mirror of
https://github.com/whoisdsmith/BOOKMRKS-MTHRFCKR.git
synced 2025-04-29 14:14:37 +02:00
201 lines
14 KiB
Markdown
201 lines
14 KiB
Markdown
---
|
|
title: Security
|
|
sidebar_label: Security
|
|
---
|
|
|
|
## Secure Messenger
|
|
|
|
- [Signal](http://signal.org/)
|
|
- [Briar](http://briarproject.org/)
|
|
- [Riot](http://matrix.org/blog/home/)
|
|
- [Threema](http://threema.ch/en)
|
|
- [Wire](http://wire.com/)
|
|
|
|
## Password Managers
|
|
|
|
:::caution
|
|
|
|
[LastPass security issues](https://en.wikipedia.org/wiki/LastPass#Security_issues) - Wikipedia
|
|
|
|
:::
|
|
|
|
- [Wikipedia's list of Password Managers](http://en.wikipedia.org/wiki/List_of_password_managers) - Overview of all password manager utilities.
|
|
- [BitWarden](https://bitwarden.com/) - Open source password management solution, can be self-hosted.
|
|
- [KeePassXC](https://keepassxc.org/) - KeePassXC is a community fork of KeePassX, a native cross-platform port of KeePass Password Safe.
|
|
- [LessPass](https://lesspass.com/) - Stateless open source password manager.
|
|
- [1Password](https://1password.com/) - Popular cloud-hosted password manager.
|
|
- [KeePass](https://keepass.info/) - Free, open source, light-weight, and easy-to-use password manager.
|
|
- [Plugins](https://keepass.info/plugins.html) - A list of third-party plugins for KeePass.
|
|
- [Keepass2Android](https://github.com/PhilippC/keepass2android) - A Password manager app for Android based on Keepass.
|
|
- [KeePassium](https://keepassium.com/) - KeePassium combines the security of KeePass with a clean intuitive design.
|
|
- [KeeWeb](https://keeweb.info/) - Free cross-platform password manager compatible with KeePass.
|
|
- [Pass](https://www.passwordstore.org/) - Simple GPG/Git password manager. Follows the Unix philosophy.
|
|
- [Dashlane](https://www.dashlane.com/) - An intuitive password manager with over with over 8 million users worldwide.
|
|
- [Passbolt](https://www.passbolt.com/) - Free, open source, self-hosted, extensible, OpenPGP based.
|
|
- [Psono](https://psono.com/) - Open source and self-hosted password manager for teams.
|
|
- [Buttercup](https://buttercup.pw/) - Another open source password manager with desktop, mobile, and browser clients.
|
|
- [MiniKeePass](https://minikeepass.github.io/) - iOS version of KeePass (_unofficial_).
|
|
- [KeeVault](http://keevault.pm/) - Secure, Open Source Password Management.
|
|
- [LastPass (Last Choice)](https://www.lastpass.com/) - LastPass remembers all your passwords, so you don't have to.
|
|
|
|
## Alternate Networks
|
|
|
|
- [I2P](https://geti2p.net/en/) - I2P is an anonymous overlay network - a network within a network. It is intended to protect communication from dragnet surveillance and monitoring by third parties such as ISPs.
|
|
- [ANONYMOUS TORRENTING WITH I2P-SNARK: USING SNARK](https://privacytutorials.wordpress.com/2015/01/05/anonymous-torrenting-with-i2p-snark-using-snark/)
|
|
- [Zeronet](https://zeronet.io/) - Open, free and uncensorable websites, using Bitcoin cryptography and BitTorrent network.
|
|
- [Loki](https://github.com/loki-project/loki-network) - Lokinet is an anonymous, decentralized and IP based overlay network for the internet.
|
|
- [SILO](https://medium.com/arweave-updates/building-silo-a-truly-private-internet-556c860222ca) - Offers complete privacy across the network (work in progress project in cooperationship with Loki).
|
|
- [IPFS](https://ipfs.io/) - A peer-to-peer hypermedia protocol designed to make the web faster, safer, and more open.
|
|
- [Yggdrasil](https://yggdrasil-network.github.io/about.html) - Makes use of a global spanning tree to form a scalable IPv6 encrypted mesh network.
|
|
- [cjdns](https://github.com/cjdelisle/cjdns) - Cjdns (Caleb James DeLisle's Network Suite) - is a networking protocol and reference implementation, founded on the ideology that networks should be easy to set up.
