From Fedora Project Wiki

(Add etherape to recon list and prelude-{manager,notify} to the ids list)
 
(119 intermediate revisions by 22 users not shown)
Line 1: Line 1:
[[File:Spins-banner_security.png]]
<!-- All fields on this form are required to be accepted by the Spins SIG
We also request that you maintain the same order of sections so that all of the feature pages are uniform.  -->
= Fedora Security Spin =
= Fedora Security Spin =
{{admon/note|Wiki Page Purpose|This page follows the [[Spins_Process]]. The Development Home can be found at https://pagure.io/security-lab}}
== Summary ==
The Fedora Security Spin is a live media based on Fedora to provide a safe test environment for working on security auditing, forensics and penetration testing, coupled with all the Fedora Security features and tools.


== Goals ==
== Owner(s) ==
* To provide a fully functional livecd based on Fedora for use in security auditing, forensics, and penetration testing.
* Owner(s): [[User:q5sys | JT Pennington]]
 
== Features ==
* All of the security [[Security/Features| features]] and tools Fedora has to offer
* Ability to install directly to hard disk or usb drives
* Read-write rootfs so it's possible to install software while the livecd is running
* Minimal openbox desktop, with a customized menu ([http://lewk.org/img/securityspin.png Screenshot])


== Spinning your own ==
* Quality Assurance: [[User:Athmane | Athmane Madjoudj ]]
<pre>
$ hg clone http://hg.lewk.org/security-livecd
</pre>
Making changes to the LiveCD is as simple as modifying the '''livecd-fedora-security.ks''' configuration file.


== Contributing ==
* Former Owner(s): [[User:Lmacken | Luke Macken]], [[User:Maxamillion | Adam John Miller]], [[User:Cwickert | Christoph Wickert]], [[User:Hiemanshu | Hiemanshu Sharma]], [[User:Jsimon | Joerg Simon]], [[User:fab | Fabian Affolter]]
You can help with this project by writing RPMS for packages in the Wishlist, reviewing existing new package reports, tweaking the livecd configuration, among many other things.


Send patches, suggestions, etc to LukeMacken.
== Detailed Description ==
The spin is maintained by a community of Security testers and developers. It comes with the clean and fast Xfce Desktop Environment and a customized menu to have all the instruments one may need to follow a proper test path on security testing or to rescue a broken system. With the read-write rootfs, it is possible to install software while the live media is running. The Fedora livemedia-creator provides an overlay feature to put the Fedora Security Lab on an USB stick so that the user can install and update software and can save his test results permanently.


== Software ==
== Benefit to Fedora ==
=== Available ===
* Covered by the above description
The following packages currently exist in Fedora and are on the Security LiveCD.
* A stable platform for teaching security along security classes in universities and organisations
{| border="1"
** People learn about Fedora through these classes
|- style="color: white; background-color: #3074c2; font-weight: bold"
* Showcase for security features and testing
| '''Software''' || '''Description'''
* A tool set for proper security testing
|- ||style="color: black; background-color: #eeeff1"
* A complete repair/rescue system - with tools not contained on the other Live media to rescue your system
| ''Reconnaissance''
* Gather interested people to package new tools for this spin
|-
* Cool marketing instrument and a story to tell
| [http://ettercap.sourceforge.net ettercap] || Ettercap is a suite for man in the middle attacks on LAN. It
* There are industry partners who are interested to contribute
features sniffing of live connections, content filtering on the fly
and many other interesting tricks. It supports active and passive
dissection of many protocols (even ciphered ones) and includes many
feature for network and host analysis.
|-
| [http://monkey.org/~dugsong/dsniff/ dsniff]  || dsniff is a collection of tools for network auditing and penetration testing. ||
|-
|[http://www.hping.org/ hping3] || TCP/IP stack auditing and much more
|-
| [http://iptraf.seul.org iptraf] || IPTraf is a console-based network monitoring utility.
|-
|[http://www.deepspace6.net/projects/netcat6.html nc6]  || Netcat with IPv6 Support
|-
|[http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/nc/ nc]  || Reads and writes data across network connections using TCP or UDP
|-
|[http://www.nessus.org nessus] || Remote vulnerability scanner
|-
|[http://ngrep.sourceforge.net/  ngrep] || Network layer grep tool
|-
|[http://www.insecure.org/nmap/ nmap] || Network exploration tool and security scanner
|-
|[http://lcamtuf.coredump.cx/p0f.shtml p0f]  || Versatile passive OS fingerprinting tool
|-
|[http://monkey.org/~provos/scanssh scanssh]  || Fast SSH server and open proxy scanner
|-
|[http://www.dest-unreach.org/socat socat] || Bidirectional data relay between two data channels ('netcat++')
|-
|[http://www.tcpdump.org tcpdump]  || A network traffic monitoring tool
|-
|[http://www.nongnu.org/tiger/ tiger] || Security auditing on UNIX systems
|-
|[http://www.wireshark.org/ wireshark]  || Network traffic analyzer
|-
|[http://www.sys-security.com/index.php?page=xprobe xprobe2]  || An active operating system fingerprinting tool
|-
|[http://www.inetcat.net/software/nbtscan.html nbtscan]  || Tool to gather NetBIOS info from Windows networks
|-
| [http://tcpxtract.sourceforge.net/ tcpxtract]  || Tool for extracting files from network traffic based on file signatures
|-
| [http://www.packetfactory.net/projects/firewalk/ firewalk]  || Firewalk is an active reconnaissance network security tool that attempts to determine what layer 4 protocols a  given IP forwarding device will pass.
|-
| [http://lin.fsid.cvut.cz/~kra/index.html hunt]  || Tool for demonstrating well known weaknesses in the TCP/IP protocol suite
|-
| [http://halberd.superadditive.com halberd]  || Tool to discover HTTP load balancers
|-
| [http://qosient.com/argus/ argus] || Argus is a fixed-model Real Time Flow Monitor designed to track and report on the status
and performance of all network transactions seen in a data network traffic stream.
|-
| [http://www.eff.org/testyourisp/pcapdiff/ pcapdiff] || Compares packet captures, detects forged, dropped or mangled packets
|-
|[http://www.wallinfire.net/picviz picviz] || Picviz is a parallel coordinates plotter which enables easy scripting from various input (tcpdump, syslog, iptables logs, apache logs, etc..) to visualize your data and discover interesting results quickly.  Its primary goal is to graph data in order to be able to quickly analyze problems and find correlations among variables. With security analysis in mind, the program has been designed to be very flexible, able to graph millions of events.  The language is designed to be close to the graphviz graph description language.
|-
| [http://etherape.sourceforge.net/ etherape] || EtherApe is a graphical network monitor modeled after etherman.


