issue55:critique
Différences
Ci-dessous, les différences entre deux révisions de la page.
Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
issue55:critique [2012/01/28 16:26] – auntiee | issue55:critique [2012/02/02 03:54] (Version actuelle) – shinichi | ||
---|---|---|---|
Ligne 5: | Ligne 5: | ||
On the surface, both appear similar and they are in several respects, but there are radical differences between them, so a head-to-head comparison may be merited.** | On the surface, both appear similar and they are in several respects, but there are radical differences between them, so a head-to-head comparison may be merited.** | ||
- | Pendant de nombreuses années, les seuls choix pour le personnel IT chargé de la sécurité en matière | + | Pendant de nombreuses années, les seuls choix pour le personnel IT chargé de la sécurité en matière |
- | Il y a juste un peu plus d'un an, les options des utilisateurs se sont étoffées avec l' | + | Il y a juste un peu plus d'un an, les options des utilisateurs se sont étoffées avec l' |
- | Superficiellement, | + | Superficiellement, |
- | History and Underlying Base | + | **History and Underlying Base |
BackTrack is from Switzerland, | BackTrack is from Switzerland, | ||
- | Backbox comes from Italy, and, prior to 2010, it really didn't have much of a track record, at least not online. Other than scant mentions of version 1 (RC and then beta), even distrowatch.com doesn' | + | Backbox comes from Italy, and, prior to 2010, it really didn't have much of a track record, at least not online. Other than scant mentions of version 1 (RC and then beta), even distrowatch.com doesn' |
- | Website | + | Histoire et bases |
+ | |||
+ | BackTrack est d' | ||
+ | |||
+ | BackBox vient d' | ||
+ | |||
+ | **Website | ||
BackTrack' | BackTrack' | ||
Ligne 25: | Ligne 31: | ||
Those wishing to skip all the pages can jump to offensive-security.com to get right to the courses; however, the website is nearly identical to links off the main BackTrack page, and, since it has the .com suffix, it's quite apparent the goal is sales. It could be argued that many developers pitch paraphernalia on their websites, but most of it won't require a second mortgage. | Those wishing to skip all the pages can jump to offensive-security.com to get right to the courses; however, the website is nearly identical to links off the main BackTrack page, and, since it has the .com suffix, it's quite apparent the goal is sales. It could be argued that many developers pitch paraphernalia on their websites, but most of it won't require a second mortgage. | ||
- | Forums appear to be comprehensive, | + | Forums appear to be comprehensive, |
- | BackBox is a little different in their website. Mainly in English, about half of the forum contents are in Italian - so if you need information there, use your browser' | + | Site web |
+ | |||
+ | Le meilleur qualificatif pour le site web de BackTrack (backtrack-linux.org) est éclectique. Avec leur slogan « plus votre silence devient profond et plus vous pourrez entendre » et une page wiki appelée //Le guide de BackTrack pour les Ninjas//, on ne peut qu' | ||
+ | |||
+ | Creusez assez loin dans le site et vous trouverez une litanie de cours de « sécurité offensive », dont la plupart, sinon tous, demandent aux étudiants de faire des « pentests » et d' | ||
+ | |||
+ | Ceux qui veulent sauter toutes les pages peuvent aller directement à offensive-security.com pour voir les cours tout de suite. Cela dit, le site web est presque identique aux liens figurant sur les pages de BackTrack et, puisque le suffixe est .com, c'est évident que l' | ||
+ | |||
+ | Les forums ont l'air d' | ||
+ | |||
+ | **BackBox is a little different in their website. Mainly in English, about half of the forum contents are in Italian - so if you need information there, use your browser' | ||
Unlike BackTrack, BackBox doesn' | Unlike BackTrack, BackBox doesn' | ||
Ligne 33: | Ligne 49: | ||
The forums are puny compared to BackTrack, but this OS is only a year old, and it’s trying to build a fan base. Since some of the security-based programs are the same or nearly identical to those offered by BackTrack, users could jump the fence and visit the competition' | The forums are puny compared to BackTrack, but this OS is only a year old, and it’s trying to build a fan base. Since some of the security-based programs are the same or nearly identical to those offered by BackTrack, users could jump the fence and visit the competition' | ||
- | It appears there may have been an Italian site at http:// | + | It appears there may have been an Italian site at http:// |
- | OS Size and Options | + | Le site web de BackBox est un peu différent. En anglais pour la plupart, environ la moitié du contenu du forum est en italien. Si vous avez besoin d' |
+ | |||
+ | Contrairement à BackTrack, BackBox ne vend pas des supports de cours, bien que, de façon étrange, le site contient des liens google vers d' | ||
+ | |||
+ | Comparés à ceux de BackTrack, les forums sont maigres, mais ce système d' | ||
+ | |||
+ | Il semblerait qu'il y ait eu un site italien à http:// | ||
+ | |||
+ | **OS Size and Options | ||
BackBox (right) packs two desktops as standard, Xfce, and BackBox Session - a modified Xfce design with a bottom dock, top panel, and more sophisticated background design than standard Xfce. In early 2011, it appears a Fluxbox package was offered but I couldn' | BackBox (right) packs two desktops as standard, Xfce, and BackBox Session - a modified Xfce design with a bottom dock, top panel, and more sophisticated background design than standard Xfce. In early 2011, it appears a Fluxbox package was offered but I couldn' | ||
