی آن بکنند.در پستهای بعدی سعی خواهم کرد که برای هر سرویس مشهور در شبکه چک لیستی ارایه داده تا به عنوان یک baseline شما دوستان بتوانید hardening سرورهای خود را انجام دهید .بدیهی است چک لیستهای ارائه شده حاوی حداقلهای الزامات است واین به معنی کفایت امر hardening نمی باشد.
و این هم یادمون نره که امنیت نسبی است.
چک لیست فوق نکاتی در مورد امنیت سرورهای IIS جهت hardening می باشد.👆👆👆👆👆👆
نرم افزار LC6 یکی از ابزارهای پیشرفته برای ریکاوری پسورد و بازرسی پسورد می باشد ،از خصوصیات جالب آن واسط کاربری ساده و سرعت بالای آن در
Password brute force
می باشد.
Password brute force
می باشد.
نرم افزار cain and abel (همون هابیل و قابیل خودمون 😜 ) یکی از نرم افزارهای مطرح در windows برای
Password recovery
به حساب میاد .
Cain and Abel (often abbreviated to Cain) is a password recovery tool for Microsoft Windows. It can recover many kinds of passwords using methods such as network packet sniffing, cracking various password hashes by using methods such as dictionary attacks, brute force and cryptanalysis attacks. Cryptanalysis attacks are done via rainbow tables which can be generated with the winrtgen.exe program provided with Cain and Abel. Cain and Abel is maintained by Massimiliano Montoro and Sean Babcock.
از این نرم افزار جالب لذت ببرید.
@nettrain
http://www.telegram.me/nettrain
Password recovery
به حساب میاد .
Cain and Abel (often abbreviated to Cain) is a password recovery tool for Microsoft Windows. It can recover many kinds of passwords using methods such as network packet sniffing, cracking various password hashes by using methods such as dictionary attacks, brute force and cryptanalysis attacks. Cryptanalysis attacks are done via rainbow tables which can be generated with the winrtgen.exe program provided with Cain and Abel. Cain and Abel is maintained by Massimiliano Montoro and Sean Babcock.
از این نرم افزار جالب لذت ببرید.
@nettrain
http://www.telegram.me/nettrain
👍1
1. Nmap
Nmap (“Network Mapper”) is a free and open source (license) utility for network discovery and security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network,
what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. It was designed to rapidly scan large networks, but works fine against single hosts. Nmap runs on all major computer operating systems, and official binary packages are available for Linux, Windows, and Mac OS X. In addition to the classic command-line Nmap executable, the Nmap suite includes an advanced GUI and results viewer (Zenmap), a flexible data transfer, redirection, and debugging tool (Ncat), a utility for comparing scan results (Ndiff), and a packet generation and response analysis tool (Nping).
2. Angry IP Scanner
Angry IP Scanner (or simply ipscan) is an open-source and cross-platform network scanner designed to be fast and simple to use. It scans IP addresses and ports as well as has many other features.
It is widely used by network administrators and just curious users around the world, including large and small enterprises, banks, and government agencies. It runs on Linux, Windows, and Mac OS X, possibly supporting other platforms as well.
3. SuperScan
SuperScan 4 is an update of the highly popular Windows port scanning tool, SuperScan.
Windows XP Service Pack 2 has removed raw sockets support which now limits SuperScan
and many other network scanning tools. Some functionality can be restored by running
the following at the Windows command prompt before starting SuperScan:
net stop SharedAccess
Here are some of the new features in this version.
Superior scanning speed
Support for unlimited IP ranges
Improved host detection using multiple ICMP methods
TCP SYN scanning
UDP scanning (two methods)
IP address import supporting ranges and CIDR formats
Simple HTML report generation
Source port scanning
Fast hostname resolving
Extensive banner grabbing
Massive built-in port list description database
IP and port scan order randomization
A selection of useful tools (ping, traceroute, Whois etc)
Extensive Windows host enumeration capability
4. unicornscan
Unicornscan is a new information gathering and correlation engine built for and by members of the security research and testing communities. It was designed to provide an engine that is Scalable, Accurate, Flexible, and Efficient. It is released for the community to use under the terms of the GPL license.
Benefits:
Unicornscan is an attempt at a User-land Distributed TCP/IP stack. It is intended to provide a researcher a superior interface for introducing a stimulus into and measuring a response from a TCP/IP enabled device or network. Although it currently has hundreds of individual features, a main set of abilities include:
Asynchronous stateless TCP scanning with all variations of TCP Flags.
Asynchronous stateless TCP banner grabbing
Asynchronous protocol specific UDP Scanning (sending enough of a signature to elicit a response).
Active and Passive remote OS, application, and component identification by analyzing responses.
PCAP file logging and filtering
Relational database output
Custom module support
Customized data-set views
5. autoscan
AutoScan-Network is a network scanner (discovering and managing application). No configuration is required to scan your network. The main goal is to print the list of connected equipments in your network.