|- ||style="color: black; background-color: #eeeff1"
== Kickstart File ==
| ''Forensics''
|-
|[http://www.chkrootkit.org chkrootkit] || Tool to locally check for signs of a rootkit
|-
|[http://www.clamav.net clamav] || Clam Antivirus
|-
|[http://www.garloff.de/kurt/linux/ddrescue/ dd_rescue] || Fault tolerant "dd" utility for rescuing data from bad media
|-
|[http://www.stud.uni-hannover.de/user/76201/gpart/ gpart]  || A program for recovering corrupt partition tables
|-
|[http://merd.sourceforge.net/pixel/hexedit.html hexedit] ||  A hexadecimal file viewer and editor
|-
|[http://prelude-ids.org/ prelude] || Log analyzer
|-
|[http://www.cgsecurity.org/wiki/TestDisk testdisk]  || Tool to check and undelete partition
|-
|[http://foremost.sf.net foremost]  || Recover files by "carving" them from a raw disk
|-
| [http://fedorahosted.org/sectool sectool] || A security audit system and intrusion detection system
|-
| [http://www.rootkit.nl/projects/rootkit_hunter.html rkhunter]  || A host-based tool to scan for rootkits, backdoors and local exploits
|- ||style="color: black; background-color: #eeeff1"
|-
| [http://taviso.decsystem.org/scanmem.html scanmem]  || scanmem is a simple interactive debugging utility, used to locate
the address of a variable in an executing process. This can be used
for the analysis or modification of a hostile process on a
compromised machine, reverse engineering, or as a "pokefinder" to
cheat at video games.


| ''Wireless''
* https://pagure.io/security-lab/blob/master/f/fedora-livecd-security.ks
|-
|[http://www.aircrack-ng.org aircrack-ng] || aircrack is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured.
|-
|[http://airsnort.shmoo.com/ airsnort]  || Wireless LAN (WLAN) tool which recovers encryption keys
|-
|[http://www.kismetwireless.net kismet] || WLAN detector, sniffer and IDS
|- ||style="color: black; background-color: #eeeff1"
| ''Code Analysis''
|-
|[http://www.striker.ottawa.on.ca/~aland/pscan pscan]  || Limited problem scanner for C source files
|-
|[http://www.splint.org/ splint]  || A tool for statically checking C programs for coding errors and security vulnerabilities
|-
| [http://www.dwheeler.com/flawfinder flawfinder]  || Examines C/C++ source code for security flaws
|- ||style="color: black; background-color: #eeeff1"
| ''Intrusion Detection''
|-
|[http://sourceforge.net/projects/aide aide] || Intrusion detection environment
|-
|[http://www.prelude-ids.org prewikka] || Graphical front-end analysis console for the Prelude Hybrid IDS Framework
|-
|[http://www.prelude-ids.org prelude-manager] || Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is a multithreaded server which handles connections from the Prelude sensors. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis. It also provides relaying capabilities for failover and replication. The IDMEF standard is used for alert representation. Support for filtering plugins allows you to hook in different places in the Manager to define custom criteria for alert relaying and logging.


