[Fedora-livecd-list] Security LiveCD

Jane Dogalt jdogalt at yahoo.com
Mon Mar 5 02:51:43 UTC 2007



--- Luke Macken <lmacken at redhat.com> wrote:

> I started piecing together a Fedora Security LiveCD, designed for
> security auditing, penetration testing, and forensics.  See my blog
> post and the wiki page for more information:
> 
>     http://lewk.org/blog/2007/03/04/security-livecd
>     http://fedoraproject.org/wiki/LukeMacken/SecurityLiveCD
> 
> {comments,suggestions,patches} welcome.

Perhaps an even better usage scenrio than the one I just mentioned is
this-

The security livecd boots on any target system, and then qemu boots the
harddisk of the local system in snapshot mode (so that no actual
changes ever get made to the local disk).  Then the security livecd
host system does a penetration test against the virtually booted system
from the local disk.

Effectively this would be a way to walk up to any server (even
winblowz/ubuntu/etc...) and be able to "bless" it as being up to some
minimum level of secure, or alert the user to exactly which penetration
tests the target system failed to fend off.

-dmc/jdog

 


 
____________________________________________________________________________________
Don't get soaked.  Take a quick peak at the forecast
with the Yahoo! Search weather shortcut.
http://tools.search.yahoo.com/shortcuts/#loc_weather




More information about the Fedora-livecd-list mailing list