you are visiting < http://www.ibiblio.org/matusiak/bkmrk.html >.     if you are feeling lost, click here.

ibiblio.org orangeroom.org matusiak.org

    NOTE: This page changed as of 09 September 2007.   All feedback is welcome at matusiak at ibiblio dot org.   Thanks for visiting this bookmark page!

network operating systems security resources web development
ppc/macOSX
bsd unix
svr4 unix
gnu/linux
firewalls
intrusion detection & prevention
virtual private network
honeypots & miscellaneous
apache
HTML
databases
XML
perl
PHP
networking people & technology web services
trade publications
intro & tutorials
RFC & white papers
IPv6 info
wonderful contributors
tech coverage
books & publishers
organizations
domain registrars
hosting services
spam services
other services

_network operating systems_

ppc/macOSX

Mac OS X Apps - http://www.macosxapps.com/
Apple's Open Source Mailing Lists - http://developer.apple.com/darwin/mail.html
The Darwin Project - http://developer.apple.com/darwin/
Open Darwin - http://www.opendarwin.org/
Fink - Debian-like (apt-get) Package Management System for OS X - http://fink.sourceforge.net/
GNU-Darwin - FreeBSD ports system for OS X - http://gnu-darwin.sourceforge.net/
Stepwise - news and tips for programmers - http://www.stepwise.com/
Mac Security dot org - http://www.macsecurity.org/
Version Tracker - the place to look for OS X software - http://www.versiontracker.com/
O'Grady's PowerPage - http://www.powerpage.org/
Mac Dev Center dot com from O'Reilly - http://www.macdevcenter.com/
SecureMac dot com - http://www.securemac.com/
Apple Developer Connection News - http://developer.apple.com/devnews/
mac OSX (10.2 or higher *highly* recommended!) - http://www.apple.com/macosx/
troubleshooting OS X - http://www.info.apple.com/usen/macosx/tshoot.html
tidbits - for mac lovers - http://www.tidbits.com/
mac os x hints - http://www.macosxhints.com/
Mac OSX Labs dot org - OSX Deployment in Higher Education - http://www.macosxlabs.org/
mercury news article on Problems with Jaguar - http://www.bayarea.com/mld/mercurynews/business/3961332.htm
openbsd on mac ppc - http://www.openbsd.org/macppc.html
building dual (or triple boot) mac - http://mail-index.netbsd.org/port-macppc/2001/04/10/0002.html

bsd unix

OpenBSD - http://openbsd.org
NetBSD - http://netbsd.org
FreeBSD - http://freebsd.org
DaemonNews - Bringing BSD Together - http://www.daemonnews.org/
Secure srv/fw w/ openbsd - http://www.openbsd.org/papers/oreilly2000/index.html
upgrading ipfilter on openbsd - http://www.tfsb.org/ipf-openbsd/
triangle bsd usr grp - http://www.tribug.org/
monitoring unix logins - http://www.oreillynet.com/pub/a/bsd/2001/02/14/FreeBSD_Basics.html
Using an OpenBSD Firewall to Share a Cable Modem - http://gridley.acns.carleton.edu/~lowem/pages/openbsd.html
bsd forums - http://www.freebsdforums.org/
greasy daemon news - http://www.greasydaemon.com/news/

svr4 unix

Freeware for Solaris - come git your free binaries! - http://www.sunfreeware.com/
UnixReview dot com - http://www.unixreview.com/
unix guru universe - http://www.ugu.com/
NC sys admins - http://www.ncsysadmin.org/index.html
Sys Admin Magazine Online - http://www.sysadminmag.com/    also: http://www.samag.com/
intro to unix sys admin - http://www.skilltop.com/unixadmin/
unix insider - http://www.sunworld.com/common/
sun microsystems - http://www.sun.com/
sun solaris - http://www.sun.com/solaris/
Sun BigAdmin portal - http://www.sun.com/bigadmin/
sgi irix - http://www.sgi.com/software/software.html#IRIX