|
|
- [Freenet](https://freenetproject.org/) - Freenet is free software which lets you anonymously share files, browse and publish "freesites" (web sites accessible only through Freenet) - and chat on forums, without fear of censorship.
|
|
- [GnUNet](https://gnunet.org/) - GNUnet is a framework for secure peer-to-peer networking that does not use any centralized or otherwise trusted services.
|
|
- [Psiphon](https://www.psiphon.ca/) - Run your own server, invite your friends, build a community, provide free and unfiltered Internet access to the world.
|
|
- [Scuttlebutt](https://www.scuttlebutt.nz/) - A decentralised secure gossip platform that aims to harmonize four perspectives of life: Environment reflecting Technology reflecting Community reflecting Society.
|
|
|
|
### Tor
|
|
|
|
- [Tor](https://www.torproject.org/) - Tor is free software and an open network that helps you defend against traffic analysis.
|
|
|
|
:::caution
|
|
|
|
I'm not responsible for the links, domains, it's content or if the provided `.onion` links are really the ones advertised. It's impossible for me as individual person to check every single page every second and monitor it's content.
|
|
|
|
Also be very carefull of scams. you can find the links to some scam sites on [`torss7t3bxd3qsxn.onion`](http://torss7t3bxd3qsxn.onion/)
|
|
|
|
:::
|
|
|
|
:::note Something to consider
|
|
|
|
[Judge Recommends to Deny Summary Judgment Against Tor Exit Node Operator in Piracy Case](https://torrentfreak.com/judge-recommends-to-deny-summary-judgment-against-tor-exit-node-operator-in-piracy-case-190907/) - TorrentFreak
|
|
|
|
:::
|
|
|
|
:::caution
|
|
|
|
[Bittorrent over Tor isn't a good idea](https://blog.torproject.org/bittorrent-over-tor-isnt-good-idea) - Tor Blog
|
|
|
|
:::
|
|
|
|
:::info
|
|
If you suspect your access to the Tor network is being blocked, you may want to use bridges.
|
|
|
|
You can get latest Tor bridges from [bridges.torproject.org](https://bridges.torproject.org/)
|
|
|
|
:::
|
|
|
|
:::tip
|
|
|
|
Just replace .onion with .onion.ws or any other domain made available by volounteers [Tor2web](https://www.tor2web.org/) operators.
|
|
|
|
Example: `http://archivecaslytosk.onion/ => http://archivecaslytosk.onion.ws/`
|
|
|
|
This connects you with Tor2web, which then talks to the onion service via Tor and relays the response back to you.
|
|
|
|
**WARNING**: Tor2web only protects publishers, _not readers_. As a reader installing Tor Browser will give you much greater anonymity than using Tor2web. Using Tor2web trades off security for convenience and usability.
|
|
|
|
:::
|
|
|
|
#### Web Archive
|
|
|
|
- [🧅 Archive Today](http://archivecaslytosk.onion/) |
|
|
- [🧅 Internet Archive](http://archivebyd3rzt3ehjpm4c3bjkyxv3hjleiytnvxcn7x32psn2kxcuid.onion/)
|
|
|
|
#### Misc
|
|
|
|
- [🧅 The Hidden Wiki](http://zqktlwi4fecvo6ri.onion/)
|
|
- [🧅 Is it up?](http://nlmymchrmnlmbnii.onion/)
|
|
- [🧅 Anonet Webproxy](http://xdagknwjc7aaytzh.onion/)
|
|
- [🧅 Gateway to Freenet](http://2vlqpcqpjlhmd5r2.onion/)
|
|
- [🧅 Tor links](http://torlinkbgs6aabns.onion/)
|
|
|
|
### P2P Networks
|
|
|
|
- [eDonkey network](https://en.wikipedia.org/wiki/EDonkey_network) - A decentralized, mostly server-based, peer-to-peer file-sharing network.
|
|
- [Gnutella](https://en.wikipedia.org/wiki/Gnutella) - P2P network behind the popular LimeWire file sharing app.
|
|
- [FastTrack](https://en.wikipedia.org/wiki/FastTrack) - Protocol used by the Kazaa, Grokster, iMesh, and Morpheus file-sharing programs.