Ligne 43: | Ligne 67: | ||
BackTrack offers Gnome and KDE as desktop options - along with 32 and 64-bit configurations, | BackTrack offers Gnome and KDE as desktop options - along with 32 and 64-bit configurations, | ||
- | No matter which version you choose, the image is near or at 2GB. | + | No matter which version you choose, the image is near or at 2GB.** |
+ | |||
+ | La taille et les options du système d' | ||
+ | |||
+ | BackBox (à droite) possède en standard deux bureaux, Xfce et BackBox Session - comme un bureau Xfce modifié avec un dock en bas, un panneau en haut et un arrière-plan plus sophistiqué que la norme pour Xfce. Début 2011, il paraît qu'ils proposaient un paquet Fluxbox, mais je n'ai pas réussi à savoir si c'est le cas dans la version actuelle (Fluxbox avait des problèmes initiaux avec d' | ||
+ | |||
+ | Des options 32-bit et 64-bit à 913 et 945 Mo, respectivement, | ||
+ | |||
+ | BackTrack offre le choix entre le bureau de Gnome et celui de KDE, ainsi que des configurations 32- et 64-bits, mais au lieu de mettre Gnome et KDE dans le même paquet, ils sont séparés. Les utilisateurs qui veulent essayer toutes les possibilités doivent ainsi télécharger 4 paquets. | ||
+ | |||
+ | Quelle que soit la version que vous choisissez, l' | ||
- | Upgrade From Earlier Versions? | + | **Upgrade From Earlier Versions? |
Even though both OS are based on Ubuntu, the upgrade process is not the same as going to Update Manager and stepping up to the next available version. Yes, you can do that for the underlying code base, but what could happen to the specialized security software? | Even though both OS are based on Ubuntu, the upgrade process is not the same as going to Update Manager and stepping up to the next available version. Yes, you can do that for the underlying code base, but what could happen to the specialized security software? | ||
Ligne 55: | Ligne 89: | ||
BackBox really doesn' | BackBox really doesn' | ||
- | Best idea for either OS? Break out aptoncd and get busy backing up those programs you want to keep, and hope the security oriented programs you like are still there once the new installation is completed. | + | Best idea for either OS? Break out aptoncd and get busy backing up those programs you want to keep, and hope the security oriented programs you like are still there once the new installation is completed. |
- | Installation | + | Peut-on faire une mise à niveau à partir de versions antérieures ? |
+ | |||
+ | Malgré le fait que les deux systèmes d' | ||
+ | |||
+ | BackTrack ne propose pas d' | ||
+ | |||
+ | Bien que je ne puisse pas le vérifier personnellement, | ||
+ | |||
+ | BlackBox ne parle pas vraiment du problème sur son site web, mais un courriel du développeur, | ||
+ | |||
+ | Meilleure idée pour chacun des systèmes d' | ||
+ | |||
+ | **Installation | ||
Both OSes offer live mode, and the ability to use persistence via USB flash drive. Unless you need portability, | Both OSes offer live mode, and the ability to use persistence via USB flash drive. Unless you need portability, | ||
Ligne 63: | Ligne 109: | ||
The real test is full installation, | The real test is full installation, | ||
- | BackTrack (right) is unique in this respect in that all users must sign in as root. As a result, the usual Ubuntu installer method is lacking since there is no user ID or password collected – the OS is installed and that's that. About the only input involved is determining the amount of hard drive space to use. | + | BackTrack (right) is unique in this respect in that all users must sign in as root. As a result, the usual Ubuntu installer method is lacking since there is no user ID or password collected – the OS is installed and that's that. About the only input involved is determining the amount of hard drive space to use.** |
+ | |||
+ | Installation | ||
+ | |||
+ | Les deux systèmes d' | ||
+ | |||
+ | Le vrai test est une installation complète et celle-ci peut parfois être parsemée d' | ||
+ | |||
+ | BackTrack (à droite) est unique à cet égard, car tous les utilisateurs doivent se connecter en tant que root. Par conséquent, | ||
- | From DVD in to final restart took roughly 30 minutes, or about the average amount of time for an Ubuntu installation. | + | **From DVD in to final restart took roughly 30 minutes, or about the average amount of time for an Ubuntu installation. |
BackBox is classic Ubiquity and installation was a rather spectacular 17 minutes. By the time I turned around to make a sandwich it was completed. | BackBox is classic Ubiquity and installation was a rather spectacular 17 minutes. By the time I turned around to make a sandwich it was completed. | ||
Ligne 73: | Ligne 127: | ||
Updates were equal with about 200MB waiting post-installation - which is good for BackTrack since it's based on last year's Ubuntu base. | Updates were equal with about 200MB waiting post-installation - which is good for BackTrack since it's based on last year's Ubuntu base. | ||
- | Hard drive space was typical with DVD contents expanding 100% once unpacked. BackTrack recommends 10GB hard drive space, while BackBox posts 2GB. BackTrack is more in line with reality, and it appears BackBox is using outdated or overly optimistic specs which wouldn' | + | Hard drive space was typical with DVD contents expanding 100% once unpacked. BackTrack recommends 10GB hard drive space, while BackBox posts 2GB. BackTrack is more in line with reality, and it appears BackBox is using outdated or overly optimistic specs which wouldn' |
- | Login Protocol | + | Il a fallu environ 30 minutes, de l' |
+ | |||
+ | BackBox est de l' | ||
