RVASI – Ethical Hacking Solutions
Search
About US

About Our Resources

The team at RVASI firmly believes that one of the key components needed for designing, building, and maintaining secure systems is the ability to find useful resources quickly.  In order to assist in this area, our team has collected and published links to a rich variety of Information Security recourses that we hope will be helpful.

 

Broken Links

The Web is a very dynamic place; a link today may not mean a link tomorrow. We would greatly appreciate your assistance with helping us maintain the usefulness of this Resource page by reporting any broken or questionable links you encounter. We request that you send the link in question, along with a brief description of the issue, to webmaster@rvasi.com.

 

The team at RVASI is always on the lookout for great links to Information Security resources and related materials. If you know of one or more links that fit this bill, please send an email with the link(s) to resourcelinks@rvasi.com.  All submitted links will be evaluated and those deemed suitable/appropriate will be published.

   

Also, we often reward our top link contributors with RVASI G3AR!

 

Link Disclaimer

Linked Sites are not under the control of RVASI and RVASI is not responsible for the contents of any Linked Site, including, without limitation, any link contained on a Linked Site, or any changes or updates to a Linked Site. Follow links off our site at your own risk.  Furthermore, RVASI is not responsible for web casting or any other form of transmission received from any Linked Site, nor is RVASI responsible if the Linked Site is not working appropriately.  RVASI provides these links merely as a convenience and the inclusion of any link does not imply endorsement by RVASI.

 

Please be aware that we, RVASI, are not responsible for the privacy practices of any Linked Sites.  We encourage you to be aware when you leave our site and to read the privacy statements of every Web site that collects Personally Identifiable Information (PII).  RVASI’s Privacy Statement only applies to information collected on or by our Web site.

 

For additional great resources, visit the RVASI Forum.

 

 

Table of Contents     

Security Alerts/Advisories Cyber Law Sites
       
Vulnerability Databases Privacy Focused Sites
       
Industry Best Practices Web Application Security
       
InfoSec News Secure Development Resources
       
InfoSec Publications Computer Forensics
       
InfoSec Research Personal Firewalls
       
InfoSec Statistics Spyware & Adware Tools
       
InfoSec Sites Security Testing Sites
       
Government InfoSec Sites Security Books
       
Regulatory Agencies & Compliance Miscellaneous Sites
       
Fun Stuff    

 

 

Security Alerts/Advisories

Visit one or more of these sites to stay current with newly published vulnerabilities

and exploits.

 

SANS Institute - Security Advisories, Alerts, and More

http://www.sans.org/newsletters/

 

CERT Security Alerts, Advisories, and Summaries

http://www.us-cert.gov/cas/techalerts/index.html

 

Internet Security Systems Alerts and Advisories (X-Force)

http://xforce.iss.net/xforce/alerts

 

Zone-H Security Alerts and Advisories

http://www.zone-h.org/en/advisories

 

AusCERT - Australia's National Computer Emergency Response Team

http://www.auscert.org.au/

 

U.S. DOE-CIAC (Computer Incident Advisory Capability) Website

http://www.ciac.org/ciac/index.html

 

CIAC - Security Bulletins and Advisories

http://ciac.llnl.gov/cgi-bin/index/bulletins

 

SecurityTracker.com - Keep Track of the Latest Vulnerabilities

http://www.securitytracker.com/startup/index.html

 

Oracle Technology Network - Security

http://www.oracle.com/technology/deploy/security/alerts.htm

 

Macromedia Security Bulletins

http://www.macromedia.com/devnet/security/security_zone/

 

Microsoft Security Home Page - Updates, Incidents, & Bulletins

http://www.microsoft.com/security/default.mspx

 

NOVELL Security Alerts

http://support.novell.com/security-alerts/

 

Sun Security Bulletins   

http://sunsolve.sun.com/pub-cgi/show.pl?target=security/sec

 

Cisco Security Advisories and Notices

http://www.cisco.com/en/US/products/products_security_advisories_listing.html

 

Debian Security Information - Latest Debian Security Advisories

http://www.debian.org/security/

 

Wireless Security Alerts - From F-Secure

http://www.europe.f-secure.com/wireless/security/

 

Trend Micro - Virus Information and Alerts

http://www.trendmicro.com/vinfo/

 

McAfee - Virus Alerts

http://us.mcafee.com/virusInfo/default.asp?cid=10371

 

Symantec Security Response - Latest Virus Threats and Security Advisories

http://securityresponse.symantec.com/

 

                                                                                                                        Top of Page

 

 

Vulnerability Databases

Research past and current vulnerabilities and find the information/details you need.

