trust is easily compromised
Showing 101 - 125 of 2,080 RSS Feed

Files

OpenNHRP NBMA Next Hop Resolution 0.11.5
Posted Mar 20, 2010
Authored by Timo Teras | Site sourceforge.net

OpenNHRP implements the NBMA Next Hop Resolution Protocol (as defined in RFC 2332). It makes it possible to create a dynamic multipoint VPN Linux router using NHRP, GRE, and IPsec. It aims to be Cisco DMVPN compatible.

Changes: Shortcut renewals were fixed. Negative cached entries of a peer are now cleared when it sends a resolution request (which proves it\'s alive again), improving convergence time. The libev version was updated, and some related fixes were made.
tags | encryption, protocol
systems | cisco, linux
MD5 | 0982ce7c39bd760f0b58161f0883d4ec
GNU Privacy Guard 2.0.15
Posted Mar 10, 2010
Site gnupg.org

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

Changes: A regression in 2.0.14 which prevented unprotection of new or changed gpg-agent passphrases was fixed. A new command "--passwd" was added. libassuan 2.0 is now used.
tags | encryption
MD5 | c1286e85b66349879dc4b760dd83e2f1
OpenSSH 5.4p1
Posted Mar 8, 2010
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: This is a major feature and bugfix release. Major changes include disabling SSH protocol 1 by default, removal of legacy OpenSC/libsectok smartcard support, addition of PKCS#11 support, introduction of a new certificate authentication method for users and hosts, revised session multiplexing code, many improvements to sftp from the Google Summer of Code 2009, and lots of bugfixes.
tags | encryption
systems | linux, openbsd
MD5 | da10af8a789fa2e83e3635f3a1b76f5e
OpenNHRP NBMA Next Hop Resolution 0.11.3
Posted Mar 5, 2010
Authored by Timo Teras | Site sourceforge.net

OpenNHRP implements the NBMA Next Hop Resolution Protocol (as defined in RFC 2332). It makes it possible to create a dynamic multipoint VPN Linux router using NHRP, GRE, and IPsec. It aims to be Cisco DMVPN compatible.

Changes: A check that prevented the forwarding of multicast packets in some cases was removed. Netlink buffer sizes were increased.
tags | encryption, protocol
systems | cisco, linux
MD5 | 6f6f8571ccc0a9f97e52c6240fe9002a
Harden SSL/TLS Tool
Posted Feb 18, 2010
Authored by Thierry Zoller | Site g-sec.lu

"Harden SSL/TLS" hardens the default SSL/TLS settings of Windows 2000,2003,2008,2008R2, XP,Vista,7. It allows you to remotely set SSL/TLS policies allowing or denying certain ciphers/hashes or complete ciphersuites.

tags | encryption
systems | windows, 2k
MD5 | 5db5730516652db7e4920cf04249469b
libssh2 C Library 1.2.4
Posted Feb 15, 2010
Site libssh2.org

libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS, SECSH-USERAUTH, SECSH-CONNECTION, SECSH-ARCH, SECSH-FILEXFER, SECSH-DHGEX, SECSH-NUMBERS, and SECSH-PUBLICKEY.

Changes: Several different build problems were fixed.
tags | encryption, protocol
MD5 | 4d65a66d5f232e5bb1d05b311e43d46d
strongSwan IPsec / IKEv1 / IKEv2 Implementation For Linux 4.3.6
Posted Feb 12, 2010
Authored by Andreas Steffen | Site strongswan.org

strongSwan is a complete IPsec and IKEv1 implementation for Linux 2.4 and 2.6 kernels. It interoperates with most other IPsec-based VPN products. It is a descendant of the discontinued FreeS/WAN project. The focus of the strongSwan project is on strong authentication mechanisms using X.509 public key certificates and optional secure storage of private keys on smartcards through a standardized PKCS#11 interface. A unique feature is the use of X.509 attribute certificates to implement advanced access control schemes based on group memberships.

Changes: Starting with the Linux 2.6.33 kernel, the SHA-256/384/512 HMAC ESP data integrity algorithms are now configured by strongSwan with the correct truncation length. Older kernels require a SHA-2 patch. The IKEv2 charon daemon has been ported to the Android platform. DNS and NBNS server information stored in an SQL database can be distributed to VPN clients via the IKEv1 Mode Config or the IKEv2 Configuration payload.
tags | kernel, encryption
systems | linux
MD5 | 54c24f1390b37cc2474b4eb45cd9810f
SSL Audit Tool
Posted Feb 10, 2010
Authored by Thierry Zoller | Site g-sec.lu

Developed as part of G-SEC's investigation for the "Secure SSL/TLS configuration Report 2010", they developed this little tool called SSL Audit. SSL Audit scans web servers for SSL support, unlike other tools it is not limited to ciphers supported by SSL engines such as OpenSSL or NSS and can detect all known cipher suites. It also has a fingerprinting mode.

tags | web, encryption
MD5 | 862a18ea08deccd5a2a9c9e7db074ebf
libssh2 C Library 1.2.3
Posted Feb 4, 2010
Site libssh2.org

libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS, SECSH-USERAUTH, SECSH-CONNECTION, SECSH-ARCH, SECSH-FILEXFER, SECSH-DHGEX, SECSH-NUMBERS, and SECSH-PUBLICKEY.

