Re: Pointers solicited

From: abc (abc_at_123.com)
Date: 07/20/04


Date: Tue, 20 Jul 2004 04:55:04 -0400

Dorsai wrote:

> I'm (obviously) new to the computer security deal, and was hoping someone
> would be kind enough to point me toward some decent reference materials on
> day-to-day computer security operations. I'm looking for things like:
>
> * At what point does port scanning become 'hostile'?
> * Is there any _legitimate_ reason to try and get a list of cgi scripts?
> * What is a good 'tolerance level' for security (ie, one scan free, then
> complain? Zero tolerance? Other?)
> * Any automated tools (Linux/Windows) to go with the above?
>
> Any help would be appreciated; I want to try and get this right without
> bashing my head against the wall (can't stand the soft, squishy sound it
> makes)...
>

You can order some free training materials from DISA here:

http://iase.disa.mil/ars/cgi-bin/arweb?Form=useschema&s=mattche&S=ETA:Product-Rqst&Act=Submit

Check out some NIST publications:

http://csrc.nist.gov/

SecurityFocus has lots of information:

http://www.securityfocus.com/

Or these guys:

http://www.cymru.com/


Quantcast