Local Area Security Linux 0.4a
Anonymous Coward writes "Local Area Security Linux is a small 'live CD' distribution based on Knoppix that aims at being less than 185MB so it will fit on a MiniCD. It is now 107MB with FluxBox as the window manager. It contains about 100 security (forensics, penetration testing, firewall, intrusion detection, etc.) tools including Ethereal and Nessus. See a screenshot here."
And at the end of this article...
>Note: The information transmitted in this Notice is intended only for the
>person or entity to which it is addressed and may contain confidential
>and/or privileged material. Any review, reproduction, retransmission,
>dissemination or other use of, or taking of any action in reliance upon,
>this information by persons or entities other than the intended recipient
>is prohibited. If you received this in error, please contact the sender
>and delete the material from all computers.
BWAHAHAHA!
FIRST POST
of PoOpNoOdLe STRENGTH!
yes yes no no asdf
'Nuff said already.
Anyone have linux formatted for my vic20.. I like the computer and i use it every day.. I want to get a distrabution that will fit on the vic 20 tape.. I feel my vic20 computer is the most safe of the market for hackers and such.. I am running windows xp on it at the moment.. Anyone help me?
You jewish sand-fags never learn.
Enjoy!
So is this a security or hacking cd? Seems like some good tools to me.
Can you ping me now?... Good!
How do you deal with the weekly Nessus plugin updates? Do you have to d/l and burn a new disk every week or two?
Sounds like futuristic porno rather than Unix security.
Sorry. That was not funny and clearly off-topic. Mod me down :-(
I dont know it realy looks like a toy to throw in and boot up some lab machine without leaving many traces. Most people I can think that need this allready have linux on a laptop for this function or are running windows equivialants.
Maybe it's a good giveaway for consultants to throw a little knoledge at the clients let them get scared and then do a real audit?
No sir I dont like it.
plz $t0p m0dd1ng |>0\/\/n 0u12 7r011s $0 f4$7
...All on 1 miniCD. That sounds very convenient.
I request that the next feature to develop is an option where you just wave or shake the miniCD at the computer to remedy any problems. This would alleviate the hassle of putting the miniCD into the tray and running it.
I am a big fan of easy to use diagnostics/repair utilities. This sounds very good, and with just this one final tweaking, I think it will be perfect.
Slashdot Syndrome: the sudden, extreme urge to correct someone in order to validate one's self.
Now, how many tools like this do you see for a windows, or any closed source environment. Its tools like these that keep linux away from crap like this balster worm. Linux isn't perfect, but it learns from its mistakes, thats what makes it superior to and closed source software
-=You might be a geek if your computer is worth more than your car=-
Live CDs like knoppix are all very lovely but when's the day that I can roll out my own live CDs without TOO much effort? Just select the packages you want, kernel, drivers, etc, wait as the program churns out a nice ISO for you which you can burn to a CD and voila, insta-Linux! Now that would seriously rock as you can simply modify all the basics as you see fit and can easily alter the whole deal for bugfixes.
Hate me!
We need a modification of the robots.txt file standards to indicate that major pages like slashdot should not link here.
Knoppix-STD has been out for over 2 months. Lame.
Overall, this is a great new window manager, that will perform well on lower end machines.
::::: New Mirrors Added! :::::
N .i so -The Netherlands
4 a_ MAIN.iso -India/Asian Pacific
A IN .iso -USA
3 b. iso
s o
S ER V.iso
3 b_ SECSERV.iso
E CS ERV.iso
L.A.S. 0.4a Main with FluxBox MD5: 0939d7294035b5246bedbce1085bb1e1
http://lightning.chem.tue.nl/las/l.a.s_0.4a_MAI
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.4a_M
L.A.S. 0.3b Main MD5: f47150d2458c78169a65458bcf8ebf96
http://lightning.chem.tue.nl/las/l.a.s_0.3b.iso
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.3b.i
L.A.S. 0.3b SECSERV MD5: ff412734492e39d1d084ced556a47493
http://lightning.chem.tue.nl/las/l.a.s_0.3b_SEC
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.3b_S
I'm getting to really love these things. If it's got ssh, scp, ethereal, port scanner, and a few other goodies, this thing's gonna rock.
Karma: Chameleon (mostly due to the fact that you come and go).
I thought I was the only one who still had one of those laying around. ;) Nice computer...when I was 8.