 

ICAT Metabase

http://icat.nist.gov/icat.cfm

 

Open Source Vulnerability Database

http://www.osvdb.org/

 

SecurityFocus

http://www.securityfocus.com/

 

Internet Security Systems' X-Force Database

http://xforce.iss.net/xforce/search.php

 

Safety Lab - Vulnerability Database

http://www.safety-lab.com/audits/categorylist.pl?lang=en

 

                                                                                                            Top of Page

 

 

Industry Best Practices

Find links to "Best Practice" documentation, checklists, and other resources for a variety of

Information Security areas.

 

NIST - Computer Security Resource Center (CSRC)

http://csrc.nist.gov/publications/nistpubs/ 

 

Improving Web Application Security: Threats and Countermeasures

http://download.microsoft.com/download/d/8/c/d8c02f31-64af-438c-a9f4-e31acb8e3333/Threats_Countermeasures.pdf

           

Basic Security Practices for Web Applications

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/vbcon/html/vbconbestsecuritypracticesforwebapplications.asp

 

Secure Coding Guidelines for the .NET Framework

http://msdn.microsoft.com/security/securecode/bestpractices/default.aspx?pull=/library/en-us/dnnetsec/html/seccodeguide.asp

 

Building and Configuring More Secure Web Sites - Win2k, IIS 5.0, SQL2K,

& .NET Framework

http://msdn.microsoft.com/security/securecode/bestpractices/default.aspx?pull=/library/en-us/dnnetsec/html/openhack.asp

 

Designing Application-Managed Authorization

http://msdn.microsoft.com/security/securecode/bestpractices/default.aspx?pull=/library/en-us/dnbda/html/damaz.asp

 

Best Practices for Secure Development

http://www.linuxsecurity.com/resource_files/documentation/best_prac_for_sec_dev4.pdf

 

Cisco - Network Security Policy: Best Practices

http://www.cisco.com/warp/public/126/secpol.html 

 

ISECOM - Institute for Security and Open Methodologies

http://www.isecom.org/

 

ISO - International Organization for Standardization

http://www.iso.org/iso/en/ISOOnline.openerpage

 

Wireless Security Best Practices

http://www.intel.com/business/bss/infrastructure/wireless/security/best_practices.htm

 

World Wide Web Consortium

http://www.w3.org/

 

Top of Page

 

 

InfoSec News

Visit one or more of these sites to stay current with past and present Information Security

news developments.

 

Zone-H.org * News

http://www.zone-h.org/en/news

 

IRIA - Security in the News

http://www.thei3p.org/news/today.html

 

NewsNow: Encryption / Security

http://www.newsnow.co.uk/newsfeed/?name=Encryption+/+Security

 

Security News Portal

http://www.securitynewsportal.com/index.shtml

 

SearchSecurity.com, the news and tips source on information security and firewalls

http://searchsecurity.techtarget.com/ 

 

Security | The Register 

http://www.theregister.co.uk/security/

 

McAfee.com - Recently Discovered Viruses

http://vil.mcafee.com/newVirus.asp

 

                                                                                                            Top of Page

 

 

InfoSec Publications

Subscribe or read these Information Security related publications online.

 

Information Security magazine

http://infosecuritymag.techtarget.com/

 

Secure Computing Magazine

http://www.scmagazine.com/home/index.cfm

 

CSO - Resource for Security Executives

http://www.csoonline.com/index.html

 

Security Management

http://www.securitymanagement.com/main.html

 

Top of Page

 

 

InfoSec Research

Research past or current Information Security topics, vulnerabilities, exploits, and more.

