Security Resources. * Packet Storm . Packet Storm Security, a huge collection of software, exploit code, and docs. * SecurityFocus . SecurityFocus web site (the bugtraq, vuln-dev, and pen-test home). * SecurityDocs . Directory of Security White Papers, an impressive web repository about security. * CVE Project . The Dictionary of Common Vulnerabilities and Exposures at Mitre. * Security Tracker . Keep track of the latest vulnerabilities with this free on-line service. * OSVDB . An independent and open-source vulnerability database created by and for the community. * Full-Disclosure . A non-moderated full-disclosure mailing list, for discussion of security issues. * Darklab . The intelligence organization of Phenoelit, with an interesting mailing list. * Sikurezza.org . The first italian mailing list for discussion on computer security, since year 1999. * TH-List . This is the official homepage of the Trojan Horses Research mailing list. * OWASP . The Open Web Application Security Project. Useful information on application security. * Sarca Project . Sarca Rainbow Tables, instant Windows password cracker web interface. * Known Goods . Big database of checksums, useful for verification of system binaries. * Honeynet . Honeynet Project: a non-profit research organization dedicated to information security. * NSRC . Network Startup Resource Center, securing network services and infrastructure. * Security Metrics . The official NIST Security Metrics Workshop homepage. * Login Banners . Detailed guidelines about creating login banners for sensitive computers. * SANS . Computer security education and information security training. * Technical Info . Really interesting computer security papers, tools, and publications. * Googledorks . Noun 1. Slang. An inept or foolish person as revealed by Google. Don't miss it. * DOTU . Project DOTU, undocumented Cisco IOS commands reference. * Malware . Malicious software: in-depth information about client applications security flaws. * Pete Finnigan . Oracle and Oracle security information and free tools/scripts. * Security.org . Extensive information on the evaluation of physical security systems. Security Research. * Phrack Archives . Phrack, the hacker magazine by the community, for the community. * AT&T labs . AT&T research labs homepage: lots of interesting projects. * LSD . LSD-PLaNET, the Last Stage of Delirium research group homepage. * TESO . Homepage of the TESO security group: releases, advisories, articles, and projects. * THC . The Hacker's Choice official web site: software, papers, and much more. * Xfocus . Home of the Xfocus team: documents, programs, exploits, advisories, and forums. * w00w00 . The official homepage of the w00w00 non-profit security research group. * Phenoelit . Welcome to Phenoelit, the land of packets, brute force, and misuse of trust. * S0ftpj . The official web site of my friends at S0ftpr0ject (and home of the BFi e-zine). * The Broken . This is a hacking videozine, a very interesting/artistic project. * Lcamtuf . Michal Zalewski (lcamtuf) homepage: very interesting research projects. * Solar Eclipse . Solar's homepage: black hat exploits, documents, and programs. * Cr.yp.to . D. J. Bernstein's homepage (qmail, djbdns, daemontools, ucspi-tcp, and crypto). * Index of /~silvio . Silvio Cesare's homepage, about UNIX viruses and more. * Guninski . Georgi Guninski security research homepage: papers, advisories, and exploits. * P. Gutmann . Peter Gutmann's homepage, research from a professional paranoid. * M. Kuhn . Markus Kuhn's homepage (computer security, hardware security, and more). * P. Biondi . Philippe Biondi's homepage, some interesting documents, program, and hacks. * L. Spitzner . Lance Spitzner's whitepapers, about honeypots, hardening, and firewalls. * JWA . An interesting homepage with some old but useful UNIX security tools. * Antirez . Salvatore Sanfilippo's homepage (home of hping TCP/IP auditing software). * Awgn . Bonelli Nicola aka awgn (additive white gaussian noise) homepage. * NMRC . Nomad Mobile Research Centre, the Novell Netware bible and more. * X.25 zine . Russian X.25 zine, interesting (and almost up-to-date) reading. * 9x . 