+ | |||
+ | Dans les deux, la reconnaissance du matériel a été superbe, le seul emplacement de pilote qu'il fallait donner étant celui pour ma carte graphique ATI/AMD. Le sans-fil fonctionnait à merveille sous les deux, bien qu'il faille continuer votre lecture pour voir les problèmes rencontrés lorsque je cherchais à me connecter à internet sous BackTrack. | ||
+ | |||
+ | Les mises à jour furent pareilles avec environ 200 Mo en attente après l' | ||
+ | |||
+ | L' | ||
+ | |||
+ | **Login Protocol | ||
Just when you thought you'd never hear of the root/toor procedure again, it's back! | Just when you thought you'd never hear of the root/toor procedure again, it's back! | ||
Ligne 83: | Ligne 147: | ||
Unfortunately, | Unfortunately, | ||
- | Best as I can tell, BackTrack offers no option to use the standard Ubuntu protocol of user ID and password. You're in as root and that's all there is to that, although the password can be changed from toor once booted. | + | Best as I can tell, BackTrack offers no option to use the standard Ubuntu protocol of user ID and password. You're in as root and that's all there is to that, although the password can be changed from toor once booted.** |
- | Possibly because of the Gnome desktop, boot times were often somewhat dismal with 1 to 1.5 minutes being the norm (part of which was taken up entering root specs mentioned above). | + | Protocole de connexion |
+ | |||
+ | Au moment où vous avez pensé ne plus jamais entendre parler de la procédure root/toor, elle est de retour ! | ||
+ | |||
+ | BackTrack mérite bien son nom en utilisant cette procédure ici, bien que les utilisateurs puissent changer le mot de passe après l' | ||
+ | |||
+ | Malheureusement, | ||
+ | |||
+ | D' | ||
+ | |||
+ | **Possibly because of the Gnome desktop, boot times were often somewhat dismal with 1 to 1.5 minutes being the norm (part of which was taken up entering root specs mentioned above). | ||
If you're looking for a colorful splash screen, forget it. BackTrack goes to verbose mode for the login process. | If you're looking for a colorful splash screen, forget it. BackTrack goes to verbose mode for the login process. | ||
Ligne 93: | Ligne 167: | ||
Much like BackTrack, there is no splash screen in BackBox, and new users may initially be put off by what they don't see. In short, a black screen with a flashing cursor is all that greets the user, and even that disappears after a few seconds - leaving just the blank screen until the desktop opens. At first, I thought the installation had failed and nearly powered down. | Much like BackTrack, there is no splash screen in BackBox, and new users may initially be put off by what they don't see. In short, a black screen with a flashing cursor is all that greets the user, and even that disappears after a few seconds - leaving just the blank screen until the desktop opens. At first, I thought the installation had failed and nearly powered down. | ||
- | Is one login protocol any better than the other? That's subject to interpretation - although most accounts I've reviewed state that signing in as root is inviting trouble since any mistakes or missteps can lead to the OS crashing. Fact is, anybody using root in live mode can merely do a forced reboot and be back to square one - but those using a persistent USB system may be doomed, since changes, including mistakes, are saved. | + | Is one login protocol any better than the other? That's subject to interpretation - although most accounts I've reviewed state that signing in as root is inviting trouble since any mistakes or missteps can lead to the OS crashing. Fact is, anybody using root in live mode can merely do a forced reboot and be back to square one - but those using a persistent USB system may be doomed, since changes, including mistakes, are saved.** |
+ | |||
+ | Peut-être à cause du bureau Gnome, les temps de démarrage furent souvent assez lamentables, | ||
+ | |||
+ | Ce n'est pas la peine d' | ||
+ | |||
+ | Backbox se sert de l' | ||
+ | |||
+ | Comme pour BackTrack, il n'y a pas d' | ||
+ | |||
+ | Est-ce que l'un des protocoles de connexion est meilleur que l' | ||
- | Desktop | + | **Desktop |
BackBox is Xfce with a modification called BackBox session that adds a dock and top panel to the usual rat logo on a bland background. It doesn' | BackBox is Xfce with a modification called BackBox session that adds a dock and top panel to the usual rat logo on a bland background. It doesn' | ||
Ligne 101: | Ligne 185: | ||
The desktop design, in keeping with Xfce tradition, is minimalistic, | The desktop design, in keeping with Xfce tradition, is minimalistic, | ||
- | There is the Xfce dock at the bottom, but look quickly because it disappears as soon as the desktop appears (right click the dock to kill autohide in options). It contains a few icons for Internet (aka Firefox), a mail reader, among others, but the one that's interesting is Vidalia. Not the onion, mind you, but the program that acts as a graphical front-end for Tor. | + | There is the Xfce dock at the bottom, but look quickly because it disappears as soon as the desktop appears (right click the dock to kill autohide in options). It contains a few icons for Internet (aka Firefox), a mail reader, among others, but the one that's interesting is Vidalia. Not the onion, mind you, but the program that acts as a graphical front-end for Tor.** |
- | That's not a misprint of Thor by the way, it is Tor, a program used to cover your tracks by redirecting your traces, to the point that surveillance is tough. Good thing, too, since some of the included programs I'll discuss later are best left unknown. The Firefox version included has Vidalia installed by default, and activation is by clicking the onion icon to the left of the URL field. (In one check it showed I was from the Ukraine when I was a few miles away in central Florida). | + | Le bureau |