 

Institute for Security Technology Studies (ISTS)

http://www.ists.dartmouth.edu/ 

 

CVE - Common Vulnerabilities and Exposures

http://www.cve.mitre.org/ 

 

Open Vulnerability Assessment Language (OVAL)

http://oval.mitre.org/ 

 

The Center for Education and Research in Information Assurance and

Security (CERIAS)

http://www.cerias.purdue.edu/ 

 

Sys-Security.com - Dedicated to Computer Security Research

http://www.sys-security.com/

 

Top of Page

 

 

InfoSec Statistics

Stay current with Information Security statistics and trends

 

SecurityStats.Com

http://www.securitystats.com/

 

Computer Security Institute (CSI)

http://www.gocsi.com/ 

                       

                                                                                                            Top of Page

 

 

InfoSec Sites

Visit one or more of these sites dedicated to the topic of Information Security and find

valuable information, tools, resource links, and more.

 

SANS (SysAdmin, Audit, Network, Security) Institute

http://www.sans.org/index.php

 

CERT® Coordination Center (CERT/CC)

http://www.cert.org/

 

The Security Portal for Information System Security Professionals

http://www.infosyssec.net/infosyssec/

 

WindowSecurity.com - Windows Security News, Articles, Tutorials, Software, and more

http://www.windowsecurity.com/

 

SecureMac.com - Macintosh Security Site

http://www.securemac.com/

 

Help Net Security

http://www.net-security.org/index.php

 

Dutch Security Information Network

http://www.dsinet.org/

 

Linux Security - The Community's Center For Security

http://www.linuxsecurity.com/

 

Center for Internet Security - Standards

http://www.cisecurity.com/

 

Computer Security Institute

http://www.gocsi.com/

 

The World Wide Web Consortium (W3C) Security Resources

http://www.w3.org/Security/Overview.html

 

Wirelesscon.com - Wireless Web portal - security

http://www.wardrive.org/live/

 

U.S. Security Awareness

http://www.ussecurityawareness.org/highres/index.html

 

Top of Page

 

 

Government InfoSec

Visit one or more of these government Information Security sites and find valuable

information, tools, resource links, and more.

 

The Federal Computer Incident Response Center (FedCIRC)

http://permanent.access.gpo.gov/websites/www.fedcirc.gov/

 

DoD Cyber Crime Center - Crime, Forensics, and Training

http://www.dcfl.gov/dc3/home.htm

           

US-CERT - United States Computer Emergency Readiness Team

http://www.us-cert.gov/

 

Office of the Deputy Chief Information Officer (ODCIO)

http://irm.cit.nih.gov/

 

Computer Crime and Intellectual Property Section (CCIPS)

http://cybercrime.gov/

 

National Security Agency/Central Security Service (NSA/CSS)

http://www.nsa.gov/ 

 

Department of Homeland Security (DHS)

http://www.dhs.gov/dhspublic/

         

                                                                                                Top of Page

                                               

 

Regulatory Agencies & Compliance

Find links to various Government and Industry sites that deal with Regulatory Compliance;

these sites also provide a wide-range of information and links to other related topics.

 

Compliance Pipeline - Vast Repository Of Regulatory Compliance Related

Information

http://www.compliancepipeline.com/ 

 

Federal Financial Institutions Examination Council's (FFIEC)

http://www.ffiec.gov/

 

Board of Governors of the Federal Reserve System (FRB)

http://www.federalreserve.gov/ 

 

Federal Deposit Insurance Corporation (FDIC)

http://www.fdic.gov/ 

 

The Office of the Comptroller of the Currency (OCC)

http://www.occ.treas.gov/ 

 

The Office of Thrift Supervision (OTS)

http://www.ots.treas.gov/ 

 

National Credit Union Administration (NCUA)

http://www.ncua.gov/ 

 

Federal Trade Commission

http://www.ftc.gov/index.html

 

Top of Page

 

 

Cyber Law Sites

Visit one or more of these sites and stay current with past and present legislation affecting

and/or directed towards Cyberspace

 

BitLaw - A Comprehensive Internet Resource on Technology Law

http://www.bitlaw.com/ 

 

GigaLaw.com - Legal Information for Internet Professionals

http://www.gigalaw.com/index.html

 

Top of Page

 

 

Privacy Focused Sites

Visit one or more of these sites and stay current with a multitude of Information Security

privacy issues, concerns, and more.