|
|
- [Napster](https://en.wikipedia.org/wiki/Napster) - Peer-to-peer file sharing Internet service that emphasized sharing digital audio files, typically audio songs, encoded in MP3 format.
|
|
- [IPFS - Distributed Web](https://en.wikipedia.org/wiki/InterPlanetary_File_System) - Peer-to-peer distributed file system that seeks to connect all computing devices with the same system of files.
|
|
- [Kad](https://en.wikipedia.org/wiki/Kad_network) - The Kad network is a peer-to-peer (P2P) - network that implements the Kademlia P2P overlay protocol.
|
|
|
|
## Router Firewalls
|
|
|
|
- [OpenWRT](https://openwrt.org/) - The OpenWrt Project is a Linux operating system targeting embedded devices.
|
|
- [VyOS.io](https://www.vyos.io/) - VyOS is a Linux-based network operating system that provides software-based network routing, firewall, and VPN functionality.
|
|
- [GufW](http://gufw.org/)
|
|
- [FlatPak](https://www.flatpak.org/)
|
|
- [IPFire](https://www.ipfire.org)
|
|
- [Endian Firewall](https://www.endian.com)
|
|
- [pfSense](https://www.pfsense.org)
|
|
- [LibreCMC](https://librecmc.org/)
|
|
- [Opensense](https://opnsense.org)
|
|
- [gl-inet](https://www.gl-inet.com/)
|
|
|
|
## Antivirus
|
|
|
|
:::tip Overall Strategy
|
|
|
|
- Diversify your analysis approach.
|
|
- Don't rely on the results from a single tool.
|
|
- Run everything with as few privileges as necessary.
|
|
- APT investigations must be seperated from commodity malware, otherwise you give malware authors "ideas".
|
|
- Treat everything like it could be malicious until you have enough evidence to suggest otherwise.
|
|
|
|
:::
|
|
|
|
- ⭐ [Awesome Malware Analysis](https://github.com/rshipp/awesome-malware-analysis) - Malware analysis tools / resources
|
|
- ⭐ [How to Avoid Malware Guide](https://www.reddit.com/r/Piracy/wiki/browsing_and_downloading_guide)
|
|
- ⭐ [Malwarebytes](https://www.malwarebytes.com/), [IOBit](https://www.iobit.com/en/malware-fighter.php) or [Immunet](https://www.immunet.com) - Anti-Malware / Antivirus
|
|
- ⭐ [AdwCleaner](https://www.malwarebytes.com/adwcleaner/) or [Ultra Adware Killer](https://www.carifred.com/ultra_adware_killer/) - Anti-Adware
|
|
- ⭐ [VirusTotal](https://www.virustotal.com/)\*\*, [VirSCAN](https://www.virscan.org/), [BitBaan](https://lab.bitbaan.com/en/home), [Joe Sandbox](https://www.joesandbox.com/), [MetaDefender](https://metadefender.opswat.com/?lang=en) or [Jotti](https://virusscan.jotti.org/en) - Analyze suspicious files / URLs / [Telegram Bot](https://t.me/virus_total_scan_bot) / [Uploader](https://github.com/SamuelTulach/VirusTotalUploader)
|
|
- ⭐ [URL Void](https://www.urlvoid.com/), [ThreatStop](https://threatstop.com/checkip), [Scamadviser](https://www.scamadviser.com/), [SiteSheck](https://sitecheck.sucuri.net/), [IsLegitSite](https://www.islegitsite.com/) or [Google Safe Browsing](https://transparencyreport.google.com/safe-browsing/search) - Check Site Legitimacy
|
|
- [Antivirus Kaspersky Cloud](https://usa.kaspersky.com/free-cloud-antivirus) or [Adaware Antivirus](https://www.adaware.com/free-antivirus-download) - Antivirus
|
|
- [MCShield](https://www.mcshield.net/) - Removable Drive Antivirus
|
|
- [Should I Remove It?](https://www.shouldiremoveit.com/) - Easily Find & Remove Adware, Spyware ect.
