Threat Intelligence

6/5/2018
10:05 AM
100%
0%

10 Open Source Security Tools You Should Know

Open source tools can be the basis for solid security and intense learning. Here are 10 you should know about for your IT security toolkit.
Previous
1 of 11
Next

(Image: Anemone123)

(Image: Anemone123)

The people, products, technologies, and processes that keep businesses secure all come with a cost  — sometimes quite hefty. That is just one of the reasons why so many security professionals spend at least some of their time working with open source security software.

Indeed, whether for learning, experimenting, dealing with new or unique situations, or deploying on a production basis, security professionals have long looked at open source software as a valuable part of their toolkits. 

However, as we all are aware, open source software does not map directly to free software; globally, open source software is a huge business. With companies of various sizes and types offering open source packages and bundles with support and customization, the argument for or against open source software often comes down to its capabilities and quality.

For the tools in this slide show, software quality has been demonstrated by thousands of users who have downloaded and deployed them. The list is broken down, broadly, into categories of visibility, testing, forensics, and compliance. If you don't see your most valuable tool on the list, please add them in the comments.

 

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Previous
1 of 11
Next
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Jon M. Kelley
100%
0%
Jon M. Kelley,
User Rank: Moderator
6/12/2018 | 9:49:10 AM
Paragraph per screen - slowly for Users
Sorry, if I was on your network, I might go through all 11 of your screens. 

Unfortunately I live behind a protective system, and every new page link from DarkReading takes a minute or more to pop up.  The info provided be the multiply is seldom worth the frustration of waiting for it.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
6/20/2018 | 12:46:39 PM
Re: report on tools in .pdf format
Great security here - wow, posting a military email address.  YOU just opened up your email a bit.  Hope that was worth the risk.  Don't do THAT ever again. 
lulzsec
50%
50%
lulzsec,
User Rank: Apprentice
6/21/2018 | 9:28:50 AM
Re: report on tools in .pdf format
nice OPSEC dude - hope soccer season is going well!

 

https://www.linkedin.com/in/marc-kolenko-cissp-ceh-ccsk-m-s-mgmt-8854971
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6691
PUBLISHED: 2019-01-23
phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup database" option.
CVE-2018-19019
PUBLISHED: 2019-01-22
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
CVE-2019-6260
PUBLISHED: 2019-01-22
The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console u...
CVE-2018-19011
PUBLISHED: 2019-01-22
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
CVE-2018-19013
PUBLISHED: 2019-01-22
An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file.