+ | |||
+ | Backbox, c'est Xfce avec une modification appelée BackBox session qui ajoute un dock et une barre en haut au logo habituel d'un rat sur un fond neutre. Il ne propose pas Gnome ou KDE en standard comme BackTrack ; cela dit, ce n'est pas nécessairement mauvais. | ||
+ | |||
+ | Conformément à la tradition Xfce, la conception du bureau est minimaliste, | ||
+ | |||
+ | Il y a le dock Xfce en bas, mais regardez-le vite parce qu'il disparaît dès l' | ||
+ | |||
+ | **That's not a misprint of Thor by the way, it is Tor, a program used to cover your tracks by redirecting your traces, to the point that surveillance is tough. Good thing, too, since some of the included programs I'll discuss later are best left unknown. The Firefox version included has Vidalia installed by default, and activation is by clicking the onion icon to the left of the URL field. (In one check it showed I was from the Ukraine when I was a few miles away in central Florida). | ||
A lone panel sits up top with the usual icons, with the only exception being the BackBox logo in the left corner acting as a main menu button. Xfce also allows access to most of the main menu via a left click anywhere on the desktop. | A lone panel sits up top with the usual icons, with the only exception being the BackBox logo in the left corner acting as a main menu button. Xfce also allows access to most of the main menu via a left click anywhere on the desktop. | ||
- | BackTrack is also artistically designed, and the desktop design is eye catching. Consisting of a black and red mixture with what appears to be a galloping horse with a flowing mane in the background, the only thing breaking the design is the logo “<< | + | BackTrack is also artistically designed, and the desktop design is eye catching. Consisting of a black and red mixture with what appears to be a galloping horse with a flowing mane in the background, the only thing breaking the design is the logo “<< |
- | I didn't get a chance to test the KDE desktop, so I can only comment on Gnome. Since this is based on Lucid 10.04 instead of Natty, there is no Unity option. | + | Soit dit en passant, ce n'est pas une erreur d' |
+ | |||
+ | Un seul panneau s' | ||
+ | |||
+ | La conception de BackTrack est aussi artistique et, en particulier, | ||
+ | |||
+ | **I didn't get a chance to test the KDE desktop, so I can only comment on Gnome. Since this is based on Lucid 10.04 instead of Natty, there is no Unity option. | ||
Beyond aesthetics, the desktop may look like every other Gnome design you've seen, but this is deceiving. Sure, you get the usual tri-entry menu system in the left corner (Applications, | Beyond aesthetics, the desktop may look like every other Gnome design you've seen, but this is deceiving. Sure, you get the usual tri-entry menu system in the left corner (Applications, | ||
Ligne 117: | Ligne 215: | ||
Give up? No wireless or network connection icons, and the user name is gone from the right side. The missing name is obvious since you're signed in as root, but the network icon is something of a mystery. Yes, wireless and Ethernet both work, but BackTrack has dumped the icon as some sort of secretive measure to keep prying eyes from knowing(?). | Give up? No wireless or network connection icons, and the user name is gone from the right side. The missing name is obvious since you're signed in as root, but the network icon is something of a mystery. Yes, wireless and Ethernet both work, but BackTrack has dumped the icon as some sort of secretive measure to keep prying eyes from knowing(?). | ||
- | So how do you know you're connected? Go to Internet under the main menu, and find Wicd, and it'll advise you of wireless connections, | + | So how do you know you're connected? Go to Internet under the main menu, and find Wicd, and it'll advise you of wireless connections, |
- | And now for the curiosity that has everybody scratching their head. | + | Je n'ai pas eu l' |
+ | |||
+ | Au-delà de l' | ||
+ | |||
+ | Trouvez-en une capture d' | ||
+ | |||
+ | Vous donnez votre langue au chat ? Aucune icône de wifi, ni de connexion à un réseau et le nom de l' | ||
+ | |||
+ | Dans ce cas, comment savoir si vous êtes connecté ? Allez à Internet dans le menu principal, trouvez Wicd et il vous informera des connexions wifi ; par ailleurs, vous pouvez utiliser le gestionnaire de réseau pour la partie Ethernet. | ||
+ | |||
+ | **And now for the curiosity that has everybody scratching their head. | ||
After one week of using BackBox, I opted to log out to test Xfce, and was surprised to see Gnome Classic and Unity listed as options. BackBox doesn' | After one week of using BackBox, I opted to log out to test Xfce, and was surprised to see Gnome Classic and Unity listed as options. BackBox doesn' | ||
- | But there is one issue I find somewhat contradictory in both OSes: if these are supposed to be stealthy and secretive, then why do both have desktop designs that can be spotted half a mile away? True, you can change them, but those opting for live mode without persistence will have that clue pop up every time they boot. | + | But there is one issue I find somewhat contradictory in both OSes: if these are supposed to be stealthy and secretive, then why do both have desktop designs that can be spotted half a mile away? True, you can change them, but those opting for live mode without persistence will have that clue pop up every time they boot.** |