|
|
- [Wise Anti-Malware](https://www.wisecleaner.com/wise-anti-malware.html) - Anti-Malware
|
|
- [Rewind](https://github.com/Neo23x0/Rewind) - Immediate Virus Infection Counter Measures
|
|
- [Spybot](https://www.safer-networking.org/products/spybot-free-edition/) or [SUPERAntiSpyware](https://www.superantispyware.com/free-edition.html) - Anti-spyware
|
|
- [LMT Anti-Logger](https://leminhthanh.me/antilogger/) - Anti-Loggers (e.g. Keyloggers)
|
|
- [VT4Browsers](https://support.virustotal.com/hc/en-us/articles/115002700745-Browser-Extensions) - Easily Scan Downloads
|
|
- [Cuckoo](https://cuckoosandbox.org/) - Malware Analysis Tool
|
|
- [WireShark](https://www.wireshark.org/) - Network Protocol Analyzer
|
|
- [PacketTotal](https://packettotal.com/) - PCAP / Network Analysis
|
|
- [should-i-trust](https://github.com/ericalexanderorg/should-i-trust) - Evaluates OSINT Signals for a Domain
|
|
- [Phish.ly](https://phish.ly/) - Scan Suspicious Emails
|
|
- [Amnpardaz](https://jevereg.amnpardaz.com/) - Scan EXE Files
|
|
- [testsafebrowsing](https://testsafebrowsing.appspot.com/) - Safe Browsing Testing Links
|
|
- [QuickSand](https://quicksand.io/) - PDF / Document Malware Scanner
|
|
- [Dangerzone](https://dangerzone.rocks/) - Convert dangerous PDF to safe PDF
|
|
- [ThreatMap](https://threatmap.checkpoint.com/) - Live Malware Distribution Map
|
|
- [Web Of Trust](https://www.mywot.com/) - Check Website Safety
|
|
- [Virus Checker](https://add0n.com/virus-checker.html) - Virus Check for Downloads
|
|
- [Malware Search+++](https://addons.mozilla.org/en-US/firefox/addon/malware-search-plusplusplus/) - Malware Search Extension
|
|
- [Malware Analysis Search](https://cse.google.com/cse?cx=011750002002865445766%3Apc60zx1rliu)
|
|
- [VirusShare](https://virusshare.com/) - Search / Share Malware Samples
|
|
- [SigThief](https://github.com/secretsquirrel/SigThief) - Signature Test
|
|
- [Awesome Penetration Testing](https://github.com/enaqx/awesome-pentest) - Penetration Testing Index
|
|
- [ClamAV](https://www.clamav.net/) - An open source antivirus engine for detecting trojans, viruses, malware & other malicious threats.
|
|
|
|
### VirusTotal alternatives
|
|
|
|
- [Any-Run](https://any.run/) - Run files in a sandbox.
|
|
- [Thread Minder](https://www.threatminer.com/) - Allow analysts to find additional information on indicators of compromise (IOC) - such as domain names, IP's and more.
|
|
- [ThreatCrowd](https://www.threatcrowd.com/) - Search engine for threats, show correlations of submitted entries eg IP, hashes, domains etc.
|
|
- [URLScan](https://urlscan.io/) - Check the website.
|
|
- [Sooty](https://github.com/TheresAFewConors/Sooty) - SOC Analyst Tool.
|
|
- [Hybrid-Analysis](https://www.hybrid-analysis.com/) - [alternative](https://app.sndbox.com/) - The free version is normally good enough.
|
|
|
|
## Virtualisation
|
|
|
|
- [FireJail](http://firejail.wordpress.com/) - Firejail is a SUID program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf.
|
|
- [FlatPak](http://flatpak.org/getting) - Standalone apps for Linux are here!
|
|
- [KVM](http://www.linux-kvm.org/page/Main_Page) - KVM (for Kernel-based Virtual Machine) - is a full virtualization solution for Linux on x86 hardware containing virtualization extensions (Intel VT or AMD-V).
|
|
- [Sandboxie](http://www.sandboxie.com/) - Install and run programs in a virtual sandbox (software based) - environment without writing to the hard drive itself.
|
|
- [Virtualbox](http://www.virtualbox.org/wiki/Downloads) - VirtualBox is a general-purpose full virtualizer for x86 hardware, targeted at server, desktop and embedded use.
|
|
- [VMWare](https://www.vmware.com/en.html) - (paid) - Closed source, but maybe the most reliable and used program for creating/booting up a virtual machine.
|
|
|
|
## Checksum verification
|
|
|
|
- [OpenHashTab](https://github.com/namazso/OpenHashTab) - File hashing shell extension for Windows.
|
|
- [GtkHash](https://github.com/tristanheaven/gtkhash) - A cross-platform desktop utility for computing message digests or checksums.
|