Security Resources.
* Packet Storm . Packet Storm Security, a huge collection of software, exploit code, and docs.
* SecurityFocus . SecurityFocus web site (the bugtraq, vuln-dev, and pen-test home).
* SecurityDocs . Directory of Security White Papers, an impressive web repository about security.
* CVE Project . The Dictionary of Common Vulnerabilities and Exposures at Mitre.
* Security Tracker . Keep track of the latest vulnerabilities with this free on-line service.
* OSVDB . An independent and open-source vulnerability database created by and for the community.
* Full-Disclosure . A non-moderated full-disclosure mailing list, for discussion of security issues.
* Darklab . The intelligence organization of Phenoelit, with an interesting mailing list.
* Sikurezza.org . The first italian mailing list for discussion on computer security, since year 1999.
* TH-List . This is the official homepage of the Trojan Horses Research mailing list.
* OWASP . The Open Web Application Security Project. Useful information on application security.
* Sarca Project . Sarca Rainbow Tables, instant Windows password cracker web interface.
* Known Goods . Big database of checksums, useful for verification of system binaries.
* Honeynet . Honeynet Project: a non-profit research organization dedicated to information security.
* NSRC . Network Startup Resource Center, securing network services and infrastructure.
* Security Metrics . The official NIST Security Metrics Workshop homepage.
* Login Banners . Detailed guidelines about creating login banners for sensitive computers.
* SANS . Computer security education and information security training.
* Technical Info . Really interesting computer security papers, tools, and publications.
* Googledorks . Noun 1. Slang. An inept or foolish person as revealed by Google. Don't miss it.
* DOTU . Project DOTU, undocumented Cisco IOS commands reference.
* Malware . Malicious software: in-depth information about client applications security flaws.
* Pete Finnigan . Oracle and Oracle security information and free tools/scripts.
* Security.org . Extensive information on the evaluation of physical security systems.
Security Research.
* Phrack Archives . Phrack, the hacker magazine by the community, for the community.
* AT&T labs . AT&T research labs homepage: lots of interesting projects.
* LSD . LSD-PLaNET, the Last Stage of Delirium research group homepage.
* TESO . Homepage of the TESO security group: releases, advisories, articles, and projects.
* THC . The Hacker's Choice official web site: software, papers, and much more.
* Xfocus . Home of the Xfocus team: documents, programs, exploits, advisories, and forums.
* w00w00 . The official homepage of the w00w00 non-profit security research group.
* Phenoelit . Welcome to Phenoelit, the land of packets, brute force, and misuse of trust.
* S0ftpj . The official web site of my friends at S0ftpr0ject (and home of the BFi e-zine).
* The Broken . This is a hacking videozine, a very interesting/artistic project.
* Lcamtuf . Michal Zalewski (lcamtuf) homepage: very interesting research projects.
* Solar Eclipse . Solar's homepage: black hat exploits, documents, and programs.
* Cr.yp.to . D. J. Bernstein's homepage (qmail, djbdns, daemontools, ucspi-tcp, and crypto).
* Index of /~silvio . Silvio Cesare's homepage, about UNIX viruses and more.
* Guninski . Georgi Guninski security research homepage: papers, advisories, and exploits.
* P. Gutmann . Peter Gutmann's homepage, research from a professional paranoid.
* M. Kuhn . Markus Kuhn's homepage (computer security, hardware security, and more).
* P. Biondi . Philippe Biondi's homepage, some interesting documents, program, and hacks.
* L. Spitzner . Lance Spitzner's whitepapers, about honeypots, hardening, and firewalls.
* JWA . An interesting homepage with some old but useful UNIX security tools.
* Antirez . Salvatore Sanfilippo's homepage (home of hping TCP/IP auditing software).
* Awgn . Bonelli Nicola aka awgn (additive white gaussian noise) homepage.
* NMRC . Nomad Mobile Research Centre, the Novell Netware bible and more.
* X.25 zine . Russian X.25 zine, interesting (and almost up-to-date) reading.
* 9x . 9x security group homepage. Interesting old school information.