Benefits
Fast network scanner
Automatic network discovery
TCP/IP scanner
Wake on lan functionality
Multi-threaded Scanner
Port scanner
Low surcharge on the network
VNC Client
Telnet Client
SNMP scanner
Simultaneous subnetworks scans without human intervention
Realtime detection of any connected equipment
Super
Nmap (“Network Mapper”) is a free and open source (license) utility for network discovery and security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network,
what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. It was designed to rapidly scan large networks, but works fine against single hosts. Nmap runs on all major computer operating systems, and official binary packages are available for Linux, Windows, and Mac OS X. In addition to the classic command-line Nmap executable, the Nmap suite includes an advanced GUI and results viewer (Zenmap), a flexible data transfer, redirection, and debugging tool (Ncat), a utility for comparing scan results (Ndiff), and a packet generation and response analysis tool (Nping).
2. Angry IP Scanner
Angry IP Scanner (or simply ipscan) is an open-source and cross-platform network scanner designed to be fast and simple to use. It scans IP addresses and ports as well as has many other features.
It is widely used by network administrators and just curious users around the world, including large and small enterprises, banks, and government agencies. It runs on Linux, Windows, and Mac OS X, possibly supporting other platforms as well.
3. SuperScan
SuperScan 4 is an update of the highly popular Windows port scanning tool, SuperScan.
Windows XP Service Pack 2 has removed raw sockets support which now limits SuperScan
and many other network scanning tools. Some functionality can be restored by running
the following at the Windows command prompt before starting SuperScan:
net stop SharedAccess
Here are some of the new features in this version.
Superior scanning speed
Support for unlimited IP ranges
Improved host detection using multiple ICMP methods
TCP SYN scanning
UDP scanning (two methods)
IP address import supporting ranges and CIDR formats
Simple HTML report generation
Source port scanning
Fast hostname resolving
Extensive banner grabbing
Massive built-in port list description database
IP and port scan order randomization
A selection of useful tools (ping, traceroute, Whois etc)
Extensive Windows host enumeration capability
4. unicornscan
Unicornscan is a new information gathering and correlation engine built for and by members of the security research and testing communities. It was designed to provide an engine that is Scalable, Accurate, Flexible, and Efficient. It is released for the community to use under the terms of the GPL license.
Benefits:
Unicornscan is an attempt at a User-land Distributed TCP/IP stack. It is intended to provide a researcher a superior interface for introducing a stimulus into and measuring a response from a TCP/IP enabled device or network. Although it currently has hundreds of individual features, a main set of abilities include:
Asynchronous stateless TCP scanning with all variations of TCP Flags.
Asynchronous stateless TCP banner grabbing
Asynchronous protocol specific UDP Scanning (sending enough of a signature to elicit a response).
Active and Passive remote OS, application, and component identification by analyzing responses.
PCAP file logging and filtering
Relational database output
Custom module support
Customized data-set views
5. autoscan
AutoScan-Network is a network scanner (discovering and managing application). No configuration is required to scan your network. The main goal is to print the list of connected equipments in your network.
Benefits
Fast network scanner
Automatic network discovery
TCP/IP scanner
Wake on lan functionality
Multi-threaded Scanner
Port scanner
Low surcharge on the network
VNC Client
Telnet Client
SNMP scanner
Simultaneous subnetworks scans without human intervention
Realtime detection of any connected equipment
Super
vision of any equipment (router, server, firewall…)
Supervision of any network service (smtp, http, pop, …)
Automatic detection of known operatic system (brand and version), you can also add any unknown equipment to the database
The graphical interface can connect one or more scanner agents (local or remote)
Scanner agents could be deployed all over the network to scan through any type of equipment (router, NAT, etc)
Network Intruders detection (in intruders detection mode, all new equipments blacklisted)
Complete network tree can be saved in a XML file.
Privileged account is not required
برای شناسایی و اسکن پورتهای باز مدیران شبکه از ابزارهای مختلفی استفاده می کنند ،که به طور کلی به آنها port scanner اطلاق می شود ؛ابزارهای متعدد و عمدتا رایگان برای این منظور ساخته شده است که برخی تحت سیستم عامل ویندوز و نسخه های حرفه ای تر عمدتا تحت لینوکس می باشند ؛در ابتدای این پست 5 ابزار مفید برای این کار معرفی شده است.
@nettrain
http://www.telegram.me/nettrain
Supervision of any network service (smtp, http, pop, …)
Automatic detection of known operatic system (brand and version), you can also add any unknown equipment to the database
The graphical interface can connect one or more scanner agents (local or remote)
Scanner agents could be deployed all over the network to scan through any type of equipment (router, NAT, etc)
Network Intruders detection (in intruders detection mode, all new equipments blacklisted)
Complete network tree can be saved in a XML file.
Privileged account is not required
برای شناسایی و اسکن پورتهای باز مدیران شبکه از ابزارهای مختلفی استفاده می کنند ،که به طور کلی به آنها port scanner اطلاق می شود ؛ابزارهای متعدد و عمدتا رایگان برای این منظور ساخته شده است که برخی تحت سیستم عامل ویندوز و نسخه های حرفه ای تر عمدتا تحت لینوکس می باشند ؛در ابتدای این پست 5 ابزار مفید برای این کار معرفی شده است.
