<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.howtoforge.net" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
 <title>HowtoForge - Linux Howtos and Tutorials - Security</title>
 <link>http://www.howtoforge.net/taxonomy/term/9/0</link>
 <description></description>
 <language>en</language>
 <atom:link href="http://www.howtoforge.net/taxonomy/term/9/0/feed" rel="self" type="application/rss+xml" />
 <image>
  <title>HowtoForge - Linux Howtos and Tutorials - Security</title>
  <url>http://www.howtoforge.com/themes/htf_glass/images/howtoforge_logo_glass_blue.gif</url>
  <link>http://www.howtoforge.net/taxonomy/term/9/0</link>
 </image>

<item>
 <title>Samba + Clamd + Samba-Vscan On CentOS 5.2</title>
 <link>http://www.howtoforge.net/samba-clamd-samba-vscan-on-centos-5.2</link>
 <description>&lt;table align=&quot;left&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; width=&quot;45&quot; height=&quot;40&quot; style=&quot;margin-top:0px;margin-bottom:0px;&quot;&gt;&lt;tr&gt;&lt;td&gt;&lt;img class=&quot;teaser-image-odd&quot; src=&quot;http://images.howtoforge.com/images/teaser/centos.gif&quot; width=&quot;42&quot; height=&quot;40&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;p&gt;&lt;b&gt;Samba + Clamd + Samba-Vscan On CentOS 5.2&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;This is a howto on getting samba + clamav + samba-vscan to work on a CentOS 5.2 system.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/centos">CentOS</category>
 <category domain="http://www.howtoforge.net/sitemap/samba">Samba</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Fri, 28 Nov 2008 17:01:49 +0100</pubDate>
 <guid>http://www.howtoforge.net/samba-clamd-samba-vscan-on-centos-5.2</guid>
 <comments>http://www.howtoforge.net/samba-clamd-samba-vscan-on-centos-5.2#comment</comments>
</item>
<item>
 <title>Setting Up ProFTPd + TLS On Ubuntu 8.10 (Intrepid Ibex)</title>
 <link>http://www.howtoforge.net/setting-up-proftpd-tls-on-ubuntu-8.10</link>
 <description>&lt;table align=&quot;left&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; width=&quot;96&quot; height=&quot;40&quot; style=&quot;margin-top:0px;margin-bottom:0px;&quot;&gt;&lt;tr&gt;&lt;td&gt;&lt;img class=&quot;teaser-image-even&quot; src=&quot;http://images.howtoforge.com/images/teaser/proftpd.gif&quot; width=&quot;93&quot; height=&quot;40&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;b&gt;Setting Up ProFTPd + TLS On Ubuntu 8.10 (Intrepid Ibex)&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;FTP is a very insecure protocol because all passwords and all data
are transferred in clear text. By using TLS, the whole communication
can be encrypted, thus making FTP much more secure. This article
explains how to set up ProFTPd with TLS on an Ubuntu 8.10 server.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/ubuntu">Ubuntu</category>
 <category domain="http://www.howtoforge.net/sitemap/ftp">FTP</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Sun, 16 Nov 2008 19:23:24 +0100</pubDate>
 <guid>http://www.howtoforge.net/setting-up-proftpd-tls-on-ubuntu-8.10</guid>
 <comments>http://www.howtoforge.net/setting-up-proftpd-tls-on-ubuntu-8.10#comment</comments>
</item>
<item>
 <title>Installing ISP-fw (Firewall) On Linux</title>
 <link>http://www.howtoforge.net/installing-isp-fw-firewall-on-linux</link>