-Looking for a job as a materials chemist or multivariat
I have a script on my box that puts the eth0 interface down and back up every 3 minutes to break the connection of any evil pirate who might haNO CARRIER
"A door is what a dog is perpetually on the wrong side of" - Ogden Nash
What happened to Jon Katz? Slashdot should do an interview with him.
DO NOT CLICK ON THAT LINK!
...wish mods would check the urls before moderating...
How about an version that you can (easily) put on an USB flash memory card and boot from there?
This sounds a LOT like F.I.R.E. (http://fire.dmzs.com) which I've found to be extremely useful, and highly recommend for forensics, pen testing, and other practical security efforts.
I've been wondering about this as well. I would like to see an online generic kernel/package distributor offer a system where I could select, say from a series of menus, the packages I would like (possibly with custom tweaks) and have an iso/s generated just for me to download. The processor and bandwidth requirements of this pipedream are probably too cost prohibitive right now for a free system. If you would like to see a demo of a similar system (for graphics rendering) check out cooltext.com.
Why did they choose MS win95 default aqua as a background color? BLUUUAAAAAHHHHHHHH!!!!!!!
In the real world, you don't always have permission to take a box down to perform forensics. Rebooting == downtime. Booting into Linux from a CD to inspect == downtime. When you *are* granted permission to take down a box for forensics analysis (you have to get permission in a search warrant for this, or permission from the company that wants you to investigate, but this is rarely feasable), you'll probably be working for a large firm that can afford forensics tools that cost tons of cash and do much more advanced forensics analysis than the forensics software for Linux.
This sounds more like another goodies CD for people to mess around with at school. Or perhaps something to give people Linux demos with. Who knows. I wouldn't market it as a forensics tool, though.
www.sitetronics.com/wordpress
Yet Another D??? Linux Distro....
Haven't we already got enough?
And what is this Coroner's toolkit thingy? Something for the morgue? What does it have to do with Linux?
And forget this Lazarus thingy-- if you want religion, get Jesux.
Oh, and more more thing. My pen writes fine. No need to test it.
(for the humor impaired-- if you didn't get it, forget it)
LedgerSMB: Open source Accounting/ERP
they may be secure but it seems they weren't ready for /. - can't resolve already :S
I've left to find myself. If you happen to see me, please, keep me there until I return.
Well, as I see it, with Knoppix (and derivatives) you get almost everything you need. If not you can always apt-get what you need as it's based on Debian. Not exactly what you want, but it's easily customizable from this viewpoint.
zWhat would an EWOULDBLOCK block, if an EWOULDBLOCK could block would? -- me
I always save my last mod point to mod up a good troll. You people are too serious.
(formerly the unknown oil for babies effort) into won post.
responding to the rumour that some of our attention spans are limitdead buy endless corepirate nazi hypenosys.
you can anticipate all you want. our advise is to be as far away from the walking dead contingent as possible, when the big flash occurs. you wouldn't want to get any of that evile on you.
as to the free unlimited energy plan, as the lights come up, more&more folks will stop being misled into sucking up more&more of the infant killing barrolls of crudeness, & learn that it's more than ok to use newclear power generated by natural (hydro, solar, etc...)methods. of course more information about not wasting anything/behaving less frivolously is bound to show up, here&there.
cyphering how many babies it costs for a barroll of crudeness, we've decided to cut back, a lot, on wasteful things like giving monIE to felons, to help them destroy the planet/population.
no matter. the #1 task is planet/population rescue. the lights are coming up. we're in crisis mode. you can help.
the unlimited power (such as has never been seen before) is freely available to all, with the possible exception of the aforementioned walking dead.
consult with/trust in yOUR creator. more breathing. vote with yOUR wallet. seek others of non-aggressive intentions/behaviours. that's the spirit, moving you.
pay no heed/monIE to the greed/fear based walking dead.
each harmed innocent carries with it a bad toll. it will be repaid by you/us. the Godless felons will not be available to make reparations.
pay attention. that's definitely affordable, plus you might develop skills which could prevent you from being misled any further by phonIE ?pr? ?firm? generated misinformation.
good work so far. there's still much to be done. see you there. tell 'em robbIE.
the rest of the wwworld is laughing/crying at/for US in sympathy/disgust, as we fall/jump into the daze of the georgewellian corepirate nazi life0cide, whilst criticizing their ip gangsters, which are also members of the walking dead.
as for va lairIE's patentdead PostBlock(tm) devise, a 'product' of the SourceForgerIE(tm) hedgemonIE no DOWt, it just doesn't work.
