WWW Security
WWW Security
Secure WWW Transactions: Client/Server Solutions
SHTTP - Secure HyperText
Transfer Protocol :
- The
Secure HyperText Transfer Protocol (ftp://ds.internic.net/internet-drafts/draft-ietf-wts-shttp-03.txt)(Internet Draft)
- cyphernet (SSL v3.0
specification SSLeay & SSLapps FAQ SSLP Project SHTTP S/KEY SSH FAQs
on sniffers, anonymous FTP & intruder-detection in UNIX FAQ on Firewalls
SESAME MOSS Decense Kerberos ) (http://www.cypher.net/info/secure.html)
SSL - Secure Sockets Layer:
- SSL
OverView (http://www.netscape.com/assist/security/ssl/index.html)
- SSL-Talk
FAQ (http://www.consensus.com/security/ssl-talk-faq.html) contains useful SSL-related information.
(http://home.netscape.com/newsref/std/sslref.html)
- NETSCAPE
SSLREF (http://home.netscape.com/newsref/std/sslref.html)
- Index
of /pub/Crypto/SSLapps (ftp://ftp.psy.uq.oz.au/pub/Crypto/SSLapps)
- Index
of /pub/internet/security/ssl/SSL (ftp://ftp.uni-mainz.de/pub/internet/security/ssl/SSL)
- SSLeay and SSLapps FAQ (http://www.psy.uq.oz.au/~ftp/Crypto/)
- Brute force SSL cracking
page (http://www.brute.cl.cam.ac.uk/brute/)
Other:
- Shen:
A Security Scheme for the World Wide Web (http://www.pku.edu.cn/on_line/w3html/Shen/ref/shen.html)
- OPIE - One-time
Passwords In Everything (ftp://ftp.nrl.navy.mil/pub/security/opie/)
NCSA WebServer Security:
- Access
control and user authentication (http://hoohoo.ncsa.uiuc.edu/docs/tutorials/user.html)
- Setting
up a secure server (http://hoohoo.ncsa.uiuc.edu/docs/tutorials/security.html)
- Setting
up a chroot server (http://hoohoo.ncsa.uiuc.edu/docs/tutorials/chroot.html)
- NCSA HTTPd 1.6 Beta
-- a security-enhanced server (http://hoohoo.ncsa.uiuc.edu/beta-1.6/)
Security Information:
Authentication:
- SKey - S/Key generated one time passwords to gain authenticated
access to computer hosts. Availability: anonymous ftp at thumper.bellcore.com
(ftp://thumper.bellcore.com/pub/skey/)or coast.cs.purdue.edu
(ftp://coast.cs.purdue.edu/pub/tools/unix/skey/)
- MD5 - MD5 is a hash function using to the authenticity of a
file. Info: RFC
1544 (gopher://ds.internic.net:70/00/rfc/rfc1544.txt), www.rsa.com (http://www.rsa.com)
- RFC 1704:
Internet Authentication (ftp://ftp.eunet.be/pub/documents/rfc/rfc1704.txt)(Eunet)
- How
to set up protection in the CERN Daemon. (http://www.w3.org/AccessAuthorization/CERNServerNutShell.html)
- A Distributed
Authorization Model for WWW (http://www.isoc.org/HMP/PAPER/107/abst.html)by Jose Kahan (INET'95).
WWW General:
- Request for Comments:
2196 (ftp://ftp.internic.net/rfc/rfc2196.txt)- This handbook is a guide to developing computer security policies
and procedures for sites that have systems on the Internet. The purpose
of this handbook is to provide practical guidance to administrators trying
to secure their information and services. The subjects covered include
policy content and formation, a broad range of technical system and network
security topics, and security incident response.
- WWW
Security FAQ (http://www-genome.wi.mit.edu/WWW/faqs/www-security-faq.html)(Lincoln Stein)
- SunWorld's Web
server security (http://www.sun.com/sunworldonline/common/swol-siteindex.html#websec) + Security
(http://www.sun.com/sunworldonline/common/swol-backissues-columns.html#security)
CGI General :
- sbox (http://www.genome.wi.mit.edu/~lstein/sbox/) is a
CGI wrapper script that allows Web site hosting services to safely grant
CGI authoring privileges to untrusted clients. In addition to changing
the process privileges of client scripts to match their owners, it goes
beyond other wrappers by placing configurable ceilings on script resource
usage, avoiding unintentional (as well as intentional) denial of service
attacks. It also optionally allows the Webmaster to place client's CGI
scripts in a chroot'ed shell restricted to the author's home directories.
- NCSA's tips
for Writing Secure CGI Scripts (http://hoohoo.ncsa.uiuc.edu/cgi/security.html)
- Writing
safe CGI scripts -- an overview (http://www.go2net.com/people/paulp/cgi-security/safe-cgi.txt) (Paul Phillips)
- CGI Security
Tutorial (http://www.csclub.uwaterloo.ca/u/mlvanbie/cgisec/)(Michael Van Biesbrouck)
- CGI-Wrap - Secure User Access
to CGI's with httpd (http://wwwcgi.umr.edu/~cgiwrap)- CGIwrap allows more secure user access to CGI's
on NCSA, Cern, Apache, and NetSite web servers.
- CGI
security FAQ (http://www.cerf.net/~paulp/cgi-security/safe-cgi.txt)-
- Using CGI at UMR (http://www.umr.edu:80/~cgiwrap/)- cgiwrap
package to allow any user to run his/her cgi's in secure way
- World Wide
Web Security (http://www-ns.rutgers.edu/www-security/index.html)- This document indexes information on security for the
World Wide Web, HTTP, HTML, and related software/protocols. It is maintained
by Rutgers University Network Services www-security team.
- The
World Wide Web Security FAQ (http://www.genome.wi.mit.edu/WWW/faqs/www-security-faq.html)
Java:
- Applet Security - FAQ (http://java.sun.com/sfaq/)
Perl:
- Latro (http://www.perl.com/perl/news/latro-announce.html),
a tool for identifying insecure Perl CGI installations, by Tom Christiansen
- Perl Security
Announcements (http://www.perl.com/perl/info/security.html)
Web Commerce Sollutions:
- CyberCash-Free
Wallet (http://www.cybercash.com/cybercash/wallet/)
- Digicash (http://digicash.support.nl/)
- First Virtual (http://www.fv.com/)
- Electronic
Commerce (http://www.informatik.uni-hildesheim.de/FB4/Projekte/sirene/outsideworld/ecommerce.html#syst) from Sirene's Pointers
- iWorld's Guide to Electronic
Commerce (http://e-comm.internet.com/)
- W3C Electronic Payments (http://www.w3.org/Payments/)
Books:
- A great
list of books with cover images and links tho their publishers (http://www.cgicon.com/perlbooks.html#WebSecurity) (by
CGI consult)