@nettrain
http://www.telegram.me/nettrain
از نرم افزار angry ip لذت ببرید ،دوستان برای استفاده از این نرم افزار نیاز به جاوا دارین .
@nettrain
http://www.telegram.me/nettrain
@nettrain
http://www.telegram.me/nettrain
در دنیای حرفه ای شبکه بندرت می توان کسی را یافت که نام مارک رزینوویچ را نشنیده باشد ،برنامه نویس قهار و فوق حرفه ای که قدرت برنامه نویسیش را با ارائه مجموعه ابزارهای sysinternal به رخ جهانیان کشید و غول ردموند را وادار به خرید این شرکت کوچک کرد تا در زیر سایه شرکت عظیم ماکروسافت ایده های ناب خود را بتواند راحت تر پیاده سازی کند ،مجموعه sysinternal ابزارهای بسیار کوچک و کارآمد و کاربردی هستند که بخصوص در عیب یابی شبکه بشدت کاربرد دارند و بر روی نقاطی از سیستم عامل ویندوز دست گذاشته است که این سیستم عامل یا راه حلی برای آن مشکل ندارد و یا برای انجام آن وظایف وقت زیادی از مدیر شبکه گرفته می شود. بعنوان مثال اجرای یک برنامه از راه دور و از طریق ویندوز برای بسیاری از مدیران شبکه کار سختی است در حالیکه در لینوکس بشدت این کار ساده و تعداد زیادی راه حل بومی دارد ،در مجموعه sysinternal با ابزار psexec به راحتی اینکار امکان پذیر است .از این ابزارها لذت برده و قدرت خود را درشبکه چند برابر کنید.
Sysinternals Learning
Mark's Webcasts
Mark's Blog
Software License
Licensing FAQ
Sysinternals Suite
By Mark Russinovich
Updated: April 28, 2016
Download Sysinternals Suite
(15.7 MB)
Rate:
Share this content # # # # #
Introduction
The Sysinternals Troubleshooting Utilities have been rolled up into a single Suite of tools. This file contains the individual troubleshooting tools and help files. It does not contain non-troubleshooting tools like the BSOD Screen Saver or NotMyFault.
The Suite is a bundling of the following selected Sysinternals Utilities:
AccessChk
AccessEnum
AdExplorer
AdInsight
AdRestore
Autologon
Autoruns
BgInfo
CacheSet
ClockRes
Contig
Coreinfo
Ctrl2Cap
DebugView
Desktops
Disk2vhd
DiskExt
DiskMon
DiskView
Disk Usage (DU)
EFSDump
FindLinks
Handle
Hex2dec
Junction
LDMDump
ListDLLs
LiveKd
LoadOrder
LogonSessions
MoveFile
NTFSInfo
PendMoves
PipeList
PortMon
ProcDump
Process Explorer
Process Monitor
PsExec
PsFile
PsGetSid
PsInfo
PsPing
PsKill
PsList
PsLoggedOn
PsLogList
PsPasswd
PsService
PsShutdown
PsSuspend
RAMMap
RegDelNull
Registry Usage (RU)
RegJump
SDelete
ShareEnum
ShellRunas
Sigcheck
Streams
Strings
Sync
Sysmon
TCPView
VMMap
VolumeID
WhoIs
WinObj
ZoomIt
@nettrain
http://www.telegram.me/nettrain
Sysinternals Learning
Mark's Webcasts
Mark's Blog
Software License
Licensing FAQ
Sysinternals Suite
By Mark Russinovich
Updated: April 28, 2016
Download Sysinternals Suite
(15.7 MB)
Rate:
Share this content # # # # #
Introduction
The Sysinternals Troubleshooting Utilities have been rolled up into a single Suite of tools. This file contains the individual troubleshooting tools and help files. It does not contain non-troubleshooting tools like the BSOD Screen Saver or NotMyFault.
The Suite is a bundling of the following selected Sysinternals Utilities:
AccessChk
AccessEnum
AdExplorer
AdInsight
AdRestore
Autologon
Autoruns
BgInfo
CacheSet
ClockRes
Contig
Coreinfo
Ctrl2Cap
DebugView
Desktops
Disk2vhd
DiskExt
DiskMon
DiskView
Disk Usage (DU)
EFSDump
FindLinks
Handle
Hex2dec
Junction
LDMDump
ListDLLs
LiveKd
LoadOrder
LogonSessions
MoveFile
NTFSInfo
PendMoves
PipeList
PortMon
ProcDump
Process Explorer
Process Monitor
PsExec
PsFile
PsGetSid
PsInfo
PsPing
PsKill
PsList
PsLoggedOn
PsLogList
PsPasswd
PsService
PsShutdown
PsSuspend
RAMMap
RegDelNull
Registry Usage (RU)
RegJump
SDelete
ShareEnum
ShellRunas
Sigcheck
Streams
Strings
Sync
Sysmon
TCPView
VMMap
VolumeID
WhoIs
WinObj
ZoomIt
@nettrain
http://www.telegram.me/nettrain
برای دوستانی که به اطلاعات بیشتری در زمینه sysinternal نیاز دارند کتاب مرجعش رو توی کانال میزارم تا به شکل حرفه ای تری با این مجموعه ابزار کار کنید.