 

Electronic Privacy Information Center

http://www.epic.org/

 

Privacy.org - The Source for News, Information, and Action

http://www.privacy.org/ 

 

                                                                                                            Top of Page

 

 

Web Application Security

Find links to various online resources whose primary focus is Web application security;

many of these sites offer outstanding whitepapers, checklists, links to additional resources,

and more.

 

Web Application Security Consortium

http://www.webappsec.org/index.html

           

The Open Web Application Security Project (OWASP)

http://www.owasp.org/index

 

Cgisecurity - Web Application News, and more

http://www.cgisecurity.com/

 

Technical Info dot Net - by Gunter Ollmann

http://www.technicalinfo.net/index.html

 

                                                                                                            Top of Page

 

 

Secure Development Resources

Find links to excellent resources focused on secure coding and developing secure Web

applications

 

Secure Coding: Principles & Practices

http://www.securecoding.org/ 

 

Secure Programming for Linux and UNIX HOWTO -
http://www.dwheeler.com/secure-programs/

 

Top of Page

 

 

Computer Forensics

Find links to a variety of sites that provide valuable information, resources, tools, insight,

and more pertaining to Computer Forensics

 

The Computer Forensics Community - CFC

http://computerforensics.99er.net/index.php

 

Computer Forensics Tool Testing Program - NIST

http://www.cftt.nist.gov/

 

The International Association of Computer Investigative Specialist (IACIS)

http://www.cops.org/

 

Top of Page

 

 

Personal Firewalls

Find links to proven personal firewall technology

 

ZoneAlarm - Personal Firewall & Security Suite

http://www.zonelabs.com/store/content/home.jsp

 

BlackICE - Personal Firewall with an Advanced Intrusion Detection System

http://www.digitalriver.com/dr/v2/ec_dynamic.main?SP=1&PN=10&sid=26412

 

Top of Page

 

 

Spyware & Adware Tools

Find links to proven tools, information, and other resources dedicated to preventing and

combating Spyware & Adware.

 

Spyware Guide Database - Spyware, Malware and Adware

http://www.spywareguide.com/

 

Ad-aware - Multicomponent Detection and Removal Utility

http://www.lavasoft.de/

 

PestPatrol - Spyware and Adware Removal

http://www.pestpatrol.com/

 

Spybot-S&D - Anti-Spyware Scanner

http://security.kolla.de/

 

Spy Sweeper - Spyware Removal Software and Spyware Protection by Webroot Software

http://www.webroot.com/wb/products/spysweeper/index.php

 

SpywareBlaster - Spyware Prevention

http://www.javacoolsoftware.com/spywareblaster.html

 

SpywareGuard - Spyware Prevention

http://www.javacoolsoftware.com/spywareguard.html

 

Top of Page

 

 

Security Testing

Find links to various sites that offer free online remote security testing of your System.

 

Gibson Research Corporation Home Page - Multiple Remote Testing Utilities

http://www.grc.com/default.htm

 

Symantec Security Check

http://security.symantec.com/ssc/home.asp?j=1&langid=ie&venid=sym&plfid=23&pkj=RJUSLYOCXXKZFRGIJYW

 

Security Scan - Sygate Online Services (free)

http://scan.sygatetech.com/ 

 

McAfee - Computer Virus Software and Internet Security For Your PC

http://us.mcafee.com/root/mfs/default.asp?WWW_URL=www.mcafee.com/myapps/mfs/default.asp

 

Top of Page

 

 

Security Books

Find links to highly rated books within the Information Security community that deal with

a variety of topics.