Someone earlier said companies cannot afford downtime. True but in most corporate enviroments there are plenty of boxes to take over the job of the hacked box most times and in the event that there's no backup most serious hackings will require the downtime anyways to investigate and fix the issue.
Can you imagine if a credit card database was hacked and they said just bring it back up?
Click here for more info about this fascinating topic. I think it could help the pro-MS crowd go a long way to understanding why we Linuxers think they are evil.
A few days after Christmas, a mother working in the kitchen was listening to her son playing with his new electric train in the living room. She heard the train stop and her son said, "All of you sons of bitches who want off, get the hell off now, 'cause this is the last stop...and all of you sons of bitches who are gettin' on, get your asses in the train, 'cause we're leaving!"
The mother went in and told her son, "We don't use that kind of language in this house. Now I want you to go to your room for two hours. When you come out, you may play with your train. But I want you to use nicer language. Two hours later, her son came out of the bedroom and resumed playing with his train. Soon the train stopped and the mother heard her son say, "All passengers who are disembarking the train, please remember to take all of your belongings with you. We thank you for riding with us today and hope that you will ride with us again soon.
For those of you just boarding, we ask that you stow all of your hand luggage under your seat. Remember that there is no smoking except in the club car. We hope that you will all have a pleasant and relaxing journey with us today. For those of you who are pissed off because of the two hour delay, please see the bitch in the kitchen."
Yeah, so I don't own a Powerbook, but does anyone really use mini-CDs?
I knew Linux could do a lot of things, but I never would have thought it could replace women.
5...4...3...2...1...
SCO has just accused them of patent infringement.
It seems our host in Argentina didn't like all the bandwidth we were using even though we get 20GB a month not including ftp traffic. If anyone wants to donate some hosting we'd appreciate it. . .
-J-
was when I clicked on the link to the screenshot only to be presented with a 444 error:
"You do not have permission to access the requested file on this server."
Wow, when it comes to security, these folks aren't kidding around! It's so secure, you can't even look at the images it serves! Now THAT'S tight!
Newer mini-CDs now fit up to 210Meg, FYI.
And they have R/W versions, as well. Nifty!
I always thought something like these would make great floppy replacements, but it looks like USB flash drives are gonna do that first. That's OK - solid state storage rawks, and their capacity is already well over that of even the 210Meg CD-R(/W) mini-CDs.
Here's to hoping they come out with FireWire '2' (IEEE1394.b) flash drives! *cheers*
You should be able to customize what is on the knoppix cd fairly easy already. If you look at the Knoppix cheatcodes, for manipulating hardware detection, there is a note in there about remastering the cd:
:)
If you wish to remaster the CD, please don't forget to specify
-b KNOPPIX/boot.img
for the german version of the bootfloppy, or
-b KNOPPIX/boot-en.img
for the english version, as option to mkisofs. Otherwise your CD
won't be bootable. The directory KNOPPIX, containig the compressed
filesystem file "KNOPPIX", must be located in the top level
directory of the CD.
So, just take the knoppix ISO, copy to disk and modify away. Then use mkisofs with the -b flag to make your new custom ISO.
Why would I want to use an unoptimized version of each of these security tools when I could speed up their operation by at least 10%?
It just makes imminently more sense to only have source on your CD. What's the use of binary packaged security tools that could have buffer overflow vulnerabilities of their own, that I could not first examine before using.
i wonder if fyodor can use this to hack sdem's computer
I walk around with that in my pocket until a rent-a-cop, or paranoid faculty member, at college sees me with it and, after inspecting it, accuses me of trying to hack into the college computer system. After all, its like carrying around a lockpick set, at least to some people.
You're -still- not fooling anyone. Leave now. Plz fx k thkz.
what do you need a screen shot for? It's fucking Linux.
http://www.knoppix-std.org/.
-- PhoneBoy
The views expressed herein are not necessarily those of anyone, including the poster.
I used to use an old floppy based distro called Trinux. On about 3 floppies I had X server + GUI web browser and some network tools to do some testing. I think it was flown as a security tool distro but I used it mainly for network troubleshooting. Still ahve the floppies but I think the site and distro have died.