 <description>&lt;table align=&quot;left&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; width=&quot;36&quot; height=&quot;40&quot; style=&quot;margin-top:0px;margin-bottom:0px;&quot;&gt;&lt;tr&gt;&lt;td&gt;&lt;img class=&quot;teaser-image-odd&quot; src=&quot;http://images.howtoforge.com/images/teaser/debian.gif&quot; width=&quot;33&quot; height=&quot;40&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;p&gt;&lt;b&gt;Installing ISP-fw (Firewall) On Linux&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;ISP-fW
is a firewall script that provides port forwarding, packet filtering,
stateful packet inspection, port redirection, masquerading, SNAT/ DNAT,
TOS, and never the last it generates htb rules for bandwidth
management. With ISP-fw, you can turn a PC into a gateway with shaping
capabilities.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/debian">Debian</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Tue, 28 Oct 2008 12:05:48 +0100</pubDate>
 <guid>http://www.howtoforge.net/installing-isp-fw-firewall-on-linux</guid>
 <comments>http://www.howtoforge.net/installing-isp-fw-firewall-on-linux#comment</comments>
</item>
<item>
 <title>Preventing MySQL Injection Attacks With GreenSQL On Debian Etch</title>
 <link>http://www.howtoforge.net/preventing-mysql-injection-attacks-with-greensql-on-debian-etch</link>
 <description>&lt;table align=&quot;left&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; width=&quot;128&quot; height=&quot;40&quot; style=&quot;margin-top:0px;margin-bottom:0px;&quot;&gt;&lt;tr&gt;&lt;td&gt;&lt;img class=&quot;teaser-image-even&quot; src=&quot;http://images.howtoforge.com/images/teaser/mysql.gif&quot; width=&quot;125&quot; height=&quot;40&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;p&gt;&lt;b&gt;Preventing MySQL Injection Attacks With GreenSQL On Debian Etch&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;GreenSQL (or &lt;span class=&quot;system&quot;&gt;greensql-fw&lt;/span&gt;)
is a firewall for MySQL databases that filters SQL injection attacks.
It works as a reverse proxy, i.e., it takes the SQL queries, checks
them, passes them on to the MySQL database and delivers back the result
from the MySQL database. It comes with a web interface (called &lt;span class=&quot;system&quot;&gt;greensql-console&lt;/span&gt;)
so that you can manage GreenSQL through a web browser. This guide shows
how you can install GreenSQL and its web interface on a Debian Etch
server.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/debian">Debian</category>
 <category domain="http://www.howtoforge.net/sitemap/mysql">MySQL</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Sun, 26 Oct 2008 19:10:16 +0100</pubDate>
 <guid>http://www.howtoforge.net/preventing-mysql-injection-attacks-with-greensql-on-debian-etch</guid>
 <comments>http://www.howtoforge.net/preventing-mysql-injection-attacks-with-greensql-on-debian-etch#comment</comments>
</item>
<item>
 <title>Ultimate Security Proxy With Tor</title>
 <link>http://www.howtoforge.net/ultimate-security-proxy-with-tor</link>
 <description>&lt;table align=&quot;left&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; width=&quot;39&quot; height=&quot;40&quot; style=&quot;margin-top:0px;margin-bottom:0px;&quot;&gt;&lt;tr&gt;&lt;td&gt;&lt;img class=&quot;teaser-image-odd&quot; src=&quot;http://images.howtoforge.com/images/teaser/tux.gif&quot; width=&quot;36&quot; height=&quot;40&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&lt;b&gt;Ultimate Security Proxy With Tor&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;Nowadays, within the growing web 2.0 environment you may want to
have some anonymity, and use other IP addresses than your own IP.
Or, for some special purposes - a few IPs or more, frequently changed.