gnu/linux

Linux Documentation Project (LDP) - http://www.tldp.org/
Linux Terminal Server Project (LTSP) - http://www.ltsp.org
Linux Administrator's Security Guide (LASG) by Kurt Seifried - http://www.seifried.org/lasg/
RHCE RH302 exam prep book from Osborne Press - http://shop.osborne.com/cgi-bin/osborne/0072224851.html
En Garde secure linux distro - http://www.engardelinux.org/
Immunix.org: Secure Linux - http://immunix.org/
Owl from Openwall - a security-enhanced server platform - http://www.openwall.com/Owl/
NSA's Security-Enhanced Linux - http://nsa.gov/selinux/
LIDS Project - Secure Linux System - http://www.lids.org/
Astaro secure linux - http://www.astaro.com/
Medusa DS9 security system - http://medusa.fornax.sk/
Linux by Libranet - http://www.libranet.com/
triangle linux usr grp - http://www.trilug.org/
debian - http://www.debian.org/
redhat - http://www.redhat.com/
suse - http://www.suse.com/
linuxbase - http://www.linuxbase.org/
free standards - http://www.freestandards.org/
linux central - http://linuxcentral.com/
book: "Securing and Optimizing RH Linux" - http://en.tldp.org/LDP/solrhe/Securing-Optimizing-Linux-RH-Edition-v1.3/index.html
LDP Linux Network Administrators Guide - http://en.tldp.org/LDP/nag2/index.html
zdnet linux resource center - http://www.zdnet.com/enterprise/filters/resources/0,10227,2186824,00.html
Floppy/CD Linux Distributions - http://users.sunet.com.au/~tsn/floppy_linux.html
Meeting Critical Security Objectives with Security-Enhanced Linux - http://nsa.gov/selinux/doc/ottawa01/ottawa01.html
Rule Set Based Access Control for Linux - http://www.rsbac.org/
Linux on Laptops - http://www.linux-laptop.net/    also: http://www.linux-on-laptops.com/

_security resources_

SANS dot org - home of GIAC certification - http://www.sans.org/
SANS TCP/IP knowledge quiz - http://www.sans.org/conference/tcpip_quiz.php
InternetStormCenter - incidents dot org - http://isc.incidents.org/
vulnerabilities dot org - free system scanning - http://www.vulnerabilities.org/
WWW Security FAQ - http://www.w3.org/Security/Faq/
AusCERT home page - http://www.auscert.org.au/
AusCERT Unix Security Checklist v2.0 - http://www.cert.org/tech_tips/AUSCERT_checklist2.0.html
OWASP - the "Open Web Application Security Project" - http://www.owasp.org/
SWITCH links - http://www.switch.ch/cert/info/links.html
SecurityGeeks News by the Shmoo Group - http://securitygeeks.shmoo.com/
Counterpane Internet Security, Inc. - http://www.counterpane.com/

firewalls

Halted Firewalls from Sys Admin Mag - http://www.samag.com/documents/s=1824/sam0201d/0201d.htm
ipfilter (ipf) - http://coombs.anu.edu.au/~avalon/ip-filter.html
ipf info - http://www.obfuscation.org/ipf/
upgrading ipfilter on openbsd - http://www.tfsb.org/ipf-openbsd/
pf - OpenBSD packet filter - http://www.benzedrine.cx/pf.html
pf HOWTO - http://www.deadly.org/pf-howto/
checkpoint firewall 1 - http://www.checkpoint.com/products/security/firewall-1.html
Hacking Firewalls - http://www.piuha.net/~martti/papers/hacking/hacking.html
FW config prereqs - http://securityportal.com/articles/prereq20010219.html
phoneboy knows checkpoint FWs and cisco routers - http://www.phoneboy.com/
IPTables tutorial 1.0.4 - http://people.unix-fu.org/andreasson/index.html
Firewalls and Internet Security: Repelling the Wily Hacker - http://www.wilyhacker.com/
TCP traceroute - http://michael.toren.net/code/tcptraceroute/

intrusion detection & prevention (ids) (ips)

CERT Intruder Detection Checklist - http://www.cert.org/tech_tips/intruder_detection_checklist.html
Snort - worlds best free IDS - http://www.snort.org/
CrunchBox from ShopIP.com - CrunchBox 3.1
Tripwire dot org - Home of the Tripwire Open Source Project - http://www.tripwire.org/
farm9.com - Intrusion Detection & Prevention - http://farm9.com/content/
psionic - abacus is their intrusion /prevention/ system - http://www.psionic.com/abacus/
psionic common intrusions - http://www.psionic.com/papers/attacks
Prelude Hybrid IDS - http://www.prelude-ids.org/
DARPA/MIT IDS evaluations - http://www.ll.mit.edu/IST/ideval/

virtual private network (vpn)