9x security group homepage. Interesting old school information. * Hybrid . Hybrid homepage, useful hacking, phreaking, and old school information. * Vorper7 . Home of Doberman Propulsion Laboratories, X.25 and old school stuff. Security Technologies. * OpenBSD PF . The new OpenBSD Packet Filter official homepage. * IP Filter . IP Filter, stateful TCP/IP Firewall/NAT Software for UNIX systems. * VPN HOWTO . VPN implementation details for a large variety of environments. * IKE + X.509 . How to use X.509v3 certificates for authentication with isakmpd. * VPN Hacking . Useful compendium of VPN resources for the *BSD environment. * IPSec HOWTO . How to setup IPSec interoperable for Linux, OpenBSD and PGPNet. * Windows VPN . Using Windows 2000/XP as a VPN client for Linux FreeS/WAN. * Snort NIDS . Snort, the open-source Network Intrusion Detection System. * L7 Filter . Homepage of the Application Layer Packet Classifier kernel patch for Linux. * Insecure . Nmap free stealth network port scanner, tools, and hacking by Fyodor. * Openwall . Information Security software for open environments, by Solar Designer. * Papillon . Security module for Solaris 8 and 9, inspired by Openwall and HAP patches. * Systrace . Systrace Policy Generation, the main systrace resource on the Internet. * Djohn . Distributed John can crack passwords using John the Ripper on several machines. * SELinux . Security-Enhanced Linux, Mandatory Access Control (MAC) from NSA. * SPIKE . Immunity's network protocol analysis and reverse engineering suite. * CHAOS . A Linux and openMosix cluster distribution: the supercomputer for your wallet. * Airtools . BSD-Airtools, a suite of programs for wlan auditing, from dachb0den labs. * Kismet . Kismet wireless sniffer, one of the best 802.11b auditing tools. * 802.11ninja . Another 802.11 wlan resource (home of airjack slides/code). * 802.11 Security . The unofficial IEEE 802.11 security web page. A good start place. * Securing 802.11 . Securing 802.11 with OpenBSD, an interesting wlan security resource. * WEP FAQ . (In)Security of the WEP (Wireless Equivalent Privacy) algorithm. Crypto and Privacy. * Cryptome . Cryptography and Digital Privacy: the best resource on the Internet. * Cartome . Spatial and geographic documents on privacy, cryptography, and intelligence. * IACR . International Association for Cryptologic Research official web site. * Cypherpunks . Cypherpunks archive at soda.berkeley.edu: PGP, remailers, rants, and tools. * Cipherwar . Cipherwar information warfare news web site. Interesting stuff. * Crypto . Matt Blaze's cryptography resource on the web: very interesting papers. * Riot.EU.org . Riot anonymous remailer and pseudonymous service. * Rubberhose . A cryptographically deniable transparent encryption system for Linux 2.2. * PGP Home Site . Pretty Good Privacy (PGP) international homepage. * GNUPG . The GNU Privacy Guard (a free OpenPGP implementation). * B. Jenkins . Bob Jenkin's web site, about math and crypto. Very interesting stuff. * Spylife . Spy equipment: cameras, encryption systems, night vision scopes, and more. * Spyworld . Another spy and surveillance equipment site: a very rich catalog. Coding. * IOCCC . The International Obfuscated C Code Contest homepage. Voodoo magic. * Perlmonks . Perlmonks homepage: remember that Perl is a religion and check out Perl Poetry. * Secure Programming . Secure Programming for Linux and UNIX HOWTO (HTML version). * Insecure Programming . A nice collection of insecure code for didactical purposes, by gera. * MetaSploit . Win32 shellcode, Perl exploit library (Pex), opcode/jmp/function address search engine. * Juliano . A good collection of security-related documents, mostly about exploitation techniques. * 0xbadc0ded . Security research group: advisories, exploits, code, and interesting