|-
== ISO Name / FS Label ==
|[http://www.www.prelude-ids.com prelude-notify] ||  Prelude-notify is a desktop oriented application that works as a monitoring tool that capture events from prelude manager using the prelude connection pool event checker. Its purpose is to help security managers and/or administrators to see in real time what's going on in their network.
* ISO name: Fedora-$release-$arch-LiveSecurity
* FS-Label: Fedora-$release-$arch-Security


|-
== Dependencies ==
|[http://www.snort.org snort]  || Intrusion detection system
* security-menus
|-
** <s>https://bugzilla.redhat.com/show_bug.cgi?id=548824#c17</s> DONE
|[http://www.tripwire.org/ tripwire] || IDS (Intrusion Detection System)
|-
|[http://sourceforge.net/projects/labrea/ labrea] || Intrusion detection "sticky" honey pot technology using virtual
servers to detect and trap worms, hackers, and other malware.
|- [http://passive.sourceforge.net/ pads] || PADS is a libpcap based detection engine used to passively detect network assets.  It is designed to complement IDS technology by providing context to IDS alerts. When new assets are found, it can send IDMEF alerts via prelude.
|- [http://www.honeyd.org/ honeyd] || Honeyd is a small daemon that creates virtual hosts on a network.  The hosts can be configured to run arbitrary services, and their TCP personality can be adapted so that they appear to be running certain versions of operating systems. Honeyd enables a single host to claim multiple addresses on a LAN for network simulation.


|- ||style="color: black; background-color: #eeeff1"
== Testing / QA ==
| ''Password Tools''
* Run [[JeremyKatz/SpinChecklist#Testing_of_the_Spin| basic spin testing]]
|-
* Test installs from live media, test livemedia-creator
|[http://www.openwall.com/john john] || John the Ripper password cracker
* Persistence of Security Menu after installations
|- ||style="color: black; background-color: #eeeff1"
* How do the available applications work?
| ''Anonymity''
* [https://fedoraproject.org/wiki/Category:Security_Lab Current security lab applications test cases]
|-
* As of Fedora 16, Security Lab release validation test events are available.
| [http://tor.eff.org tor] || Anonymizing overlay network for TCP (The onion router)
|}


=== Wishlist ===
Please track your checks on the relevant release in the [https://fedoraproject.org/wiki/Category:Security_Lab_Testing Security Lab Testing category]
Note: the software listed below has not yet been verified to make sure the licenses meet our [[Packaging/Guidelines|  Guidelines]] .  Please see the [[Extras/NewPackageProcess|  NewPackageProcess]]  to help get these packages into Fedora.
{| border="1"
|- style="color: white; background-color: #3074c2; font-weight: bold"
| '''Software''' || '''Description''' || '''Notes'''
|-
| [http://airsnarf.shmoo.com/ airsnarf]  || A rogue AP setup utility ||
|-
| [http://www.rfxnetworks.com/apf.php apf]  || PF is a policy based iptables firewall system designed for ease of use and configuration ||Packager unfriendly. Upstream contacted with no response
|-
| [http://www.sleuthkit.org/autopsy/ autopsy]  || The Autopsy Forensic Browser is a graphical interface to the command line digital investigation tools in The Sleuth Kit. || huzaifas will do it ||
|-
| [http://farm9.org/Cryptcat/ cryptcat]  || Cryptcat is the standard netcat enhanced with twofish encryption. ||
|-
| [http://www.thc.org/thc-hydra/ hydra]  ||  A very fast network logon cracker which support many different services || Under [https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=461385 review (#Bug 461385)]
|-
| [http://sourceforge.net/projects/iisemul8/ iisemulator]  || The goal of this project is to create a functioning web server which is indistinguishable from Microsoft's IIS product at a topical level. ||
|-
| [http://www.metasploit.com/ metasploit]  || The Metasploit Framework is an advanced open-source platform for developing, testing, and using exploit code. ||
|-
| [http://www.sleuthkit.org/sleuthkit/index.php sleuthkit]  || The Sleuth Kit (TSK) is a collection of UNIX-based command line tools that allow you to investigate a computer. || In the repository
|-
| [http://directory.fsf.org/security/misc/TCT.html tct]  || Tools for analyzing a system after a break-in || Deprecated (See TSK above)
|-
| [http://www.securesoftware.com/download_rats.htm rats]  || Rough Auditing Tool for Security || In the repo now
|-
| [http://www.academicunderground.org/examiner/ examiner]  || The Examiner is an application that utilizes the objdump command to disassemble and comment foreign executable binaries ||
|-
| [http://sourceforge.net/projects/cowpatty/ cowpatty]  || Audit Wpa pre-shared keys || Under [https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=231011 review (#Bug 231011)]
|-
| [http://directory.fsf.org/sdd.html sdd]  || 'sdd' is a replacement for a program called 'dd'. sdd is much faster than dd in cases where input block size (ibs) is not equal to the output block size (obs). Statistics are more easily understoon than those from 'dd'. Timing available, -time option will print transfer speed Timing & Statistics available at any time with SIGQUIT (^\) Can seek on input and output Fast null input Fast null output. Support for the RMT (Remote Tape Server) protocol makes remote I/O fast and easy.  ||
|-
| [http://www.truecrypt.org/downloads.php TrueCrypt] || Free open-source disk encryption software for Windows Vista/XP/2000 and Linux || Questionable license?
|-
| [http://www.honeyd.org honeyd]  || Honeyd is a small daemon that creates virtual hosts on a network. The hosts can be configured to run arbitrary services, and their personality can be adapted so that they appear to be running certain operating systems. ||
|-
| [http://arpon.sourceforge.net arpon] || ArpON (Arp handler inspectiON) is a portable handler daemon with some nice tools to handle all ARP aspects. ||
|-
| [http://sourceforge.net/projects/labrea labrea] || Intrusion detection "sticky" honey pot technology using virtual servers to detect and trap worms, hackers, and other malware. || rpm is build, will be in the repo soon ||
|-
| [http://www.openvas.org OpenVAS] || The Open Vulnerability Assessment System is a network security scanner with associated tools like a graphical user front-end. The core component is a server with a set of network vulnerability tests (NVTs) to detect security problems in remote systems and applications. || huzaifas will do it ||
|}


