Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 42 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow General Certificationarrow Auotmated Hardening Tools
EH-Net
May 19, 2013, 09:37:45 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Auotmated Hardening Tools  (Read 5707 times)
0 Members and 1 Guest are viewing this topic.
crossover
Newbie
*
Offline Offline

Posts: 21


View Profile
« on: June 28, 2010, 06:54:08 PM »

Hello All ! I'm looking for Automated Tools for Hardening( servers/routers). Any ideas? I know that NIST provides SCAP files but i don't know how to run.

http://cisecurity.org/en-us/?route=downloads.audittools
Logged
Bane
Guest
« Reply #1 on: June 29, 2010, 03:31:44 PM »

Unfortunatelly, there is only one free tool left for SCAP, that I am aware of. Fortunatelly, it works pretty well. The tool is Secutor Prime.

http://www.threatguard.com/downloads.htm
Logged
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #2 on: June 30, 2010, 09:08:40 AM »

SCAP provides validation of tools whether or not the companies providing the tools offer them at a cost or for free are a different story. CISecurity offers their tools at an extremely low cost. It used to be free once upon a time but bandwidth costs money so I don't see a problem with them charging. Especially when its about $300.00

What SPECIFICALLY are you looking to lock down though? The NSA has some pretty good "readme's" along with certain scripts for different types of servers. For example, Win2k3, 2K servers are covered as are desktop variants. For versions of Solaris, I would go with Titan however, with the newer releases of Solaris (lower than 10) you will have to modify Titan to run. Using the same scripts and principals off of Titan, you could port it and run it on the RH family (CentOS, Fedora) unsure about Debian variants.

What is it *specifically* you're looking to lockdown. Routers differ, I could point you to a Cisco hardening guide only to find out you wanted a Juniper guide.
Logged

sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #3 on: June 30, 2010, 10:56:03 AM »

See... A little more clarity makes a lot more sense. So you're looking for a method to lock down multiple components on an enterprise network that consists of Ciscos, Windows, etc...

Now the question becomes... To what degree do you want to lock them down? Let me tell you a little story here... 12 years ago, a company called Security Dynamics (Intrusion) came out with a cool program called Kane Security... Provided pretty much all you asked for on most Windows and Novell systems. At the time I was a security engineer @ a dotcom company which was an MSSP. Kane was "the tool" to have. Offered C2 level security if you needed it...

Being the pain I was back then, I decided to "automate" security processes. I ran Kane on a NT 4 Server Enterprise Edition (they were about a year old back then). Man!!! Did I have security!!! So much security, I couldn't print, couldn't copy and paste, couldn't pretty much do anything. I hadn't taken the time to determine to WHAT EXTENT I needed things secured to. Fun fun fun.

Anyhow, here are some links however, I suggest you create a gameplan instead of relying on too many tools. You'll find at the end of the day its easier to build your own scripts, programs, etc., based on your specific criteria.

NSA Cisco Hardening Guides March 2009
http://www.nsa.gov/ia/_files/routers/cis_securityguides.zip

Microsoft Windows Hardening Tips and Scripts
http://www.nsa.gov/ia/guidance/security_configuration_guides/operating_systems.shtml#microsoft

RHEL Hardening
http://people.redhat.com/sgrubb/files/hardening-rhel5.pdf

Still Secure VAM (if you want to spend some cash)
http://www.stillsecure.com/vam/index.php

Babel Enterprise
http://babelenterprise.com/index.php?lang=en&sec=Babel&sec2=militarizacion

Personally, I would (as stated) probably take a 50k foot view, install something like OSSIM to see what I currently have, where I need to be, and go from there. With OSSIM, you could just script fixes into your risky machines with wmic, python, etc..
Logged

sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #4 on: June 30, 2010, 11:23:22 AM »

Lest I forget...

http://www.mcafee.com/us/enterprise/products/risk_and_compliance/remediation_manager.html
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.075 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.