Changes: This release adds ssh-agent support, libssh2_trace_sethandler(), and two new examples. It fixes 8 bugs, including two memory leaks.
tags | encryption, protocol
MD5 | 24144c99908f377c2c4a9b3942102f0b
Stunnel SSL Wrapper 4.31
Posted Feb 4, 2010
Authored by Michal Trojnara | Site stunnel.org

Stunnel is a program that allows you to encrypt arbitrary TCP connections inside SSL (Secure Sockets Layer) available on both Unix and Windows. Stunnel can allow you to secure non-SSL aware daemons and protocols (like POP, IMAP, NNTP, LDAP, etc) by having Stunnel provide the encryption, requiring no changes to the daemon's code.

Changes: Log file reloading with SIGUSR1 was added. Some regression issues introduced in the experimental version 4.30 were fixed.
tags | arbitrary, encryption, tcp, imap, protocol
systems | windows, unix
MD5 | 2fc31bc0c940fbe545a88d896b13cacf
Tinc VPN Daemon 1.0.12
Posted Feb 4, 2010
Authored by Ivo Timmermans | Site tinc.nl.linux.org

tinc is a Virtual Private Network (VPN) daemon that uses tunneling and encryption to create a secure private network between multiple hosts on the Internet. This tunneling allows VPN sites to share information with each other over the Internet without exposing any information.

Changes: This release really allows fast roaming of hosts to other nodes in a switched VPN, fixes potentially missing or incorrect environment variables when calling host-up/down and subnet-up/down scripts, allows the port to be specified in Address statements, clamps MSS of TCP packets to the discovered path MTU, and lets two nodes behind NAT learn each other\'s current UDP address and port via a third node, potentially allowing direct communications in a similar way to STUN.
tags | encryption
MD5 | 51dc4a2e5bcbc0ff7dd1a420635c614e
stunnel-4.30.tar.gz
Posted Feb 4, 2010
Authored by Michal Trojnara | Site stunnel.org

Stunnel is a program that allows you to encrypt arbitrary TCP connections inside SSL (Secure Sockets Layer) available on both Unix and Windows. Stunnel can allow you to secure non-SSL aware daemons and protocols (like POP, IMAP, NNTP, LDAP, etc) by having Stunnel provide the encryption, requiring no changes to the daemon's code.

Changes: Configuration can be gracefully reloaded with a HUP signal on Unix and with the GUI on Windows.
tags | arbitrary, encryption, tcp, imap, protocol
systems | windows, unix
MD5 | ff7afeb73dbb179b28b2afb346652142
GNU Privacy Guard 2.0.14
Posted Dec 22, 2009
Site gnupg.org

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

Changes: The default for "--include-cert" is now to include all certificates in the chain except for the root certificate. Numerical values may now be used as an alternative to the debug-level keywords. The GPGSM "--audit-log" feature is now more complete. A new GPGSM option "--ignore-cert-extension" was added. New and changed passphrases are now created with an iteration count requiring about 100ms of CPU work.
tags | encryption
MD5 | 54732a0a76d59646b7e0b682fb357c22
SShutout Log File Monitor 1.0.6
Posted Dec 7, 2009
Authored by Bil DuPree | Site techfinesse.com

sshutout is a daemon that periodically monitors log files, looking for multiple failed login attempts via the Secure Shell daemon. The daemon is meant to mitigate what are commonly known as "dictionary attacks," i.e. scripted brute force attacks that use lists of user IDs and passwords to effect unauthorized intrusions. The sshutout daemon blunts such attacks by creating firewall rules to block individual offenders from accessing the system. These rules are created when an attack signature is detected, and after a configurable expiry interval has elapsed, the rules are deleted.

Changes: This release fixes improper calls to open(). It increases the size of the line buffer used to read the configuration file. This allows for longer whitelists. It detects "UNKNOWN USER" signatures.
tags | shell, encryption
MD5 | 0d699bef09cf16a9c921181c19028abe
GtkHash Crypto Computer 0.3.0
Posted Nov 23, 2009
Site gtkhash.sourceforge.net

GtkHash is a utility for computing message digests or checksums using the mhash library. Currently supported hash functions include MD5, SHA1, SHA256, SHA512, RIPEMD, HAVAL, TIGER, and WHIRLPOOL.