* Hybrid . Hybrid homepage, useful hacking, phreaking, and old school information.
* Vorper7 . Home of Doberman Propulsion Laboratories, X.25 and old school stuff.
Security Technologies.
* OpenBSD PF . The new OpenBSD Packet Filter official homepage.
* IP Filter . IP Filter, stateful TCP/IP Firewall/NAT Software for UNIX systems.
* VPN HOWTO . VPN implementation details for a large variety of environments.
* IKE + X.509 . How to use X.509v3 certificates for authentication with isakmpd.
* VPN Hacking . Useful compendium of VPN resources for the *BSD environment.
* IPSec HOWTO . How to setup IPSec interoperable for Linux, OpenBSD and PGPNet.
* Windows VPN . Using Windows 2000/XP as a VPN client for Linux FreeS/WAN.
* Snort NIDS . Snort, the open-source Network Intrusion Detection System.
* L7 Filter . Homepage of the Application Layer Packet Classifier kernel patch for Linux.
* Insecure . Nmap free stealth network port scanner, tools, and hacking by Fyodor.
* Openwall . Information Security software for open environments, by Solar Designer.
* Papillon . Security module for Solaris 8 and 9, inspired by Openwall and HAP patches.
* Systrace . Systrace Policy Generation, the main systrace resource on the Internet.
* Djohn . Distributed John can crack passwords using John the Ripper on several machines.
* SELinux . Security-Enhanced Linux, Mandatory Access Control (MAC) from NSA.
* SPIKE . Immunity's network protocol analysis and reverse engineering suite.
* CHAOS . A Linux and openMosix cluster distribution: the supercomputer for your wallet.
* Airtools . BSD-Airtools, a suite of programs for wlan auditing, from dachb0den labs.
* Kismet . Kismet wireless sniffer, one of the best 802.11b auditing tools.
* 802.11ninja . Another 802.11 wlan resource (home of airjack slides/code).
* 802.11 Security . The unofficial IEEE 802.11 security web page. A good start place.
* Securing 802.11 . Securing 802.11 with OpenBSD, an interesting wlan security resource.
* WEP FAQ . (In)Security of the WEP (Wireless Equivalent Privacy) algorithm.
Crypto and Privacy.
* Cryptome . Cryptography and Digital Privacy: the best resource on the Internet.
* Cartome . Spatial and geographic documents on privacy, cryptography, and intelligence.
* IACR . International Association for Cryptologic Research official web site.
* Cypherpunks . Cypherpunks archive at soda.berkeley.edu: PGP, remailers, rants, and tools.
* Cipherwar . Cipherwar information warfare news web site. Interesting stuff.
* Crypto . Matt Blaze's cryptography resource on the web: very interesting papers.
* Riot.EU.org . Riot anonymous remailer and pseudonymous service.
* Rubberhose . A cryptographically deniable transparent encryption system for Linux 2.2.
* PGP Home Site . Pretty Good Privacy (PGP) international homepage.
* GNUPG . The GNU Privacy Guard (a free OpenPGP implementation).
* B. Jenkins . Bob Jenkin's web site, about math and crypto. Very interesting stuff.
* Spylife . Spy equipment: cameras, encryption systems, night vision scopes, and more.
* Spyworld . Another spy and surveillance equipment site: a very rich catalog.
Coding.
* IOCCC . The International Obfuscated C Code Contest homepage. Voodoo magic.
* Perlmonks . Perlmonks homepage: remember that Perl is a religion and check out Perl Poetry.
* Secure Programming . Secure Programming for Linux and UNIX HOWTO (HTML version).
* Insecure Programming . A nice collection of insecure code for didactical purposes, by gera.
* MetaSploit . Win32 shellcode, Perl exploit library (Pex), opcode/jmp/function address search engine.
* Juliano . A good collection of security-related documents, mostly about exploitation techniques.
* 0xbadc0ded . Security research group: advisories, exploits, code, and interesting challenges.
* Intel 80386 . Intel 80386 Programmer's Reference 1986 (complete instruction set).
