Internet Security


Programs

A keyboard led heartbeat program for linux which shows the load average as the flash frequency and with an integrated PS/2-keylogger detector:

heartbeat++.c



See also

Introduction to Basic Computer Security: A series of articles written by Jennifer Vesperman that discuss the various aspects of computer security. http://tldp.org/docs.html#intro

The (german) Live-CD Knoppicillin with the virus scanners BitDefender Antivirus Scanner, F-Secure Anti-Virus and Sophos SAVScan with an online-update.
The virus scanners do find also other malware than viruses and booting from CD prevents counteractive measures from rootkits and other malware.

An alternative for the knoppicillin is the Ultimate Boot CD, also with 3 virus scanners.

Securing Debian Manual

Hardening a Linux or OpenBSD Installation

Security at Heise

Linux Security Howto

Linux Administrator's Security Guide

Deniable encryption e. g. with TrueCrypt or the Encrypted Root File System Howto (Linux) or plus steganography and data compression with steghide

Network Security Hacks (O'REILLY book)

Bruce Schneier (security technologist)

How to choose an easy to memorize and safe password (in german), but i do recommend more than 10 characters for a password.

Anti-Spyware possibilities (directory loops, data hiding, etc.)

Physical IT Security with fire-, water- and bomb-safe 19"-racks (www.lampertz.de)

Common Criteria (CC)

Common Criteria (CC) at the BSI

IT-Grundschutz-Handbuch (2006: 3612 Seiten dick)

Verschlüsselung / Kryptografie / Steganografie für Mail, Dateien, Tauschbörsen / VoIP etc. (http://argh-it.de/crypto/)

Warnung vor den potenziellen Gefahren des Internet sowie möglichen Maßnahmen für seine sichere Nutzung. Vom Landeskriminalamt Baden-Württemberg.

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein

Sicherheit, Datenschutz, anonym surfen im Internet

http://www.bsi-fuer-buerger.de/

Onion Router like TOR for countermeasuring Packet sniffing, Traffic analysis and Telecommunications data retention.

Proxies like Squid and frox for Web caching, countermeasuring IP/OS/browser/referer etc. spying via http headers, and for proxy chaining. They can also be used for transparent proxying, e. g. for Onion Router exit nodes.

Freemailers with strong encryption for countermeasuring email surveillance even without PGP/GPG (see also http://www.gulli.com/netzwelt/ueberwachung/emailueberwachung/):
Hushmail (see also http://www.gulli.com/news/hushmail-petzt-verschl-2007-11-08/ ).
Safe-Mail
And don't forget to use (free)mailers only via Anonymizers or Onion Routing and neigther with your official IP nor your real data. If you need to fake data you can use e. g. notwhoami or google and an webside imprint or a whois output or ...

Link-Sammlung vom AK Vorrat

Security Tools, security lists and scanners at http://insecure.org/

Anti-Forensics:
Metasploit Anti-forensics homepage
http://www.ouah.org/p63-0x0b_Advanced_Antiforensics_and_SELF.txt
http://www.cio.com/article/print/114550
http://www.blackhat.com/presentations/bh-usa-05/bh-us-05-foster-liu-update.pdf
http://www.simson.net/clips/academic/2007.ICIW.AntiForensics.pdf
http://ws.hackaholic.org/slides/AntiForensics-CodeBreakers2006-Translation-To-English.pdf
Network Forensics Evasion: How to Exit the Matrix

A list of censorship-free DNS servers can be found e. g. at the CCC here for countermeasuring censorship via DNS.

echelonsig for countermeasuring Echelon and Carnivore (FBI).

Software anti-TEMPEST and the Complete, Unofficial TEMPEST Information Page.

The Book "How to Be Invisible", A Step-By-Step Guide To Protecting Your Assets, Your Identity, And Your Life.

See also Inside Echelon, Stasi 2.0 and decreasing the MTU for countermeasuring keyword based packet filtering or sniffing.