challenges. * Intel 80386 . Intel 80386 Programmer's Reference 1986 (complete instruction set). * Linux ASM . Information on assembly programming under UNIX-like operating systems. * Int 80h . Extensive information about Assembly language in the UNIX environment. * NOP list . Canonical list of NOP Equivalent opcodes for shellcodes, used by snort:spp_fnord.c. * Reversing.net . Very interesting forum (in russian!) for the discussion of reversing-related topics. * RACL . Reversing and Assembly Coding for Linux, italian Linux ASM resource. * ELF documentation . Executable and Linkable Format specification (ASCII version). * GDB . GNU debugger, allows you to see what is going on inside another program while it executes. * Ctags . Exuberant ctags, an useful multi-language implementation of ctags. * Cscope . Another tool for browsing source code, developed at Bell Labs and now open-sourced. * Valgrind . An interesting open-source memory debugger for x86-GNU/Linux. * The Dude . A debugger which resides in kernel memory and provides an alternative to ptrace(2). * Bastard . A disassembler -- or, more appropriately, a disassembly environment. * Boomerang . An attempt at a general, open-source, retargetable decompiler of binary files. * IDA Pro . A multi-processor, Windows hosted disassembler and debugger. * Testdrive . Hewlett-Packard Test Drive: try the latest technologies over the Internet. * CC65 . CC65 is a freeware C compiler for 6502 based systems (Commodore, Apple, Atari). * QCL . Quantum Computation Language, a programming language for quantum computers. * Brainfuck . Brainfuck is an 8-instruction Turing-complete programming language. * TLK . The Linux Kernel, a very well-written document about Linux internals. Misc. * The BOFH . The original Bastard Operator From Hell complete, by Simon Travaglia. * The Register . Biting the hand that feds IT, another juicy BOFH resource. * The Jargon File . The Jargon File homepage, mantained by Eric S. Raymond. * UNIX-Haters . UNIX-Haters mailing list and handbook official homepage. * RFC Editor . RFC (Request For Comments) Editor homepage. The official RFC repository. * Rotten . ROTTEN DOT COM: when hell is full, the dead will walk on the earth. * BME . Body Modification E-zine, the biggest and best online bod-mod site since 1994. * Info Anarchy . Which future do you want to live in? Interesting news for freedom-supporters. * Suicide Girls . Pin-up punk rock and goth girls: pictures, journals, and videos. * Philosomatika . 100% goa and psychedelic trance mp3 stream (broadband needed). * Chaos@UMD . A very interesting homepage about Chaos Theory at Maryland University. * Fuzzy logic FAQ . Frequently Asked Questions on fuzzy logic and expert systems. * Deathrow . Beave's OpenVMS cluster (DAHMER, MANSON, and RAMIREZ). * Textfiles . A glimpse into the history of writers and artists bound by ASCII's 128 chars. * Fucked Company . Official lubricant of the new economy: rumors and interesting information. * ASCII pr0n . ASCII pr0n archive, for real last stage maniacs only. * Hack Furby . Interesting site devoted to investigating the geek-appeal of the Furby toy. * (C)DNE . Copyright Does Not Exist, a remarkable book written by Linus Walleij. * TCP/IP drinking . The homepage of the (in)famous TCP/IP drinking game. Try this at home. * CHSP . The Computer History Simulation Project (the SIMH homepage). * Internet Archive . The Internet Wayback Machine, universal access to human knowledge. * Asterisk . An open-source Linux-based PBX (Private Branch eXchange). * MUSCLE Project . Movement for the Use of Smart Cards in a Linux Environment. * OpenVMS Documentation . Official OpenVMS Documentation Pages. Local Stuff. * Linux Penguin . A cool HTML Linux Penguin (257 x 303 @ 250 colors). * RTFM . Hey, you! Don't ask stupid questions, always Read The Fucking Manual. * Utah Bengaled Raptor . An 8 foot tall, 1 ton wooden monster, created by Matt Kron . * 0xdefaced . 0xdeadbeef dot info defacement hoax for April Fool's Day 2004.