Skip to content

CVE Potential/Antiquated Info Patch#161

Open
tartaruslovesnoodles wants to merge 2 commits into
decalage2:masterfrom
tartaruslovesnoodles:CRITICAL-Security-Update
Open

CVE Potential/Antiquated Info Patch#161
tartaruslovesnoodles wants to merge 2 commits into
decalage2:masterfrom
tartaruslovesnoodles:CRITICAL-Security-Update

Conversation

@tartaruslovesnoodles
Copy link
Copy Markdown
Contributor

CRITICAL: CVE and Security Sensitive Outdated Guidance

Hello,

I've come to inform you of an urgent matter regarding your repo awesome-security-hardening: you have very limited material regarding firewalls, a critical part of security hardening. You reference a book from 2009 and a repo that documents Iptables.

Overall, the book is outdated, the firewall and security model is mostly static and doesn't hold up to the 2026 modern standard. In addition, there is very little mention about DoS protection at a broad scale, a large part of firewalls as well.

In this pull request I aimed to provide a set of articles that convey the critical information that is currently missing. Here are the sources I added to your firewall section in my PR.

These cover DoS attacks

MS-ISAC & CISA: Understanding and Responding to Distributed Denial-of-Service Attacks
https://www.cisa.gov/sites/default/files/publications/understanding-and-responding-to-ddos-attacks_508c.pdf

MS-ISAC Guide to DDoS Attacks
https://learn.cisecurity.org/ms-isac-guide-to-ddos-attacks

NIST: BGP Security and Resilience IPD Jan 2025
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-189r1.ipd.pdf

These cover firewalls as a whole

NIST SP 800-207 / 800-207A
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207A.pdf

CIS Critical Security Controls Version 8.1
https://etir.unb.br/wp-content/uploads/2024/10/CIS_Controls__v8.1_Guide__2024_06.pdf

NIST SP 800-53 Revision 5
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

Sidenote

In addition, you may want to include some sources that have less depth and are concise, so readers can at least 'get their feet in the water' soon (as you've done with some other sections). I didn't take this step, but you may consider adding my repo on Unmanned Server Security, specifically an excerpt regarding DDoS protection.

On the creator's repository, I noticed the firewalls section contained only NIST guidance from 2009 and a third party documentation of the iptables service. I added 3 sources regarding firewalls and 3 regarding DoS specifically within the topic of firewalls. I also removed the 2009 NIST article but kept the iptables documentation as it is extensive and not yet antiquated.
Fixed minor typo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant