Hi I haven't been following this discussion very closely, so I apologize if I'm repeating what others have already suggested, but - depending on the OS's you are interested in auditing, bastille linux ( http://www.bastille-linux.org/ ) might be useful.
It does hardening audits based on local configuration files only (no network scans) of a number of Linux distributions, as well as HP-UX and Mac OS X. Regards Mark -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Ruiyuan Jiang Sent: March 10, 2005 08:01 To: [email protected] Subject: Re: [FW-1] OT: Security Audit Software Thanks for all the answers that I got. Ryan -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Craig Paterson Sent: Thursday, March 03, 2005 4:15 AM To: [email protected] Subject: Re: [FW-1] OT: Security Audit Software May be worth having a look at Iris from Eeye, this is a commercial vulnerability scanner but doesn't cost as much as most. The only downside I have found with it is the reports can be a bit long winded and confusing at times. Cheers, Craig -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] Behalf Of Ruiyuan Jiang Sent: 01 March 2005 19:09 To: [email protected] Subject: Re: [FW-1] OT: Security Audit Software Hi, Chris Thanks for your response. I have and use Nessus. The problem that Nessus for what I need is that Nessus only checks listening ports. It can't check un-necessary user id, system configuration, i.e. ftpuser, ftp access, etc. those configuration file on UNIX. What I need is a software can gather system configuration and analyze it and give a recommendation. Thanks. Ryan -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Covington, Chris Sent: Monday, February 28, 2005 5:08 PM To: [email protected] Subject: Re: [FW-1] OT: Security Audit Software Nessus. --- Chris Covington IT Plus One Health Management 75 Maiden Lane Suite 801 NY, NY 10038 646-312-6269 http://www.plusoneactive.com -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Ruiyuan Jiang Sent: Monday, February 28, 2005 4:04 PM To: [email protected] Subject: [FW-1] OT: Security Audit Software Hi, all Does anyone know any good system security auditing software either commercial or freeware? My client's auditors have some kind of auditing software that run across platforms (UNIX, Windows, AS/400, Mainframe), etc. and collect data such as file, directory permission, password file, enabled un-necessary daemon running on the systems, etc. Unfortunately those auditors do not share the software with clients so my clients hopefully can have similar software in house to prepare systems out before auditors come. Thanks in advance. Ryan ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= -- ------------------------------------------------------------------------ ------ Halifax plc, Registered in England No. 2367076. Registered Office: Trinity Road, Halifax, West Yorkshire HX1 2RG. Regulated by the Financial Services Authority. Represents only the Halifax Financial Services Marketing Group for the purposes of advising on and selling life assurance, pensions and collective investment scheme business. ======================================================================== ====== ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