+ | |||
+ | Et maintenant pour la bizarrerie qui rend tout le monde perplexe. | ||
+ | |||
+ | Après avoir utilisé BackBox pendant une semaine, j'ai choisi de me déconnecter afin de tester Xfce et je fus surpris de voir Gnome Classic et Unity dans la liste d' | ||
+ | |||
+ | Mais, il y a un truc dans les deux systèmes d' | ||
- | Standard Programs | + | **Standard Programs |
Let's be honest and admit the average Linux user is not going to pick either of these OSes as a main version for home computer usage. These are designed for specialists in security, or for hackers who should know better; however, even these persons like listening to music, playing the occasional game, or cranking out a newsletter. | Let's be honest and admit the average Linux user is not going to pick either of these OSes as a main version for home computer usage. These are designed for specialists in security, or for hackers who should know better; however, even these persons like listening to music, playing the occasional game, or cranking out a newsletter. | ||
Ligne 135: | Ligne 249: | ||
BackBox is even lighter, with Abiword, Firefox, Vidalia, Tor, Sound Recorder, Transmission, | BackBox is even lighter, with Abiword, Firefox, Vidalia, Tor, Sound Recorder, Transmission, | ||
- | Adding Programs is discussed later, but make sure you read it because the results are somewhat unbelievable for one of the OS. | + | Adding Programs is discussed later, but make sure you read it because the results are somewhat unbelievable for one of the OS.** |
- | Security Based Programs | + | Les programmes standard |
+ | |||
+ | Soyons honnêtes et admettons que l' | ||
+ | |||
+ | Il n'y a aucun doute : BackTrack contient plus de programmes initiaux que BackBox, mais à la longue, c'est quelque peu trompeur. | ||
+ | |||
+ | Vous verrez, pour la plupart, Disk Usage Analyzer, l' | ||
+ | |||
+ | BackBox est encore plus léger, avec Abiword, Firefox, Vidalia, Tor, Sound Recorder, Transmission, | ||
+ | |||
+ | Je parlerai de l' | ||
+ | |||
+ | **Security Based Programs | ||
There is no doubt BackTrack wins in this category - with well over 100 included programs, some of which I've never heard of. | There is no doubt BackTrack wins in this category - with well over 100 included programs, some of which I've never heard of. | ||
Ligne 145: | Ligne 271: | ||
For the most part, you find these under the area marked BackTrack on the main menu - which has subcategories for Information Gathering, Vulnerability Assessment, Exploitation Tools, Privilege Escalation, Maintaining Access, Reverse Engineering, | For the most part, you find these under the area marked BackTrack on the main menu - which has subcategories for Information Gathering, Vulnerability Assessment, Exploitation Tools, Privilege Escalation, Maintaining Access, Reverse Engineering, | ||
- | Each one of these categories breaks down into yet more categories listing programs galore to keep the most mischievous computer geek busy. While I could list them all, the total number is rather amazing, and must total over 100 as some menu categories cascade out to sub-sub-categories. | + | Each one of these categories breaks down into yet more categories listing programs galore to keep the most mischievous computer geek busy. While I could list them all, the total number is rather amazing, and must total over 100 as some menu categories cascade out to sub-sub-categories.** |
- | BackBox is somewhat similar, just with fewer programs and a menu heading of Auditing. Here you'll find Vulnerability Assessment, Forensic Analysis, VOIP Analysis, Information Gathering, Exploitation, | + | Les programmes basés sur la sécurité |
+ | |||
+ | BackTrack fait sans conteste mieux dans cette catégorie : il y a nettement plus de 100 programmes inclus, dont certains que me sont totalement inconnus. | ||
+ | |||
+ | Et c'est cela le problème. Le site web ne donne que très peu de renseignements sur ce qui est inclus et il faut l' | ||
+ | |||
+ | Pour la plupart, vous les trouverez sous BackTrack dans le menu principal. Il y a même des sous-catégories pour « Information Gathering » (la collecte d' | ||
+ | |||
+ | Chacune de ces catégories est divisée en d' | ||
+ | |||
+ | **BackBox is somewhat similar, just with fewer programs and a menu heading of Auditing. Here you'll find Vulnerability Assessment, Forensic Analysis, VOIP Analysis, Information Gathering, Exploitation, | ||
Each of these categories branches out to yet other sub-headings which give a listing of programs that can best be described as scary. Why do I believe some of these programs are suspect? Instead of the usual colorful assortment of icons, these all get skull and crossbones insignia, and various warnings pop up prior to usage. | Each of these categories branches out to yet other sub-headings which give a listing of programs that can best be described as scary. Why do I believe some of these programs are suspect? Instead of the usual colorful assortment of icons, these all get skull and crossbones insignia, and various warnings pop up prior to usage. | ||
- | BackBox is forthcoming with what their OS packs, just go to http:// | + | BackBox is forthcoming with what their OS packs, just go to http:// |
+ | |||
+ | BackBox est assez similaire, mais offre moins de programmes et un en-tête menu d'« Auditing » C'est là que vous trouverez Vulnerability Assessment, Forensic Analysis, VOIP Analysis, Information Gathering, Exploitation, | ||
+ | |||
+ | Chacune de ces catégories se subdivise encore en d' | ||
+ | |||
+ | BackBox présente volontiers le contenu de leur système d' | ||
- | Secondary Security | + | **Secondary Security |