Changes: An optional Nautilus (GNOME file manager) extension was added.
tags | encryption
MD5 | 657e5278f5f0b83a4954d09353f92294
libssh2 C Library 1.2.2
Posted Nov 18, 2009
Site libssh2.org

libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS, SECSH-USERAUTH, SECSH-CONNECTION, SECSH-ARCH, SECSH-FILEXFER, SECSH-DHGEX, SECSH-NUMBERS, and SECSH-PUBLICKEY.

Changes: This release adds support for the "aes128-ctr", "aes192-ctr", "aes256-ctr", and "arcfour128" ciphers. It fixes a crash when the server sends an invalid SSH_MSG_IGNORE message.
tags | encryption, protocol
MD5 | fa8d9cd425bdd62f57244fc61fb54da7
Stunnel SSL Wrapper 4.28
Posted Nov 17, 2009
Authored by Michal Trojnara | Site stunnel.org

Stunnel is a program that allows you to encrypt arbitrary TCP connections inside SSL (Secure Sockets Layer) available on both Unix and Windows. Stunnel can allow you to secure non-SSL aware daemons and protocols (like POP, IMAP, NNTP, LDAP, etc) by having Stunnel provide the encryption, requiring no changes to the daemon's code.

Changes: A serious bug in asynchronous shutdown code was fixed. Win32 DLLs have been added for OpenSSL 0.9.8l. Transparent proxy support was added for Linux kernels versions 2.6.28 and above.
tags | arbitrary, encryption, tcp, imap, protocol
systems | windows, unix
MD5 | 5bf753a042047f40a938e82ec7ece569
OpenSSL 0.9.8l
Posted Nov 6, 2009
Site openssl.org

OpenSSL is a robust, fully featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols with full-strength cryptography world-wide.

Changes: Fixes to stateless session resumption handling were made. Error return checking was improved for several function calls. Leading 0x80 in OIDs are no longer tolerated. The server certificate chain building code now correctly uses X509_verify_cert(). A potential denial of service attack in dtls1_process_out_of_seq_message() was resolved. Several other bugs were fixed.
tags | encryption, protocol
advisories | CVE-2009-3555
MD5 | 05a0ece1372392a2cf310ebb96333025
strongSwan IPsec / IKEv1 / IKEv2 Implementation For Linux 4.3.5
Posted Nov 3, 2009
Authored by Andreas Steffen | Site strongswan.org

strongSwan is a complete IPsec and IKEv1 implementation for Linux 2.4 and 2.6 kernels. It interoperates with most other IPsec-based VPN products. It is a descendant of the discontinued FreeS/WAN project. The focus of the strongSwan project is on strong authentication mechanisms using X.509 public key certificates and optional secure storage of private keys on smartcards through a standardized PKCS#11 interface. A unique feature is the use of X.509 attribute certificates to implement advanced access control schemes based on group memberships.

Changes: The IKEv1 pluto daemon can attach SQL-based address pools to deal out virtual IP addresses as a Mode Config server in either Pull or Push mode. In addition to time based rekeying, the IKEv2 charon daemon supports IPsec SA lifetimes based on processed volume measured in bytes or number of packets.
tags | kernel, encryption
systems | linux
MD5 | 2d0d2409032116f36a0f11f845d7bd89
Tinc Virtual Private Network Daemon 1.0.11
Posted Nov 3, 2009
Authored by Ivo Timmermans | Site tinc.nl.linux.org

tinc is a Virtual Private Network (VPN) daemon that uses tunneling and encryption to create a secure private network between multiple hosts on the Internet. This tunneling allows VPN sites to share information with each other over the Internet without exposing any information.

Changes: This release fixes a potential crash when the HUP signal is sent, fixes unnecessary broadcasts in switch mode, uses UDP in some cases where 1.0.10 fell back to TCP unnecessarily, and allows fast roaming of hosts between nodes in a switched VPN.
tags | encryption
MD5 | ee0b1a3366c6e379cae34be6fa5dcb15
SSH Keychain Utility 2.7.0
Posted Oct 26, 2009
Authored by Aron Griffis | Site gentoo.org

keychain is a utility that helps manage ssh keys in a convenient and secure manner. It acts as a frontend to ssh-agent, but allows the user to easily have one long running ssh-agent process per system, rather than the norm of one ssh-agent per login session. It also makes it easy for remote cron jobs to securely hook-in to a long running ssh-agent process, allowing your scripts to take advantage of key-based logins.

