1: Inventory of Authorized and Unauthorized Devices
Friday, 9 May 2014
20 Kontrol Keamanan
Ada 20 kontrol keamanan yang wajib di implementasi menurut SANS:
1: Inventory of Authorized and Unauthorized Devices
2: Inventory of Authorized and Unauthorized Software
3: Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers
4: Continuous Vulnerability Assessment and Remediation
5: Malware Defenses
6: Application Software Security
7: Wireless Access Control
8: Data Recovery Capability
9: Security Skills Assessment and Appropriate Training to Fill Gaps
10: Secure Configurations for Network Devices such as Firewalls, Routers, and Switches
11: Limitation and Control of Network Ports, Protocols, and Services
12: Controlled Use of Administrative Privileges
13: Boundary Defense
14: Maintenance, Monitoring, and Analysis of Audit Logs
15: Controlled Access Based on the Need to Know
16: Account Monitoring and Control
17: Data Protection
18: Incident Response and Management
19: Secure Network Engineering
20: Penetration Tests and Red Team Exercises
1: Inventory of Authorized and Unauthorized Devices
Friday, 11 April 2014
Web Application Security Scanner
Perlu dicoba free dan open source scanner untuk web application security.
http://www.arachni-scanner.com/
Selamat mencoba...
http://www.arachni-scanner.com/
Selamat mencoba...
Wednesday, 12 February 2014
DDOS Attack
Teman2
Bagi yang ingin mengetahui tentang serangan DDOS bisa kunjungi websitenya Prolexic.
http://www.prolexic.com/index.html
Selamat membaca!
Bagi yang ingin mengetahui tentang serangan DDOS bisa kunjungi websitenya Prolexic.
http://www.prolexic.com/index.html
Selamat membaca!
Thursday, 6 February 2014
Pentest FTP
Tools ini bisa digunakan utk pentest FTP.
http://securityxploded.com/ftp-password-sniffer.php
Semoga berguna!
http://securityxploded.com/ftp-password-sniffer.php
Semoga berguna!
Monday, 8 July 2013
Publikasi Spesial NIST (800 Series)
Bagi yang tertarik membaca doumen-dokumen mengenai keamanan informasi yang dipublikasi oleh NIST (800 Series) bisa lihat di link berikut:
http://csrc.nist.gov/publications/PubsSPs.html#800-115
Selamat membaca!!
http://csrc.nist.gov/publications/PubsSPs.html#800-115
Selamat membaca!!
Wednesday, 3 July 2013
PACK (Password Analysis and Cracking Toolkit)
Bagi yang tertarik mempelajari password analysis dan cracking, bisa baca di sini:
http://thesprawl.org/projects/pack/
Salam
http://thesprawl.org/projects/pack/
Salam
Incident Response Fundamentals
Artikel menarik tentang Incident Response.
https://securosis.com/blog/incident-response-fundamentals-trigger-escalate-and-size-up
Semoga bermanfaat!
https://securosis.com/blog/incident-response-fundamentals-trigger-escalate-and-size-up
Semoga bermanfaat!
Subscribe to:
Posts (Atom)