 

Linux (Hacking Exposed)

http://www.amazon.com/exec/obidos/ASIN/0072127732/cleoandnacho-20

 

Computer Forensics : Incident Response Essentials

http://www.amazon.com/exec/obidos/tg/detail/-/0201707195/ref=ase_cleoandnacho-20/104-5273379-8719930?v=glance&s=books

 

Secure Coding, by Mark Graff and Ken Van Wyk (2003)

http://www.securecoding.org

 

Building Secure Software, by Gary McGraw and John Viega (2002)

http://www.buildingsecuresoftware.com

 

Hacking Web Applications Exposed

http://www.amazon.com/exec/obidos/tg/detail/-/007222438X/002-9563622-6700041?v=glance

 

Exploiting Software, by Gary McGraw and Greg Hoglund (2004)

http://www.exploitingsoftware.com

 

Writing Secure Code, by Mike Howard and David LeBlanc (2003)

http://www.microsoft.com/mspress/books/5957.asp

 

Innocent Code, by Sverre Huseby (2004)

http://innocentcode.thathost.com

 

The Art of Deception: Controlling the Human Element of Security

http://www.amazon.com/exec/obidos/tg/detail/-/0471237124/ref=ase_cleoandnacho-20/104-5273379-8719930?v=glance&s=books

 

Network Intrusion Detection: An Analyst's Handbook (2nd Edition)

http://www.amazon.com/exec/obidos/tg/detail/-/0735710082/ref=ase_cleoandnacho-20/104-5273379-8719930?v=glance&s=books

 

Hacking Exposed: Network Security Secrets & Solutions, Second Edition (Hacking Exposed)

http://www.amazon.com/exec/obidos/tg/detail/-/0072127481/ref=ase_cleoandnacho-20/104-5273379-8719930?v=glance&s=books

 

Mastering the Requirements Process, by Robertson and Robertson

http://www.amazon.com/exec/obidos/tg/detail/-/0201360462/ref=pd_sxp_f/104-3962476-3180712?v=glance&s=books

 

The Unified Modeling Language - A User Guide

http://www.awprofessional.com/catalog/product.asp?product_id=%7B9A2EC551-6B8D-4EBC-A67E-84B883C6119F%7D

 

Top of Page

 

 

Fun Stuff

Visit one or more of these linked sites and test your hacking or other Information Security

skills in a fun and challenging environment      

 

HackQuest!

http://www.hackquest.de/

           

Hack this site!

http://www.hackthissite.org/

 

Next Generation Security Technologies

http://quiz.ngsec.biz:8080/

 

Hackits

http://www.hackits.de/

 

HackersLab Free Hacking Zone

http://www.hackerslab.org/eorg/hackingzone/hackingzone.htm

 

List of Hacker Challenges - look under What's Cool

http://hackergames.net/index.php

 

Top of Page

 

 

Miscellaneous Sites

Find links to sites that are not directly Information Security related but can be used to

support various security related endeavors

 

DoShelp.com - Intrusion & Attack Reporting Center

http://www.doshelp.com

 

Hushmail - Secure Email

http://www.hushmail.com/

 

The USENIX Association - The Advanced Computing Systems Association

http://www.usenix.org/

 

IETF RFC Page

http://www.ietf.org/rfc

 

IANA - Internet Assigned Numbers Authority

http://www.iana.org/

 

Internet RFC/FYI/STD/BCP Archives

http://www.faqs.org/rfcs/

 

FOLDOC - Computing Dictionary

http://foldoc.doc.ic.ac.uk/foldoc/index.html

 

Webopedia: Online Computer Dictionary for Computer and Internet Terms and

Definitions

http://www.webopedia.com/

 

Sysinternals - Advanced utilities, technical information, and source code related

to Windows NT/2000/XP/2K3

http://www.sysinternals.com/index.shtml

 

InfoSec Writers

http://www.infosecwriters.com/index.php

 

Way Back Machine - Internet Archive

http://www.archive.org/  

 

                                                                                                            Top of Page

Privacy Statement  |   Terms of Use  |   FAQs  |   Contact Us  |   Site Map
© Copyright 2005, RVASI, All Rights Reserved.