Application Security

11/3/2014
10:00 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

10 Cool Security Tools Open-Sourced By The Internet's Biggest Innovators

Google, Facebook, Netflix, and others have all offered up tools they've developed in-house to the community at large.
Previous
1 of 10
Next

As today's Internet giants break the barrier for speed and scale of development of systems, their teams are increasingly tasked with building home-brewed security systems that can help them develop and manage their systems securely without missing a beat. In the end, the entire security community is benefitting from a lot of these investments, as many of these firms make these tools available through open-source projects. Over the past few years, some very useful tools have come from the security and engineering teams at Facebook, Twitter, Google, Netflix, Etsy, and even AOL.

Security Monkey
Built by Netflix three years ago, Security Monkey is a monitoring and security analysis tool for Amazon Web Services configurations. It includes components for monitoring various AWS account components, developing, and executing actions based on policy rules, notifying users when audit rules are triggered and storing configuration histories for forensic and audit purposes.

(Image: Netflix)

Built by Netflix three years ago, Security Monkey is a monitoring and security analysis tool for Amazon Web Services configurations. It includes components for monitoring various AWS account components, developing, and executing actions based on policy rules, notifying users when audit rules are triggered and storing configuration histories for forensic and audit purposes.

(Image: Netflix)

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Previous
1 of 10
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
11/4/2014 | 10:49:12 AM
Solid collection of open source tools> what's your favorite?
Great job, Ericka on putting this together. Wondering which ones Dark Reading commnunity members use and what are their favorites. Share your thoughts in the comments. 
'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12630
PUBLISHED: 2018-06-21
NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.
CVE-2018-12631
PUBLISHED: 2018-06-21
Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/text?LFN=../ directory traversal.
CVE-2018-12632
PUBLISHED: 2018-06-21
Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN parameter to the /redbin/rpwebutilities.exe/text URI.
CVE-2018-12581
PUBLISHED: 2018-06-21
An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.
CVE-2018-12613
PUBLISHED: 2018-06-21
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attack...