Tina Bird's VPN FAQ - http://vpn.shmoo.com/vpn/FAQ.html
FreeS/WAN - http://www.freeswan.org/
KAME project - http://www.kame.net/
checkpoint VPN-1 - http://www.checkpoint.com/products/security/index.html

honeypots & miscellaneous

HoneyNet Project - http://project.honeynet.org/
Honeypots: Tracking Hackers - http://www.trackinghackers.com/
Secure Programming for Linux and Unix HOWTO - http://www.dwheeler.com/secure-programs/
SWATCH - simple log watcher - http://www.oit.ucsb.edu/~eta/swatch/
Next Gen Security software - makers of Typhoon scanner - http://www.nextgenss.com/
Razor security at bindview - http://razor.bindview.com/
SC Magazine - http://www.scmagazine.com/index2.html
l0pht's new home - http://www.atstake.com/research/redirect.html
securify - http://packetstorm.securify.com/
packetstorm - http://www.packetstormsecurity.com/
winfingerprint - http://winfingerprint.sourceforge.net/
xforce's list of security lists - http://xforce.iss.net/maillists/otherlists.php
xforce itself - http://xforce.iss.net/
neworder - http://neworder.box.sk/
NSI security lists - http://www.nsi.org/Computer/mailinglists.html
wiretrip - http://www.wiretrip.net/rfp/7/index.asp
robert graham - infosec - http://www.robertgraham.com/
security space - http://www.securityspace.com/sspace/index.html
security focus - http://www.securityfocus.com/
silicon defense - info for your CEO - http://www.silicondefense.com/securityinfo/ceo.htm
technotronic - another sourceforge project - http://www.technotronic.com/
whitehats - http://www.whitehats.com/
mmmm... nmap... - http://www.insecure.org/nmap/index.html
www sec from w3c - http://www.w3.org/Security/Faq/www-security-faq.html
fortier - http://www.hackervillage.com/
the end of SSL and SSH? - http://securityportal.com/cover/coverstory20001218.html
ScanSSH - protocol scanner - http://www.monkey.org/~provos/scanssh/
matt blaze's crypto site - http://www.crypto.com/
Wireshark Network Protocol Analyzer - http://www.wireshark.org/
SecurityFlaw dot Com - http://www.securityflaw.com/
Security Bugware - http://www.securitybugware.org/
Why You Should Use Encryption - http://www.goingware.com/encryption/
GnuPG dot org - GNU Privacy Guard - http://www.gnupg.org/
Freeware PGP versions - http://www.pgpi.org/products/pgp/versions/freeware/
chkrootkit -- locally checks for signs of a rootkit - http://www.chkrootkit.org/
SecuriTeam.com - http://www.securiteam.com/
TCSecure by Trusted Computer Solutions - http://www.tcs-sec.com/products/tcsecure/tcsecure-intro.html
ISP Security - http://www.isp-security.com/
Hack in the box - news from the dark side - http://www.hackinthebox.org/
EVAS dot nl - Exploit and Vulnerability Alerting Service - http://www.evas.nl/

_web development_

Programmer's Heaven for Web Dev - http://www.programmersheaven.com/zone14/index.htm
WWW Authentication - http://www.seifried.org/security/www-auth/
Viewable with Any Browser Campaign - http://www.anybrowser.org/campaign/
Web Standards Project (WaSP) - http://webstandards.org/
devshed rocks! - http://www.devshed.com/
webmonkey kinda rocks! - http://hotwired.lycos.com/webmonkey/
New Architect (used to be Web Techniques) - http://www.newarchitect.com/
wanna block M$ "Smart" tags? - http://smarttags.manilasites.com/discuss/msgReader$9
site help from speakeasy - http://www.speakeasy.net/main.php?page=sup_hosting
site help from earthlink - http://help.earthlink.net/websupport/startersite/menu.html
2-pop - The Digital Filmmaker's Resource Site - http://www.2-pop.com/
Project Manager - http://projman.sourceforge.net/

apache

apache dot org - http://www.apache.org/
apache DOCS - http://httpd.apache.org/docs/
Authentication, Authorization, and Access Control in Apache 1.3 - http://httpd.apache.org/docs/howto/auth.html

HTML

BBEdit totally rules for all types of coding!! - http://www.barebones.com/products/bbedit.html
HTML Goodies - http://www.htmlgoodies.com/
HTML-Kit from Chami dot com - http://www.chami.com/html-kit/
Web Developer Notes dot com - http://www.webdevelopersnotes.com/
Designing CSS web pages - http://www.cssbook.com/
Interface design for ecommerce applications - http://www.paulgokin.com/book/default.htm

databases

mySQL - http://www.mysql.com/
PostGreSQL - http://www.postgresql.org/

XML

XML dot com - http://www.xml.com/
XML dot org - http://www.xml.org/
XML dot apache dot org - http://xml.apache.org/
the XML FAQ - http://www.ucc.ie/xml/faq.xml
triangle xml usr grp - http://www.trixml.org/
Java and XML - according to Sun - http://java.sun.com/xml/
XML developer news - http://www.xmlhack.com/

perl

perl basics -
intro to perl - http://www.perl.com/pub/a/2000/10/begperl1.html
perl intro - http://www.devshed.com/Server_Side/Perl/Perl101_1/
Test Shows 99.99% of High School Seniors Can't Read Perl - http://bbspot.com/News/2001/03/perl_test.html