So no one will be able to track you. A solution exists, and it is
called Tor Project,
or simply tor. There are a lot of articles and howtos giving you the
idea of how it works, I&#039;m not going to describe here onion routing and
its principles, I&#039;ll rather tell you how practically pull out the
maximum out of it.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Fri, 24 Oct 2008 13:21:30 +0200</pubDate>
 <guid>http://www.howtoforge.net/ultimate-security-proxy-with-tor</guid>
 <comments>http://www.howtoforge.net/ultimate-security-proxy-with-tor#comment</comments>
</item>
<item>
 <title>Firewall Management With Gufw On Ubuntu 8.04</title>
 <link>http://www.howtoforge.net/firewall-management-with-gufw-on-ubuntu-8.04</link>
 <description>&lt;p&gt;&lt;b&gt;Firewall Management With Gufw On Ubuntu 8.04&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;Gufw is a graphical frontend for managing an iptables firewall on an Ubuntu 8.04 desktop. It is based on ufw
and enables you to allow or block pre-configured, common p2p, or
individual ports. This guide shows how you can install and use Gufw on
Ubuntu 8.04.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/ubuntu">Ubuntu</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Thu, 23 Oct 2008 19:20:25 +0200</pubDate>
 <guid>http://www.howtoforge.net/firewall-management-with-gufw-on-ubuntu-8.04</guid>
 <comments>http://www.howtoforge.net/firewall-management-with-gufw-on-ubuntu-8.04#comment</comments>
</item>
<item>
 <title>Secure SSH Using WiKID Two-Factor Authentication And TACACS+</title>
 <link>http://www.howtoforge.net/secure-ssh-using-wikid-two-factor-authentication-and-tacacs-plus</link>
 <description>&lt;p&gt;&lt;b&gt;Secure SSH Using WiKID Two-Factor Authentication And TACACS+&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;These instructions are designed to help you configure and test using
the WiKID TACACS+ protocol module via Linux PAM on Red Hat. This
document has been updated to cover pam .99 and higher. We assume that
you have already installed the open-source WiKID Strong Authentication Server Community Edition.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux">Linux</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Thu, 16 Oct 2008 13:26:26 +0200</pubDate>
 <guid>http://www.howtoforge.net/secure-ssh-using-wikid-two-factor-authentication-and-tacacs-plus</guid>
 <comments>http://www.howtoforge.net/secure-ssh-using-wikid-two-factor-authentication-and-tacacs-plus#comment</comments>
</item>
<item>
 <title>How To Enforce  Google SafeSearch With SafeSquid Proxy Server</title>
 <link>http://www.howtoforge.net/how-to-enforce-google-safesearch-with-safesquid-proxy-server</link>
 <description>
&lt;p&gt;&lt;b&gt;How To Enforce&amp;nbsp; Google SafeSearch With SafeSquid Proxy Server&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Google offers users with an option to filter out results that contain
explicit sexual content, called &lt;span class=&quot;system&quot;&gt;SafeSearch&lt;/span&gt;. It also displays a warning message with search results identified as sites
that may install malicious software on your computer. You can enforce Google SafeSearch with SafeSquid Proxy,
so that it overrides the user preferences, and displays only &lt;span class=&quot;system&quot;&gt;SafeSearch&lt;/span&gt;
results.&lt;/p&gt;</description>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Mon, 15 Sep 2008 19:56:24 +0200</pubDate>
 <guid>http://www.howtoforge.net/how-to-enforce-google-safesearch-with-safesquid-proxy-server</guid>
 <comments>http://www.howtoforge.net/how-to-enforce-google-safesearch-with-safesquid-proxy-server#comment</comments>
</item>
<item>
 <title>Spam Blocking And Web Filtering With The Untangle 5.3 Network Gateway</title>
 <link>http://www.howtoforge.net/spam-blocking-and-web-filtering-with-the-untangle-5.3-network-gateway</link>
 <description>&lt;p&gt;&lt;b&gt;Spam Blocking And Web Filtering With The Untangle 5.3 Network Gateway&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;Untangle
bundles common open-source applications for blocking spam, spyware,
viruses, adware and unwanted content on the network in one single Linux
distribution. It can be integrated into existing networks either as a
router or as a transparent bridge (directly behind the router, but