== References ==
== Spins Page ==


* http://lwn.net/Articles/225215/. Maybe provide this extension by default?
Spins Page is set up https://labs.fedoraproject.org/security/
* http://knoppix-std.org/tools.html


[[Category:Spins_Fedora_33]]
[[Category:Spins_Fedora_32]]
[[Category:Spins_Fedora_31]]
[[Category:Spins_Fedora_30]]
[[Category:Spins_Fedora_29]]
[[Category:Spins_Fedora_28]]
[[Category:Spins_Fedora_27]]
[[Category:Spins_Fedora_26]]
[[Category:Spins_Fedora_25]]
[[Category:Spins_Fedora_24]]
[[Category:Spins_Fedora_23]]
[[Category:Spins_Fedora_22]]
[[Category:Spins_Fedora_21]]
[[Category:Spins_Fedora_20]]
[[Category:Spins_Fedora_19]]
[[Category:Spins_Fedora_18]]
[[Category:Spins_Fedora_17]]
[[Category:Spins_Fedora_16]]
[[Category:Spins_Fedora_15]]
[[Category:Spins_Fedora_14]]
[[Category:Spins_Fedora_13]]
[[Category:Security Lab]]
[[Category:Spins]]
[[Category:Spins]]

Latest revision as of 19:53, 26 July 2022

Spins-banner security.png

Fedora Security Spin

Note.png
Wiki Page Purpose
This page follows the Spins_Process. The Development Home can be found at https://pagure.io/security-lab

Summary

The Fedora Security Spin is a live media based on Fedora to provide a safe test environment for working on security auditing, forensics and penetration testing, coupled with all the Fedora Security features and tools.

Owner(s)

Detailed Description

The spin is maintained by a community of Security testers and developers. It comes with the clean and fast Xfce Desktop Environment and a customized menu to have all the instruments one may need to follow a proper test path on security testing or to rescue a broken system. With the read-write rootfs, it is possible to install software while the live media is running. The Fedora livemedia-creator provides an overlay feature to put the Fedora Security Lab on an USB stick so that the user can install and update software and can save his test results permanently.

Benefit to Fedora

  • Covered by the above description
  • A stable platform for teaching security along security classes in universities and organisations
    • People learn about Fedora through these classes
  • Showcase for security features and testing
  • A tool set for proper security testing
  • A complete repair/rescue system - with tools not contained on the other Live media to rescue your system
  • Gather interested people to package new tools for this spin
  • Cool marketing instrument and a story to tell
  • There are industry partners who are interested to contribute

Kickstart File

ISO Name / FS Label

  • ISO name: Fedora-$release-$arch-LiveSecurity
  • FS-Label: Fedora-$release-$arch-Security

Dependencies

Testing / QA

Please track your checks on the relevant release in the Security Lab Testing category

Spins Page

Spins Page is set up https://labs.fedoraproject.org/security/