Compared to BackTrack, BackBox seems to be a slacker in this department - although that's subject to debate. | Compared to BackTrack, BackBox seems to be a slacker in this department - although that's subject to debate. | ||
Ligne 161: | Ligne 303: | ||
For those unfamiliar with Vidalia/ | For those unfamiliar with Vidalia/ | ||
- | As a test, I had a friend see if he could identify what OS I was using while online. BackBox did drop the ball here since it readily identified itself as “BackBox Linux 2”, but Tor made it appear like I was from the Ukraine when I was still parked in central Florida. | + | As a test, I had a friend see if he could identify what OS I was using while online. BackBox did drop the ball here since it readily identified itself as “BackBox Linux 2”, but Tor made it appear like I was from the Ukraine when I was still parked in central Florida.** |
- | BackTrack takes the opposite path, and goes full hog on keeping the outside from knowing what you do. Not only is opening music gone, even password asterisks are blocked so eavesdroppers can't see the number of characters - but the height of craziness is the complete lack of wireless or Ethernet icons on the desktop, apparently to keep other eyes from noticing you're web surfing (since some of the security programs use a browser to operate, this' | + | La sécurité secondaire |
+ | |||
+ | Comparé à BackTrack, BackBox donne l' | ||
+ | |||
+ | Sauf la suppression des notes de musique et d' | ||
+ | |||
+ | Pour ceux qui ne connaissent pas Vidalia/ | ||
+ | |||
+ | Comme test, j'ai demandé à un ami de voir s'il pouvait identifier mon système d' | ||
+ | |||
+ | **BackTrack takes the opposite path, and goes full hog on keeping the outside from knowing what you do. Not only is opening music gone, even password asterisks are blocked so eavesdroppers can't see the number of characters - but the height of craziness is the complete lack of wireless or Ethernet icons on the desktop, apparently to keep other eyes from noticing you're web surfing (since some of the security programs use a browser to operate, this' | ||
Online, it identifies itself as Ubuntu 10.04, with no other clue. Since Tor isn't activated unless users add it, my IP address was readily apparent. | Online, it identifies itself as Ubuntu 10.04, with no other clue. Since Tor isn't activated unless users add it, my IP address was readily apparent. | ||
Ligne 169: | Ligne 321: | ||
Probably the most aggravating BackTrack security feature is the inclusion of NoScript in Firefox. Until it's trained on what pages it'll accept, you can pretty much be guaranteed your page probably won't open unless you turn it off via the icon next to the URL, or remember to accept new pages as they open. New users will undoubtedly be stymied until they learn this, and the procedure was required for each and every site I visited (turning it off is good for one site at a time, and uninstalling the extension is the only way to dispose of it). | Probably the most aggravating BackTrack security feature is the inclusion of NoScript in Firefox. Until it's trained on what pages it'll accept, you can pretty much be guaranteed your page probably won't open unless you turn it off via the icon next to the URL, or remember to accept new pages as they open. New users will undoubtedly be stymied until they learn this, and the procedure was required for each and every site I visited (turning it off is good for one site at a time, and uninstalling the extension is the only way to dispose of it). | ||
- | While both seem to be interested in user security, I find it odd that both have artistic desktop designs that all but send up signal flares as advertising, | + | While both seem to be interested in user security, I find it odd that both have artistic desktop designs that all but send up signal flares as advertising, |
- | And before you state this isn't a problem, let me give you an example. While testing BackTrack at my local library, another techie behind me spotted the on-screen verbiage, and blurted out, “What version of BT are you using?” | + | BackTrack suit le chemin contraire et met le paquet pour empêcher les étrangers de savoir ce que vous faites. Il a bloqué non seulement la musique d' |
+ | |||
+ | En ligne, il s' | ||
+ | |||
+ | La fonction de sécurité de BackTrack qui est sans doute la plus agaçante est la présence de NoScript dans Firefox. Jusqu' | ||
+ | |||
+ | Alors que les deux semblent s' | ||
+ | |||
+ | **And before you state this isn't a problem, let me give you an example. While testing BackTrack at my local library, another techie behind me spotted the on-screen verbiage, and blurted out, “What version of BT are you using?” | ||
So much for stealth in this department. | So much for stealth in this department. | ||
Ligne 182: | Ligne 342: | ||
For those interested more in the security programs and artwork than the OS itself, the source can be added to standard Ubuntu via: | For those interested more in the security programs and artwork than the OS itself, the source can be added to standard Ubuntu via: | ||
+ | |||
+ | deb http:// | ||
+ | |||
+ | Et, avant que vous ne disiez que ce n'est pas un problème, permettez-moi de vous donner un exemple. J' | ||
+ | |||
+ | Voilà pour ce qui est la discrétion dans ce domaine. | ||
+ | |||
+ | Ajouter des programmes | ||
+ | |||
+ | BackBox a le Gestionnaire de paquets de Synaptic et la Logithèque Ubuntu et, bien entendu, les utilisateurs peuvent se servir d' | ||
+ | |||
+ | Malgré l' | ||
+ | |||
+ | Pour ceux qui s' | ||
deb http:// | deb http:// | ||