before the switch that connects the client PCs with the router). The
best thing about Untangle is that you don&#039;t have to reconfigure the
client PCs - Untangle works out of the box.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux">Linux</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Tue, 02 Sep 2008 17:19:07 +0200</pubDate>
 <guid>http://www.howtoforge.net/spam-blocking-and-web-filtering-with-the-untangle-5.3-network-gateway</guid>
 <comments>http://www.howtoforge.net/spam-blocking-and-web-filtering-with-the-untangle-5.3-network-gateway#comment</comments>
</item>
<item>
 <title>Preventing Brute Force Attacks With Fail2ban On Mandriva 2008.1</title>
 <link>http://www.howtoforge.net/preventing-brute-force-attacks-with-fail2ban-on-mandriva2008.1</link>
 <description>
&lt;p&gt;&lt;b&gt;Preventing Brute Force Attacks With Fail2ban On Mandriva 2008.1&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;In this article I will show how to install and configure fail2ban
on a Mandriva 2008.1 system. Fail2ban is a tool that observes login
attempts to various services, e.g. SSH, FTP, SMTP, Apache, etc., and if
it finds failed login attempts again and again from the same IP address
or host, fail2ban stops further login attempts from that IP
address/host by blocking it with an iptables firewall rule.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/mandriva">Mandriva</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Fri, 29 Aug 2008 15:34:25 +0200</pubDate>
 <guid>http://www.howtoforge.net/preventing-brute-force-attacks-with-fail2ban-on-mandriva2008.1</guid>
 <comments>http://www.howtoforge.net/preventing-brute-force-attacks-with-fail2ban-on-mandriva2008.1#comment</comments>
</item>
<item>
 <title>Preventing Brute Force Attacks With Fail2ban On Fedora 9</title>
 <link>http://www.howtoforge.net/preventing-brute-force-attacks-with-fail2ban-on-fedora9</link>
 <description>
&lt;p&gt;&lt;b&gt;Preventing Brute Force Attacks With Fail2ban On Fedora 9&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;In this article I will show how to install and configure fail2ban
on a Fedora 9 system. Fail2ban is a tool that observes login attempts
to various services, e.g. SSH, FTP, SMTP, Apache, etc., and if it finds
failed login attempts again and again from the same IP address or host,
fail2ban stops further login attempts from that IP address/host by
blocking it with an iptables firewall rule.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/fedora">Fedora</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Mon, 25 Aug 2008 17:54:51 +0200</pubDate>
 <guid>http://www.howtoforge.net/preventing-brute-force-attacks-with-fail2ban-on-fedora9</guid>
 <comments>http://www.howtoforge.net/preventing-brute-force-attacks-with-fail2ban-on-fedora9#comment</comments>
</item>
<item>
 <title>Running Vhosts Under Separate UIDs/GIDs With Apache2 mpm-peruser On Debian Etch</title>
 <link>http://www.howtoforge.net/running-vhosts-under-separate-uids-gids-with-apache2-mpm-peruser-on-debian-etch</link>
 <description>&lt;p&gt;&lt;b&gt;Running Vhosts Under Separate UIDs/GIDs With Apache2 mpm-peruser On Debian Etch&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;This article explains how you can install and configure apache2-mpm-peruser on a Debian Etch server. apache2-mpm-peruser is an MPM (Multi-Processing Module) for the Apache 2 web server, very similar to apache2-mpm-itk,
but faster (almost as fast as apache2-mpm-prefork). mpm-peruser allows
you to run each of your vhosts under a separate UID and GID - in short,
the scripts and configuration files for one vhost no longer have to be
readable for all the other vhosts. It is based on metuxmpm, a working
implementation of the perchild MPM. The result is a sane and secure web
server environment for your users, without kludges like PHP&#039;s safe_mode.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/debian">Debian</category>
 <category domain="http://www.howtoforge.net/sitemap/apache">Apache</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Thu, 21 Aug 2008 18:38:18 +0200</pubDate>
 <guid>http://www.howtoforge.net/running-vhosts-under-separate-uids-gids-with-apache2-mpm-peruser-on-debian-etch</guid>
 <comments>http://www.howtoforge.net/running-vhosts-under-separate-uids-gids-with-apache2-mpm-peruser-on-debian-etch#comment</comments>
