informatique:reseau:securite
Différences
Ci-dessous, les différences entre deux révisions de la page.
| Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
| informatique:reseau:securite [10/03/2021 08:30] – [Documentation] cyrille | informatique:reseau:securite [15/08/2026 11:34] (Version actuelle) – [Protection active] cyrille | ||
|---|---|---|---|
| Ligne 3: | Ligne 3: | ||
| ===== Documentation ===== | ===== Documentation ===== | ||
| - | [[http://cwe.mitre.org|CWE - Common Weakness Enumeration]]: International in scope and free for public use, CWE™ provides a unified, measurable set of software weaknesses that is enabling more effective discussion, description, | + | CVE, CWE, CAPEC: |
| - | http:// | + | |
| [[/ | [[/ | ||
| Ligne 14: | Ligne 13: | ||
| ===== Tests ===== | ===== Tests ===== | ||
| - | PenTesting | + | PenTest -> Test d' |
| ===== Prestataires ===== | ===== Prestataires ===== | ||
| Ligne 26: | Ligne 26: | ||
| * http:// | * http:// | ||
| - | ===== Produits ===== | ||
| - | |||
| - | [[http:// | ||
| ===== Outils ===== | ===== Outils ===== | ||
| Ligne 35: | Ligne 32: | ||
| Gestionnaire de mots de passe et autres secrets: [[/ | Gestionnaire de mots de passe et autres secrets: [[/ | ||
| + | |||
| + | ==== Audit ==== | ||
| + | |||
| + | === Lynis === | ||
| + | |||
| + | Lynis effectue des audits approfondis, | ||
| + | |||
| + | |||
| + | * https:// | ||
| + | * https:// | ||
| + | |||
| + | === maltrail === | ||
| + | |||
| + | * [[https:// | ||
| ==== Protection active ==== | ==== Protection active ==== | ||
| + | |||
| + | Voir aussi [[/ | ||
| + | |||
| + | ==== ModSecurity ==== | ||
| + | |||
| + | ModSecurity est le moteur WAF open source historique. | ||
| + | |||
| + | * https:// | ||
| + | |||
| + | === SafeLine === | ||
| + | |||
| + | SafeLine est un [[/ | ||
| + | |||
| + | * https:// | ||
| + | |||
| + | === open-appsec === | ||
| + | |||
| + | open-appsec est un WAF open source basé sur l' | ||
| + | |||
| + | * https:// | ||
| + | |||
| + | === Coraza === | ||
| + | |||
| + | OWASP Coraza est un moteur WAF moderne écrit en Go, entièrement compatible avec la syntaxe des règles ModSecurity et 100% compatible avec le Core Rule Set v4. | ||
| + | |||
| + | * https:// | ||
| + | |||
| + | === BunkerWeb === | ||
| + | |||
| + | BunkerWeb est une solution open source française qui repose sur Nginx et l' | ||
| + | |||
| + | * https:// | ||
| + | * https:// | ||
| === Floodmon === | === Floodmon === | ||
| Ligne 51: | Ligne 95: | ||
| http:// | http:// | ||
| + | |||
| + | === Crowdsec === | ||
| + | |||
| + | * [[/ | ||
| === Fail2Ban === | === Fail2Ban === | ||
| Ligne 56: | Ligne 104: | ||
| Fail2ban scans log files like / | Fail2ban scans log files like / | ||
| - | http://www.fail2ban.org/ | + | * [[/informatique/system_admin/fail2ban]] |
| === mod_evasive === | === mod_evasive === | ||
| Ligne 72: | Ligne 120: | ||
| http:// | http:// | ||
| - | ==== Blacklist ==== | + | ===== Blacklist |
| - | === Phishing and Malware Protection === | + | ==== Phishing and Malware Protection |
| L' | L' | ||
| Ligne 92: | Ligne 140: | ||
| * http:// | * http:// | ||
| - | === Spam protection === | + | ==== Spam protection |
| http:// | http:// | ||
| + | ==== Listes IP/ASN malveillants ==== | ||
| - | ===== Conseils ===== | + | * [[https:// |
| - | + | * https://www.misp-project.org/ | |
| - | On a donné dans ce fil de discussion quelques conseils de sécurité, mais à mes yeux on oublie la sécurité essentielle, | + | * Partage structuré |
| - | + | * [[https:// | |
| - | Il me semble que l'on parle ici d'une société où plusieurs employés utilisent l' | + | * https://www.firehol.org/ |
| - | + | * Fournir | |
| - | Ceci est vrai pour le ftp mais aussi pour de nombreux autres protocoles. Ce n'est d' | + | * [[https:// |
| + | * Internet insight measured and monitored from over 300 nodes across 65 metropolitan areas on 6 continents. Signals are observed and discovered from our distributed network to provide unparalleled insight into anomalies and risks. | ||
informatique/reseau/securite.1615361428.txt.gz · Dernière modification : de cyrille