Anyone know what I'm talking about?
*DrugCheese rants*
L.A.S. 0.4a MAIN with FluxBox
Description: This is the alpha version of 0.4 with FluxBox added along with more tools.
MD5: 0939d7294035b5246bedbce1085bb1e1
Version: 0.4a | Filesize: 107.29 MB
Added on: 11-Aug-2003
Homepage | Details
HTH
...is mouse support (2-button touchpad or USB wheelmouse) for a Sony VAIO PCG-GRZ610. It boots but I can't do jack with it.
I tried both: boot: knoppix wheelmouse & knoppix usbmouse
Nothing seemed to work. Also, I can't seem to get the initial config script to reload to change some other settings. Any suggestions, please...
At the Nessus site:
"A security scanner is a software which will audit remotely a given network and determine whether bad guys (aka 'crackers') may break into it, or misuse it in some way."
It fails to mention that Nessus maintains a database of all security violations that can be parsed by Hackers in the know.
WAAAHAAAHAAA... (cough) (cough) (cough)
come on fhqwhgads
what makes a (distro's) cd "live?"
i sell illegal drugs
the problem is most PCs are not yet equipped with the cd-bluetooth karmic storage drives...
I'm typing this right now in the "Links" browser. It's fast, it looks good, it has most of the tools I use (Nessus, Ethereal, XMMS, Firebird). I might just mod this and carry it with me instead of using other people's machines when I'm doing diagnostics. It picked up my wireless correctly and everything.
Have fun with this one, kids.
***
Well use your imagination, imagination, imagination. How about portable development environments? e.g. Java, Web, Perl, Eclipse, Smalltalk, etc. Or portable server environments. e.g. Web, LDAP, JBoss, Samba, Proxy, E-Commerce, Blogs, etc. A portable gaming disk, with all the dependencies wrapped up. e.g. gaming clients, and servers with the possability to put updated drivers on a USB pen drive. Complete presentation/demo disks. e.g. go beyound powerpoint, and have full interactivity with the real thing. Word-processing extrodinare. e.g. Lyx, OpenOffice, DocBook, etc. Financial whiz. Throw in proprietary software and your posabilities go up. e.g Portable CAD station, Graphics workstation. Remember DVDs open up possabilities that the CDs don't. Make a couple of all the above, and place it on your site. Offer support and you can make some nice money. Or start a small company that puts any of the above on small form-factor hardware, with easy to use interface (or just remotely manage it all from your location, as part of support).
BTW Someone needs to extend this to other platforms. They want to have fun too.
you're using your auto-configured, no-vpn wireless connection as a security platform? looks like your tools are ahead of your mindset :)
I got a shell running, but there seems to be no man command and no documentation for some things in the menu, like the TinyIRC client. Obviously since I'm posting this from the running ISO there must be a web browser, but I had never used "links" before, so it was not easy to find. How I find the security tools supposedly built into this I have no idea. I did get a GUI ethereal running by bringing up a shell and typing in ethereal, but I just don't know what else is here (and what isn't).
By the way, I have network issues when booting Knoppix on this computer, so I booted this ISO with the "Knoppix expert" option. Or at least I tried to. Although it prompted me for the boot option, it ignored it after I typed it in.
I'm an American. I love this country and the freedoms that we used to have.
One thing you can do is to install the Live CD to a hard drive to get a permanant installation. While this may seem counter productive for a Live CD, I've found it to be really useful. I'm currently using the Knoppix Security Tools Distribution as a "desktop" OS... :-) Knoppix 3.2 (what both these distros are based on) includes a really useful script to install the Live CD to the hard drive. It's the easiest way I've found so far to get a Debian testing/unstable system installed and running - with X configured correctly the first time! That, in addition to having tons of great security tools preinstalled and configured makes for one sweet network-workstation-on-steroids.
...of course, I'm in charge of security where I work, so using this as a desktop OS may get you fired from _your_ work... :)
g00r00?
If they're trying to offer a secure server Linux distro, you'd think they'd run their webserver on that instead of OpenBSD.
Sig!