Changes: The color scheme, output formatting, and the --quiet option were improved. The lockfile() implementation was simplified for smaller code. A new Mac OS X package was added.
tags | remote, encryption
MD5 | c5eecd36130d9e8617a77f96b746982d
tinc Virtual Private Network Daemon 1.0.10
Posted Oct 20, 2009
Authored by Ivo Timmermans | Site tinc.nl.linux.org

tinc is a Virtual Private Network (VPN) daemon that uses tunneling and encryption to create a secure private network between multiple hosts on the Internet. This tunneling allows VPN sites to share information with each other over the Internet without exposing any information.

Changes: This release fixes potential crashes during shutdown and in rare conditions. It improves NAT handling - tinc now copes with mangled port numbers, and will automatically fall back to TCP if direct UDP connection between nodes is not possible. Old RSA keys are disabled when generating new ones, and the default size of new RSA keys has been raised to 2048 bits. There are many fixes in the path MTU discovery code. Tinc can now drop privileges and/or chroot itself. The performance on Windows is improved.
tags | encryption
MD5 | da69d4f4c9a1b1ee44fd14a52a049141
GNU Privacy Guard 2.0.13
Posted Sep 7, 2009
Site gnupg.org

GnuPG (the GNU Privacy Guard or GPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440. As such, it is meant to be compatible with PGP from NAI, Inc. Because it does not use any patented algorithms, it can be used without any restrictions.

Changes: 2048-bit RSA keys are now generated by default. The default hash algorithm preferences have changed to prefer SHA-256 over SHA-1. Writing of keys to v2 OpenPGP cards was enhanced. Several environment variables are now passed to the Pinentry to make SCIM work. A --batch mode was added to the GPGSM command --gen-key command. Several other enhancements and minor bugs were fixed.
tags | encryption
MD5 | 41bd7629d815b90c15b37bb31c2f07c0
GNU Privacy Guard
Posted Sep 3, 2009
Site gnupg.org

The GNU Privacy Guard (GnuPG) is GNU's tool for secure communication and data storage. It is a complete and free replacement of PGP and can be used to encrypt data and to create digital signatures. It includes an advanced key management facility and is compliant with the proposed OpenPGP Internet standard as described in RFC2440.

Changes: 2048 bit RSA keys are now generated by default. The default hash algorithm preferences have changed to prefer SHA-256 over SHA-1. 2048 bit DSA keys are now generated to use a 256 bit hash algorithm. Support for v2 OpenPGP cards was added. Support for the Camellia cipher (RFC-5581) was implemented. Support for HKP keyservers over SSL ("HKPS") was added. The algorithm for computing the SIG_ID status was changed to match the one used in version 2.0.10. File locking was improved. A memory leak which made imports of many keys very slow was fixed. Many smaller bugs were fixed.
tags | encryption
MD5 | 991faf66d3352ac1452acc393c430b23
OpenNHRP NBMA Next Hop Resolution
Posted Sep 2, 2009
Authored by Timo Teras | Site sourceforge.net

OpenNHRP implements the NBMA Next Hop Resolution Protocol (as defined in RFC 2332). It makes it possible to create a dynamic multipoint VPN Linux router using NHRP, GRE, and IPsec. It aims to be Cisco DMVPN compatible.

Changes: A Libev update, fixes for bugs related to local address monitoring, and minor documentation improvements.
tags | encryption, protocol
systems | cisco, linux
MD5 | 9cc1e99de2b132591d685eb5f9d70630
Page 5 of 84
Back34567Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
New SpyEye Plugin Takes Control Of Webcam And Microphone
Posted May 24, 2012

tags | headline, privacy, malware, trojan, botnet
Attack Of The Clones: Researcher Pwns SecureID Token System
Posted May 24, 2012

tags | headline, hacker, flaw, science, rsa
Yahoo! Leaks! Private! Key! In! Axis! Chrome! Debut!
Posted May 24, 2012

tags | headline, flaw, yahoo, cryptography
Comcast Phishing Site Contains Valid TRUSTe Seal
Posted May 24, 2012

tags | headline, cybercrime, flaw, scam, phish
Armenia Jails Bredolab Botmaster For 4 Years
Posted May 24, 2012

tags | headline, government, cybercrime, botnet, fraud
Police Given 350 Mobile Fingerprint Scanners For Olympics
Posted May 24, 2012

tags | headline, government, privacy, britain
Researcher Needles Oracle Over Java Security
Posted May 24, 2012

tags | headline, flaw, oracle, java
35,000 Passwords Reset After BigPond GameArena Hacked
Posted May 24, 2012

tags | headline, hacker, data loss, password
Indian SMBs Facing Advanced Attack Threats
Posted May 23, 2012

tags | headline, hacker, india, denial of service, symantec
Jailed Facebook Hack Brit Targeted Justin Bieber's Girlfriend
Posted May 23, 2012

tags | headline, hacker, britain, facebook, social
View More News →
packet storm

© 2012 Packet Storm. All rights reserved.

close