Re: Recommended Mailing Lists - Sites

Archaic <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Since I hate web interfaces for mailing list subscription, I've expanded
on what himicos wrote.

[email protected] Type in subject: subscribe
This list is dedicated to full disclosure of any and all security
issues. Please feel free to discuss anything related to security.

[email protected]. Type in body: subscribe cert-advisory
CERT advisories address Internet security problems. They offer an
explanation of the problem, information that helps you determine if your
site has the problem, fixes or workarounds, and vendor information.

[email protected] (Leave body/subject blank)
This list is intended for the discussion of various security issues, all
for the security beginner. It is a place to learn the ropes in a
non-intimidating environment, and even a place for people who may be
experts in one particular field but are looking to increase their
knowledge in other areas of information security.

[email protected] (Leave body/subject blank)
BugTraq is a full disclosure moderated mailing list for the *detailed*
discussion and announcement of computer security vulnerabilities: what
they are, how to exploit them, and how to fix them. 

[email protected] (Leave body/subject blank)
This is a mailing list for the discussion of issues and questions about
penetration testing and network auditing.

[email protected] (Leave body/subject blank)
Focus-Linux is meant to be a resource for Linux users and
administrators, looking for that extra little bit of help in securing
Linux, using Linux in security roles, and getting additional information
about the latest in Linux vulnerabilities.

[email protected] (Leave body/subject blank)
The VULN-DEV list exists to allow people to report potential or
undeveloped holes. The idea is to help people who lack expertise, time,
or information about how to research a hole do so. 

[email protected] (Leave body/subject blank)
The INCIDENTS mailing list is a lightly moderated mailing list to
facilitate the quick exchange of security incident information. Topical
items include: Information about rootkits and backdoors; New trojan horses,
viruses, and worms; Sources of attacks; Tell-tale signs of intrusions.

[email protected]
The FOCUS-IDS list exists to allow people to discuss detection of
intrusions. This includes both discovering invisible hacker activity
(such as "stealth scans") as well as finding systems that have been
compromised.

Look at http://securityfocus.com/archive for the complete listing of
mailing lists they offer (there are many). Especially note that BUGTRAQ
is sent in other languanges as well.

> The sites worth monitoring IMHO are
> 
> www.symantec.com

This I wouldn't really consider a factor in a Linux-based project.

> www.slashdot.org
> www.newsforge.com

These guys are generally just news agencies, and by the time these guys
get a security story, it's already been seen on many mailing lists. IMO,
if they ain't the first to report, they are irrelevant. ;)

Anyway, above is the lists I sub to. There are others, but I either
don't know about them, of haven't tried them, or just plain forgot to
mention them. Feel free to fill in the blanks. :)

-- 
Archaic

"Those who make peaceful revolution impossible will make violent
revolution inevitable."

- John F. Kennedy
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.