PHP

php dot net - http://php.net/
php intro - http://www.devshed.com/Server_Side/PHP/Introduction/
zend dot com - http://www.zend.com/
zend tutorial - http://www.zend.com/zend/tut/
php nuke - http://www.phpnuke.org/
php builder - http://www.phpbuilder.com/
melonfire - http://www.melonfire.com/

_networking_

trade publications

Network World Fusion - http://www.nwfusion.com/
silicon dot com - http://www.silicon.com/
siliconvalley - http://www.siliconvalley.com/
IDG - http://www.idg.net/
ISP Planet - http://isp-planet.com/
Dr. Dobbs Journal - software coverage - http://www.ddj.com/
Application Development Trends Magazine - http://www.adtmag.com/
IT Professionals Resource Center - http://www.itprc.com/
Software Market Solution - http://www.softwaremarketsolution.com/
Software Development magazine - http://www.sdmagazine.com/

intro & tutorials

PacketNexus - http://www.packetnexus.com/
Daryl's TCP/IP Primer - http://www.ipprimer.com/
Internet Ports Database - http://www.portsdb.org/
Practically Networked dot com - http://www.practicallynetworked.com/

RFC & white papers

RFC Ignorant - http://www.rfc-ignorant.org/
IP, ICMP, TCP, UDP RFCs:
http://www.faqs.org/rfcs/rfc791.html
http://www.faqs.org/rfcs/rfc792.html
http://www.faqs.org/rfcs/rfc793.html
http://www.faqs.org/rfcs/rfc768.html

You should also read:
http://www.faqs.org/rfcs/rfc2979.html
http://www.faqs.org/faqs/firewalls-faq/
http://www.faqs.org/rfcs/rfc2827.html
http://www.faqs.org/rfcs/rfc2900.html

USENIX paper on DOS attacks - http://www.usenix.org/events/sec01/moore.html

IPv6

6NET - Large-scale IPv6 pilot - http://www.6net.org/
Sun specs on IPv6 - http://playground.sun.com/pub/ipng/html/ipng-main.html
6bone - IPv6 testbed - http://www.6bone.net/

_people & technology_

wonderful contributors

Lance Spitzner - i.e. "The Man" - http://www.spitzner.net/
Eric S. Raymond - gun nut and free software junkie - http://tuxedo.org/~esr/
Joel on Software - http://joel.editthispage.com/
KenWahl.Org - http://www.ipass.net/~kenwahl/
Hali Tower, Darkover - http://www.linux-firewall-tools.com/
Steven M. Bellovin - UNC grad and impressive computer scientist - http://www.research.att.com/~smb/
Rajeev Kumar's homepage - http://www.rajeevnet.com/
Marcus Ranum's Personal Page - http://www.ranum.com/
http://vapid.dhs.org/ - http://vapid.dhs.org/
No Such Weblog - http://log.does-not-exist.org/
Rain Forest Puppy - http://www.wiretrip.net/rfp/

tech coverage

the UK register - http://www.theregister.co.uk/
rc3 - Rafe Colburn's insightful musings - http://rc3.org/
venona.antioffline.com - http://venona.antioffline.com/
slashdot - http://slashdot.org
kuro5hin - http://kuro5hin.org
w00w00 Security Development - http://www.w00w00.org/
@stake, Inc. - http://www.atstake.com/
ModernHacker.com - http://www.modernhacker.com/
Tech Mavens - http://www.tech-mavens.com/
geek.com - http://www.geek.com/
cipherwar - goddamn hackers! - http://www.cipherwar.com/
think like a computer scientist (java focus) - http://www.ibiblio.org/obp/thinkCSjav/
free info from learningtree.com - http://www2.learningtree.com/techtips/us/index.asp
ximian is the hottest new desktop, haven't ya heard? - http://www.ximian.com/products/
Echelon is eating your babies! - http://www.zdnet.co.uk/news/specials/2000/06/echelon/
New Scientist.com - The World's No. 1 Science and Technology News Service - http://www.newscientist.com/

books & publishers

Bookpool rocks! - http://www.bookpool.com/
Quantum Bookstore - http://www.quantumbooks.com/
BookFinder - http://www.bookfinder.com/
AddAll book search - http://www.addall.com/
ISBN book search - http://isbn.nu/

How to design programs - MIT Press - http://www.htdp.org/
Open Source Development with CVS - http://cvsbook.red-bean.com/

Project Gutenberg rocks! - http://www.promo.net/pg/
The Online Books Page from UPenn.edu - http://onlinebooks.library.upenn.edu/
MIT OpenCourseWare - get a free MIT education! - http://ocw.mit.edu/
EEVL : the internet guide to engineering, mathematics and computing - http://www.eevl.ac.uk/
Useractive - O'Reilly Learning Lab - http://www.useractive.com/oreilly/
lynda dot com - education by creative professionals - http://www.lynda.com/

O'Reilly - literally the benchmark for tech books - http://www.oreilly.com/
Safari - the O'Reilly Network Bookshelf - http://safari.oreilly.com/
New Riders - a close second to O'Reilly - http://www.newriders.com/
Manning Publications - http://www.manning.com/
Syngress Publishing - makers of great "Hack Proofing" books - http://www.syngress.com/
Wrox Press - http://www.wrox.com/
Osborne Press - part of McGraw-Hill - great certification books - http://shop.osborne.com/cgi-bin/osborne/
Sybex, Inc - software and test prep books - http://www.sybex.com/
Wiley Publishers - http://www.wiley.com/
CMP Books: Developer Series - http://www.cmpbooks.com/scripts/store/vsc/dev/homepage.htm?L+/htdocs/cmpbooks/config/store+
O'Really books - have a laugh! - http://bofhcam.org/co-larters/

organizations

Electronic Frontier Foundation - http://www.eff.org/
Computer Professionals for Social Responsibility - http://www.cpsr.org/
IEEE Computer Society - http://www.computer.org/

The Shmoo Group - secure programming practice - http://www.shmoo.com/

RTP-specific
Steve Burnett's excellent list of RTP groups - http://www.pobox.com/~burnett/triangle/groups.html
NC*SA - North Carolina System Administrators - http://www.ncsysadmin.org/
triangle linux usr grp - http://www.trilug.org/
triangle bsd usr grp - http://www.tribug.org/
triangle internetworkers - http://www.ibiblio.org/internetworkers/
triangle xml usr grp - http://www.trixml.org/
triangle wireless usr grp - http://www.triwug.org/
RTP Independent Computer Consultants Association - http://www.rtp-icca.org/

_web services_

domain registrars

godaddy dot com ($8.95 domain/yr) - http://www.godaddy.com/
register - http://www.register.com/
dotster - http://www.dotster.com/home/
network solutions - http://www.networksolutions.com/
UWhois dot com UltraMega domain search - http://www.uwhois.com/cgi/domains.cgi?User=NoAds

hosting services

Hurricane Electric - totally awesome web host on the left coast - http://www.he.net/
Inflow - local RTP host that gives free rackspace to trilug.org! - http://www.inflow.com/
The Bunker dot net - heightened security hosting - http://www.thebunker.net/
HavenCo at Sealand - the free world just milliseconds away - http://www.havenco.com/
AverData web hosting - "i've heard good things..." - http://averdata.com/

spam services

SpamCop dot net - http://spamcop.net/
Spam Assassin - http://spamassassin.org/
Vipul's Razor - http://razor.sourceforge.net/

SPAM info:
http://www.ncga.state.nc.us/Statutes/GeneralStatutes/HTML/ByArticle/Chapter_14/Article_60.html
http://law.spamcon.org/
http://www.spamlaws.com/us.html
http://www.jmls.edu/cyber/cases/spam.html
http://www.thisistrue.com/spam.html
http://www.claws-and-paws.com/spam-l/
http://www.spamlaws.com/federal/s630.html
http://www.spamlaws.com/federal/list107.html
http://www.cauce.org/legislation/index.shtml
http://easyweb.easynet.co.uk/~gcaselton/spam/bill-s1618.html
http://www.fridgemagnet.org.uk/spam.html
http://www.truthorfiction.com/rumors/spam.htm
the story of 'Nadine' - http://www.visi.com/~rparker/

other services

Geek Tools - Whois proxy - http://www.geektools.com/cgi-bin/proxy.cgi
Better Whois - http://www.betterwhois.com/
Sam Spade - a host of internet tools - http://www.samspade.org
Banner Ads we would *like* to see - http://www.valleyofthegeeks.com/Features/BannerAds.html








$ibiblio.org/matusiak/: bkmrk.html, v 1.23 2007/09/09 23:18:43 drm Exp $