* Linux ASM . Information on assembly programming under UNIX-like operating systems.
* Int 80h . Extensive information about Assembly language in the UNIX environment.
* NOP list . Canonical list of NOP Equivalent opcodes for shellcodes, used by snort:spp_fnord.c.
* Reversing.net . Very interesting forum (in russian!) for the discussion of reversing-related topics.
* RACL . Reversing and Assembly Coding for Linux, italian Linux ASM resource.
* ELF documentation . Executable and Linkable Format specification (ASCII version).
* GDB . GNU debugger, allows you to see what is going on inside another program while it executes.
* Ctags . Exuberant ctags, an useful multi-language implementation of ctags.
* Cscope . Another tool for browsing source code, developed at Bell Labs and now open-sourced.
* Valgrind . An interesting open-source memory debugger for x86-GNU/Linux.
* The Dude . A debugger which resides in kernel memory and provides an alternative to ptrace(2).
* Bastard . A disassembler -- or, more appropriately, a disassembly environment.
* Boomerang . An attempt at a general, open-source, retargetable decompiler of binary files.
* IDA Pro . A multi-processor, Windows hosted disassembler and debugger.
* Testdrive . Hewlett-Packard Test Drive: try the latest technologies over the Internet.
* CC65 . CC65 is a freeware C compiler for 6502 based systems (Commodore, Apple, Atari).
* QCL . Quantum Computation Language, a programming language for quantum computers.
* Brainfuck . Brainfuck is an 8-instruction Turing-complete programming language.
* TLK . The Linux Kernel, a very well-written document about Linux internals.
Misc.
* The BOFH . The original Bastard Operator From Hell complete, by Simon Travaglia.
* The Register . Biting the hand that feds IT, another juicy BOFH resource.
* The Jargon File . The Jargon File homepage, mantained by Eric S. Raymond.
* UNIX-Haters . UNIX-Haters mailing list and handbook official homepage.
* RFC Editor . RFC (Request For Comments) Editor homepage. The official RFC repository.
* Rotten . ROTTEN DOT COM: when hell is full, the dead will walk on the earth.
* BME . Body Modification E-zine, the biggest and best online bod-mod site since 1994.
* Info Anarchy . Which future do you want to live in? Interesting news for freedom-supporters.
* Suicide Girls . Pin-up punk rock and goth girls: pictures, journals, and videos.
* Philosomatika . 100% goa and psychedelic trance mp3 stream (broadband needed).
* Chaos@UMD . A very interesting homepage about Chaos Theory at Maryland University.
* Fuzzy logic FAQ . Frequently Asked Questions on fuzzy logic and expert systems.
* Deathrow . Beave's OpenVMS cluster (DAHMER, MANSON, and RAMIREZ).
* Textfiles . A glimpse into the history of writers and artists bound by ASCII's 128 chars.
* Fucked Company . Official lubricant of the new economy: rumors and interesting information.
* ASCII pr0n . ASCII pr0n archive, for real last stage maniacs only.
* Hack Furby . Interesting site devoted to investigating the geek-appeal of the Furby toy.
* (C)DNE . Copyright Does Not Exist, a remarkable book written by Linus Walleij.
* TCP/IP drinking . The homepage of the (in)famous TCP/IP drinking game. Try this at home.
* CHSP . The Computer History Simulation Project (the SIMH homepage).
* Internet Archive . The Internet Wayback Machine, universal access to human knowledge.
* Asterisk . An open-source Linux-based PBX (Private Branch eXchange).
* MUSCLE Project . Movement for the Use of Smart Cards in a Linux Environment.
* OpenVMS Documentation . Official OpenVMS Documentation Pages.
Local Stuff.
* Linux Penguin . A cool HTML Linux Penguin (257 x 303 @ 250 colors).
* RTFM . Hey, you! Don't ask stupid questions, always Read The Fucking Manual.
* Utah Bengaled Raptor . An 8 foot tall, 1 ton wooden monster, created by Matt Kron .
* 0xdefaced . 0xdeadbeef dot info defacement hoax for April Fool's Day 2004.