</item>
<item>
 <title>How To Block Porn Pictures And Images With SafeSquid Proxy Server</title>
 <link>http://www.howtoforge.net/how-to-block-porn-pictures-and-images-with-safesquid-proxy-server</link>
 <description>&lt;p&gt;&lt;b&gt;How To Block Porn Pictures And Images With SafeSquid Proxy Server&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;Administrators can use various methods to block access to websites
that are pornographic in nature, like URL Filter, URL Blacklist,
Keyword Filter, etc. But many porn sites
allow users to register their email IDs on their website and deliver
the latest images and pictures to their personal emails. So if a user
is allowed access to his personal mail,
he can enjoy himself without having to access any porn site. Such
images are also regularly displayed as ads and banners on other web
pages, that might not be pornographic in
nature. Pornographic Image Filter can analyze an image in real-time, and
identify the ones that are pornographic in nature. It analyzes the
graphical content like skin tone, contour,
etc. to identify a pornographic image. It is a commercially distributed
add-on plug-in and can be used with SafeSquid to block pornographic
images. Although it is about 85%-90%
accurate, it acts as a good deterrent.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <category domain="http://www.howtoforge.net/sitemap/commercial">Commercial</category>
 <pubDate>Tue, 19 Aug 2008 14:40:33 +0200</pubDate>
 <guid>http://www.howtoforge.net/how-to-block-porn-pictures-and-images-with-safesquid-proxy-server</guid>
 <comments>http://www.howtoforge.net/how-to-block-porn-pictures-and-images-with-safesquid-proxy-server#comment</comments>
</item>
<item>
 <title>How To Control Or Block Instant Messengers With SafeSquid Proxy Server</title>
 <link>http://www.howtoforge.net/how-to-control-or-block-instant-messengers-with-safesquid-proxy-server</link>
 <description>&lt;p&gt;&lt;b&gt;How To Control Or Block Instant Messengers With SafeSquid Proxy Server&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;In this tutorial I will explain how you can control or completely
block access to a few instant messengers with SafeSquid, like Google
Talk, Google chat within Gmail, MSN
Messenger, Yahoo Messenger and Skype. Once you are familiar with the
method of blocking these messengers, you should be able to block other
messengers. Please note that these
methods will only be effective, if you block all direct access to the
router and firewall, except required ports like 25 &amp;amp; 110, so that
users are able to access the net only
through the proxy server. When all higher ports are blocked, most
messenger try to communicate on port 80 and 443, which will have to go
through the proxy, and thus allow you to
control them. Most messengers also allow you to define proxy settings
and username / password for authenticating Proxies.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Tue, 29 Jul 2008 15:11:53 +0200</pubDate>
 <guid>http://www.howtoforge.net/how-to-control-or-block-instant-messengers-with-safesquid-proxy-server</guid>
 <comments>http://www.howtoforge.net/how-to-control-or-block-instant-messengers-with-safesquid-proxy-server#comment</comments>
</item>
<item>
 <title>How To Patch BIND9 Against DNS Cache Poisoning On Debian Etch</title>
 <link>http://www.howtoforge.net/how-to-patch-bind-to-avoid-cache-poisoning-debian-etch</link>
 <description>&lt;p&gt;&lt;b&gt;How To Patch BIND9 Against DNS Cache Poisoning On Debian Etch&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;This article explains how you can fix a BIND9 nameserver on a Debian Etch system so that it is not vulnerable anymore to DNS cache poisoning.&lt;/p&gt;
</description>
 <category domain="http://www.howtoforge.net/sitemap/linux/debian">Debian</category>
 <category domain="http://www.howtoforge.net/sitemap/dns">DNS</category>
 <category domain="http://www.howtoforge.net/sitemap/security">Security</category>
 <pubDate>Mon, 28 Jul 2008 16:17:45 +0200</pubDate>
 <guid>http://www.howtoforge.net/how-to-patch-bind-to-avoid-cache-poisoning-debian-etch</guid>
 <comments>http://www.howtoforge.net/how-to-patch-bind-to-avoid-cache-poisoning-debian-etch#comment</comments>
</item>
</channel>
</rss>