Blatantly copying-and-pasting from LocalAreaSecurity.com (which is apparently back up on a 400 MHz box, 96 MB RAM, on a T1). I recommend BitTorrent, but if you're gonna use mirrors, here's a bigger list: ::::: New Mirrors Added! :::::
http://chefax.fe.up.pt/mirrors/las/ -HTTP Portugal
ftp://chefax.fe.up.pt/pub/mirrors/las/ FTP Portugal
ftp://ftp.ntua.gr/pub/linux/las/ -FTP Greece
http://ftp.ntua.gr/pub/linux/las/ -HTTP Greece
http://ftp.lug.udel.edu/pub/iso-images/LAS -US Delaware
ftp://ftp.lug.udel.edu/pub/iso-images/LAS -US Delaware ::::: DOWNLOAD :::::
L.A.S. 0.4a Main with FluxBox MD5: 0939d7294035b5246bedbce1085bb1e1
http://lightning.chem.tue.nl/las/l.a.s_0.4a_MAIN.i so -The Netherlands
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.4a_ MAIN.iso -India/Asian Pacific
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.4a_MAIN .iso -USA
L.A.S. 0.3b Main MD5: f47150d2458c78169a65458bcf8ebf96
http://lightning.chem.tue.nl/las/l.a.s_0.3b.iso
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.3b. iso
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.3b.iso
L.A.S. 0.3b SECSERV MD5: ff412734492e39d1d084ced556a47493
http://lightning.chem.tue.nl/las/l.a.s_0.3b_SECSER V.iso
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.3b_ SECSERV.iso
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.3b_SECS ERV.iso
________________________________________________
suwain_2
Ack, should have previewd first. ::::: New Mirrors Added! :::::
A S -US Delaware ::::: DOWNLOAD :::::
N .i so -The Netherlands
4 a_ MAIN.iso -India/Asian Pacific
A IN .iso -USA
3 b. iso
s o
S ER V.iso
3 b_ SECSERV.iso
E CS ERV.iso
http://chefax.fe.up.pt/mirrors/las/ -HTTP Portugal
ftp://chefax.fe.up.pt/pub/mirrors/las/ FTP Portugal
ftp://ftp.ntua.gr/pub/linux/las/ -FTP Greece
http://ftp.ntua.gr/pub/linux/las/ -HTTP Greece
http://ftp.lug.udel.edu/pub/iso-images/LAS -US Delaware
ftp://ftp.lug.udel.edu/pub/iso-images/L
L.A.S. 0.4a Main with FluxBox MD5: 0939d7294035b5246bedbce1085bb1e1
http://lightning.chem.tue.nl/las/l.a.s_0.4a_MAI
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.4a_M
L.A.S. 0.3b Main MD5: f47150d2458c78169a65458bcf8ebf96
http://lightning.chem.tue.nl/las/l.a.s_0.3b.iso
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.3b.i
L.A.S. 0.3b SECSERV MD5: ff412734492e39d1d084ced556a47493
http://lightning.chem.tue.nl/las/l.a.s_0.3b_SEC
http://sarovar.org/mirrors/knoppix-las/l.a.s_0.
http://psifertex.nerdc.ufl.edu/iso/l.a.s_0.3b_S
________________________________________________
suwain_2
I downloaded (via bittorrent), and burned an ISO, booting it on my laptop, figuring it'd be a great combo. But whenever I try to boot it, I get this error:
WARNING: Autodetection seems to hang, please check your computers [sic] BIOS settings. Please check.
It pauses for a bit (minutes), does some stuff (seemingly with success), and finally gets into an infinite loop of trying to use my CD, with these errors:
hdc: status error: status=0x20 { Device Fault } ide-sci: Strange, packet command initiated yet DRQ isn't asserted hdc: ATAPI reset complete
It repeats this infinitely. What's going on, and how can I stop it?
________________________________________________
suwain_2
I think this is can be a great tool for learning different tools and techniques like computer forensics. Not all schools have the cash to go out and buy the big name Forensics utilities. Neither does local law enforcement for that matter. They can go download it to CD, through it in, and boom instant forensics analysis, without having to go through the red tape or budget hassles of buying an expensive package.
- lures men by trying to look good on the outside
- is damn expansive to maintain and requires a lot of time
- can not be possibly understood
Also, mounting writable media is a good way to pass infections between your machines. Much safer not to do that.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
ive gotten rh8 on a 1.2g. it might have even been a 1.0g, im not sure. took me forever, tho. talk about package dependency nightmares, good lord. i have vowed never to try that again
i sell illegal drugs