Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

The Cheapskate's Infosecurity Toolbox

A list of free-to-download tools for the budget-pinched CIO or CISO

As we all know, not everyone is fortunate enough to have a blank cheque for security-related procurement and implementation. Making the best of your allocated budget may at times call for primary or supplementary solutions that are freely available. This strategy cuts procurement time completely out of the loop as well. Here's a list of security tools available on the Web for free that you should add to your toolbox.

BartPE: Preinstalled Environment Troubled by that incessant spyware or virus that just doesn't seem to go away? Need a way to troubleshoot a system without booting the operating system installed on it? BartPE and the right plug-ins will let you do this. www.nu2.nu/pebuilder

Snort: Open Source Intrusion Detection System Arguably the world's most used Intrusion Detection System. Both Windows and Linux binaries are available. www.snort.org

VMWare Server: A virtual environment It finally happened: VMWare is available for free. Patch management, QA, vulnerability remediation testing and other daily activities are now available without a significant capital investment. VMWare also offers images of various environments, configurations and operating systems available for download (they're called "appliances") and ready to use in conjunction with the main product. Just download, point VMWare to the image and test away! www.vmware.com/products/server

DataRescue's IDA Pro Freeware 4.3 disassembler and debugger Although not posted on the DataRescue site any more, the free version of their utility will turn up with a quick Google dig. Try www.programmersheaven.com/

OllyDbg disassembler and debugger Probably the world's most used debugger disassembler. Gives most commercial debuggers a good run for their money. www.ollydbg.de

eEye Digital Security's Binary Diffing Suite A good, free suite of binary diffing tools you can use to see the effect that a released patch may have on your environment. Read the Web site, as there are some platform dependencies. research.eeye.com/html/tools/RT20060801-1.html Cygwin: Linux-like environment for Windows Need to run some scripts or programs that previously ran only under Linux? Do you miss your Linux command line when running Windows? www.cygwin.com

Nagios: An open-source host, service and network monitoring program Not for security only, but Nagios can be used to monitor for events that typically have security implications. This is one that both the CIO and CISO will agree upon. www.nagios.org

iptables and Firewall Builder: Firewall and Management Interface Don't have the deep pockets for a Checkpoint, Cisco or Juniper? iptables comes with most Linux distributions. Not comfortable using a command line to manage it? Firewall Builder is an intuitive way to install and manage the rule set. Get a couple of credit card CDs, create a bootable distribution, and you've got a firewall in your pocket. www.iptables.org and www.fwbuilder.org

Apache SpamAssassin: Fight Spam at the Gateway Not really a secret to most people. With the right configuration this is difficult to beat no matter how much you spend on an antispam solution. spamassassin.apache.org/index.html

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Apache, Cisco, Ecora, eEye Digital Security, Gateway, Google, IDA, INS, Juniper, Linux, MBSA, Microsoft, NU, VMware

Comments

1

Andy Vaughan

Sat 15/08/2009 - 00:49

Wally Perez

[url=http://zbyh3qpdrs7qk8vw.com/]9539nwf2p50zm00c[/url]
[link=http://6ldyw2na2fhrocsz.com/]60jt1ah87c3qkaat[/link]
<a href=http://6pm0nqccv4i18w5m.com/>6pshvl0l51v92t74</a>
http://jwlvhwq8epr2hj5z.com/

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Lowering your IT Costs with Oracle Database 11g Release 2
    This white paper identifies the key capabilities in Oracle Database 11g Release 2 that enable IT professionals to successfully deliver more information, with higher quality of service, and at much lower cost, than they have been able to do in the past.
    Learn more »
  • Endpoint Buyers Guide
    It takes more than antivirus to stop today’s advanced threats. Protecting corporate assets requires a complete security solution that includes anti-malware, host-based intrusion prevention (HIPS), web protection, patch assessment, application and device control, network access control, data loss prevention, firewall and other capabilities. In short, you need an endpoint protection solution. We examine the top vendors according to market share and industry analysis: Kaspersky Lab, McAfee, Sophos, Symantec and Trend Micro. Each vendor’s solutions are evaluated according to: Product features and capabilities, Effectiveness, Performance, Usability, Data protection, and Technical support.
    Learn more »
  • Six tips for choosing a unified threat management (UTM) solution
    As network security grows more complex, businesses are demanding the simplicity of unified threat management (UTM). Businesses like yours are replacing multiple, outdated and costly appliances from different vendors with a single, reliable UTM solution. The best solutions offer a more powerful way to manage network security today and in the future. UTM also promises to slash your network security management efforts and hardware costs. This whitepaper offers you detailed advice on how to choose the comprehensive unified threat management (UTM) that best suits your business.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments

HP and IDG news, product videos and resources