- | BackTrack offers apt-get only, and goes as far as completely removing Synaptic and Ubuntu Software Center - meaning both have to be installed or users are stuck using terminal commands (which I had to use to install Synaptic so I could eventually get some programs). | + | **BackTrack offers apt-get only, and goes as far as completely removing Synaptic and Ubuntu Software Center - meaning both have to be installed or users are stuck using terminal commands (which I had to use to install Synaptic so I could eventually get some programs). |
No big deal, you say? Read on. | No big deal, you say? Read on. | ||
Ligne 191: | Ligne 365: | ||
Since BackTrack users are signed in as root, some newly installed programs may not work. A prime example is Google Chrome. It refuses to open in root, as did Opera, so my chances of using another browser just got shot down. After a while it got frustrating - since nearly 50% of what I installed wouldn' | Since BackTrack users are signed in as root, some newly installed programs may not work. A prime example is Google Chrome. It refuses to open in root, as did Opera, so my chances of using another browser just got shot down. After a while it got frustrating - since nearly 50% of what I installed wouldn' | ||
- | Much like BackBox, BackTrack utilizes their software package for the security oriented apps, and users wanting the programs without the OS can add the source (deb http:// | + | Much like BackBox, BackTrack utilizes their software package for the security oriented apps, and users wanting the programs without the OS can add the source (deb http:// |
- | Stability and Resource Usage | + | BackTrack ne propose que apt-get et en arrive à enlever complètement Synaptic et la Logithèque, |
+ | |||
+ | Ce n'est pas grave, dites-vous ? Continuez votre lecture. | ||
+ | |||
+ | Puisque les utilisateurs de BackTrack se connectent en tant que root, certains programmes nouvellement installés peuvent ne pas fonctionner. Google Chrome en est un excellent exemple. Il refuse de s' | ||
+ | |||
+ | Comme BackBox, BackTRack se sert de son paquet de logiciels pour les applis orientées vers la sécurité et les utilisateurs qui veulent les programmes sans le système d' | ||
+ | |||
+ | **Stability and Resource Usage | ||
Since both are based on Ubuntu, just different versions, stability is all but guaranteed - but BackBox' | Since both are based on Ubuntu, just different versions, stability is all but guaranteed - but BackBox' | ||
Ligne 201: | Ligne 383: | ||
BackTrack with Gnome was also a pleasant operational experience - just a bit slower than Xfce to respond and boot, and this also showed in resource depletion with RAM and processor rates being nearly twice as high on the same computer - with occasional spikes to the red line. | BackTrack with Gnome was also a pleasant operational experience - just a bit slower than Xfce to respond and boot, and this also showed in resource depletion with RAM and processor rates being nearly twice as high on the same computer - with occasional spikes to the red line. | ||
- | During one week of abusive testing, I never experienced an OS failure or crash. Quite impressive. | + | During one week of abusive testing, I never experienced an OS failure or crash. Quite impressive.** |
+ | |||
+ | La stabilité et l' | ||
+ | |||
+ | Puisque les deux sont basés sur Ubuntu, seule la version diffère, la stabilité est quasi garantie, mais l' | ||
+ | |||
+ | L' | ||
+ | |||
+ | BackTrack avec Gnome me donnait également une agréable expérience opérationnelle. Ses temps de réponse et de démarrage n' | ||
+ | |||
+ | Pendant une semaine de tests vraiment durs, presque abusifs, je n'ai jamais eu de plantage du système ou de panne. Vraiment impressionnant. | ||
- | Other Quirks and Final Comments | + | **Other Quirks and Final Comments |
This article consists of my personal observations concerning my testing of both OSes during the month of September, 2011. | This article consists of my personal observations concerning my testing of both OSes during the month of September, 2011. | ||
Ligne 213: | Ligne 405: | ||
Had I performed that operation on a corporate wireless system it would be called corporate espionage, and would probably net me 5 to 10 in the federal pen (and that's where you'll really find out what penetration testing is). | Had I performed that operation on a corporate wireless system it would be called corporate espionage, and would probably net me 5 to 10 in the federal pen (and that's where you'll really find out what penetration testing is). | ||
- | Second, 99% of the included security programs for either OS require nothing short of an advanced degree in physics to decipher. Even with tutorial help, I have no idea what some of them do other than produce prodigious amounts of on-screen gibberish - and I'm no computer novice. | + | Second, 99% of the included security programs for either OS require nothing short of an advanced degree in physics to decipher. Even with tutorial help, I have no idea what some of them do other than produce prodigious amounts of on-screen gibberish - and I'm no computer novice.** |
- | So, the question really is, would the average user find much use in either OS? | + | Autres caprices et mes derniers commentaires |
+ | |||
+ | Cet article est composé de mes observations personnelles lors de tests des deux systèmes d' | ||
+ | |||
+ | Primo, il ne s'agit pas du système d' | ||
+ | |||
+ | Jusqu' | ||
+ | |||
+ | Si j' | ||
+ | |||
+ | Deuxio, 99 % des programmes de sécurité inclus dans les deux nécessitent au moins un diplôme de 3e cycle en physique pour pouvoir les déchiffrer; | ||
+ | |||
+ | **So, the question really is, would the average user find much use in either OS? | ||
