Security Projects

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Security Projects News

StopCarnivore.org Website Launched

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A new site devoted to shutting down the FBI's Carnivore email surveillance system has launched, "Stop Carnivore", http://www.stopcarnivore.org. The site explains what Carnivore is, why it is wrong, what you can do, and how it hurts the Internet. Below is a quick summary on the major issues the site deals with. . . .

Linux developers hunt for kernel bugs

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Linux developers have begun an ambitious project to identify security problems with the open source operating system before they trouble end users. The Linux Kernel Auditing Project is an attempt to audit the Linux kernel for any security holes. The project . . .

KAIST Computer Remains Hacker Proof

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The Information Security Education Research Center (ISC) of the Korean Advanced Institute of Science and Technology (KAIST) said Sunday that no hackers among the 3,664 teams worldwide managed to conquer its third level server and win in the First World Information . . .

ZDNet hack-contest server disabled

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Exhibitionism at its worst. "Other interpretations exist. The hacking underground, for example, sees this sort of thing as part reconnaissance, and part publicity stunt, and one in which no truly elite cracker would participate for fear of having their best . . .

RootFest Opens Today

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

"The Midwest's largest computer security convention opens today in St. Paul's RiverCentre. RootFest organizers estimate that as many as 1000 people may attend RootFest this year. It is hoped that the con will be broadcast in both audio and video in . . .

Linux Kernel Auditing Project

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Brian Paxton writes, "It's an attempt to audit the linux kernel for any security vulnerabilities and/or holes and/or possible vulnerabilities and/or possible holes, and of course without adding more bugs or drawbacks to the existing kernels. The suggested kernels to be audited are 2.0.x kernel series , 2.2.x kernel series, and the 2.3.x/2.4.x kernel series. The group and it's work shall be dealt and worked with via a mailing list."

Solar Designer's OpenWall Kernel Patch

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Solar's kernel security enhancement patch is now available for the recently-released 2.2.16 Linux kernel. "This patch is a collection of security-related features for the Linux kernel, all configurable via the new 'Security options' configuration section. In addition to the . . .

Bastille Linux: A Walkthrough

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This article presents a walkthrough of Bastille Linux, a popular hardening program for Red Hat and Mandrake, available for free from Jon Lasser, Pete Watkins, myself, and the rest of the Bastille Linux project. This walkthrough won't be the kind . . .

The Arash Baratloo interview

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Here is an interview with the authors of Libsafe..."Arash Baratloo and Navjot Singh two of the primary developers for Libsafe, a free software library that protects against security exploits based on buffer overflow vulnerabilities. They work as members of . . .

Security holes going unpatched

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The CIO Council is asking every federal chief information officer to find and fix the lapses that made a top 10 list of critical Internet security threats. The list, released Thursday, includes problems that have solutions, but the solutions have . . .

SANS Top 10 Threats

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The System and Network Security group is is meeting with several key players in the information security arena on Friday to discuss and outline the 10 top security threats. "Tomorrow (June 1) the FBI, Justice Department, GSA, the CIAO . . .

Without Peer: Open Source Security

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Open source code is not infallible. It is prone to some of the glitches that plague its commercial counterpart. Yet, at the same time, it contains a number of safeguards and checks against any one person's mistake being carried too . . .