I was browsing through some of the SANS advisory board emails this morning and it made me think of a few sites that I like to regularly visit. So I thought I’d share some of them with you. Please note, this is by no means my complete list of sites (it’s far from it) and some of these sites may be of little/no interest to some of you, but these are more or less my daily security sites that I do a quick check on (most of them have RSS feeds to make life a lot easier).

Vulnerability Searches

http://www.securityfocus.com/bid

http://packetstormsecurity.org/

http://www.exploit-db.com/

http://sebug.net/

http://inj3ct0r.com/

http://www.exploit-db.com

http://www.vs-db.info/

 

Misc Sites

http://backtrack.offensive-security.com/index.php/Tools

http://isc.sans.edu

http://www.darknet.org.uk/

http://pentestmonkey.net/

http://carnal0wnage.attackresearch.com/

http://packetlife.net/library/cheat-sheets/

http://www.theregister.co.uk/

http://www.darkreading.com/

http://www.f-secure.com/weblog/

http://www.secsocial.com/blog/

http://www.chris-mohan.com/

http://sockpuppetsecurity.com/

http://www.skullsecurity.org/wiki/index.php/Passwords

http://www.security-database.com/

http://michaeldaw.org/sql-injection-cheat-sheet

http://zone-h.org/

http://taosecurity.blogspot.com/

I may post some other sites in the near future .. ones that are targeted at a specific purpose (like citrix, or SCCM etc.)

I hope you find these sites a little bit useful :)