No. Joe Average would have little use for such software, but, truthfully, it's a hoot to play with, just make sure you play nicely with friends. Just like that nice Doberman down the street, there is only so much ear tugging you can do before the fangs come out. | No. Joe Average would have little use for such software, but, truthfully, it's a hoot to play with, just make sure you play nicely with friends. Just like that nice Doberman down the street, there is only so much ear tugging you can do before the fangs come out. | ||
Ligne 221: | Ligne 425: | ||
Fact is, the security software included is for Ethical Hackers, aka White Hats, in the corporate world, and students in that area of expertise. Beyond that, the usefulness elludes me, and, if I want to swipe a signal, I'll go to McDonald' | Fact is, the security software included is for Ethical Hackers, aka White Hats, in the corporate world, and students in that area of expertise. Beyond that, the usefulness elludes me, and, if I want to swipe a signal, I'll go to McDonald' | ||
- | Now for the final analysis. Which one would I choose? | + | Now for the final analysis. Which one would I choose?** |
- | For my answer I went to fellow students and hackers, and let them give me comments. | + | La véritable question devient donc : l' |
+ | |||
+ | Non. M. Toutlemonde ne pourrait pas faire grand-chose avec de tels logiciels mais, honnêtement, | ||
+ | |||
+ | Le fait est que les logiciels de sécurité inclus sont destinés aux « Ethical Hackers », alias les « White Hats » (littéralement les chapeaux blancs), dans le monde de l' | ||
+ | |||
+ | Et maintenant, tout compte fait, lequel choisirais-je ? | ||
+ | |||
+ | **For my answer I went to fellow students and hackers, and let them give me comments. | ||
Although many were impressed by BackTrack, they found it difficult to use, and downright uncooperative when it came to added program acceptance. They also found it odd that wireless and Ethernet icons were gone, and several discovered what I did – if a signal drops, you won't know it until a webpage doesn' | Although many were impressed by BackTrack, they found it difficult to use, and downright uncooperative when it came to added program acceptance. They also found it odd that wireless and Ethernet icons were gone, and several discovered what I did – if a signal drops, you won't know it until a webpage doesn' | ||
Ligne 229: | Ligne 441: | ||
The biggest gripe? Having to use apt-get to install programs - often requiring searches to discover the proper command line for a given app. | The biggest gripe? Having to use apt-get to install programs - often requiring searches to discover the proper command line for a given app. | ||
- | The second most common complaint was about a lack of training for many of the security oriented programs, that often resulted in having to find tutorials online for assistance. | + | The second most common complaint was about a lack of training for many of the security oriented programs, that often resulted in having to find tutorials online for assistance.** |
- | They also agreed that running as root is just inviting a mistake - as one discovered when they did something to their network connection and it never worked again. | + | Pour pouvoir répondre à ma question, je suis allé voir d' |
+ | |||
+ | Bien que beaucoup soient impressionnés par BackTrack, ils le trouvaient difficile à utiliser et carrément peu coopératif pour ce qui concerne l' | ||
+ | |||
+ | La plainte la plus courante ? Devoir utiliser apt-get pour installer des programmes, ce qui, souvent, nécessite des recherches pour trouver la commande qu'il faut pour une appli donnée. | ||
+ | |||
+ | En seconde place venait le manque de formation pour beaucoup des programmes liés à la sécurité, ce qui entrainait le besoin de trouver de l'aide en ligne sous forme de tutoriels. | ||
+ | |||
+ | **They also agreed that running as root is just inviting a mistake - as one discovered when they did something to their network connection and it never worked again. | ||
BackBox fared better in that it was rated as easier to use, and much more cooperative when it came to adding programs that would work. Reviewers appreciated the inclusion of Synaptic Package Manager and Ubuntu Software Center, and they generally liked the Xfce desktop. | BackBox fared better in that it was rated as easier to use, and much more cooperative when it came to adding programs that would work. Reviewers appreciated the inclusion of Synaptic Package Manager and Ubuntu Software Center, and they generally liked the Xfce desktop. | ||
Ligne 241: | Ligne 461: | ||
As a result, I would have to give the nod to BackBox. Yes, it doesn' | As a result, I would have to give the nod to BackBox. Yes, it doesn' | ||
- | BackBox is much more accommodating to users with limited expertise; the educational aides won't require hocking the family car to pay tuition, and programs are easy to add as long as they normally would work in Ubuntu. | + | BackBox is much more accommodating to users with limited expertise; the educational aides won't require hocking the family car to pay tuition, and programs are easy to add as long as they normally would work in Ubuntu.** |
+ | |||
+ | Ils étaient également d' | ||
+ | |||
+ | BlackBox a obtenu de meilleurs résultats quant à la facilité d' | ||
+ | |||
+ | Mais c'est le bureau qui a également fait l' | ||
+ | |||
+ | Comme c' | ||
+ | |||
+ | En conséquence, | ||
+ | |||
+ | BoxBox se montre beaucoup plus conciliant envers les utilisateurs dont l' |
issue55/critique.1327764362.txt.gz · Dernière modification : 2012/01/28 16:26 de auntiee