Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 528
Alerts This Week
Warning Icon 1 528

Stay Ahead With Linux Security Features

Filter%20icon Refine features
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security features

We found 0 articles for you...
102

Top Choices For Browsers With Built-In VPNs To Protect Online Privacy

Linux is widely regarded as a great OS for users looking to increase their safety online . That being said, using a Virtual Private Network (VPN) is an easy, convenient way to strengthen your online data and network security and protect your privacy and anonymity when using the Internet. . There are many great web browsers with built-in VPNs available that include privacy and browsing extras (ad tracker-blocking, private browsing, malware prevention) while eliminating the need to manually set up a VPN. These browsers are often simple to use, free even when registration is needed, and expansive since they typically have no data limits. In this article, we will introduce our top browsers with built-in VPNs, explore their features and capabilities, and discuss the main benefits and drawbacks of each. Then, you will be equipped with the knowledge to determine what browser best suits your needs. How Does a VPN Work? A VPN uses "virtual" connections routed through the Internet from a private network or a third-party VPN service to a remote site or person. VPNs help strengthen data and network security and mask online behavior from snooping third parties by creating an encrypted connection, or "tunnel," between your device and a remote server operated by the VPN service. This prevents hackers from being able to read the encrypted data upon interception. VPNs also hide your information from Intensive Supervision Programs (ISPs). Your IP address will be concealed by directing the network traffic through a specifically set-up distant server that is operated by a VPN host. VPNs are a great data and network security toolkit that can improve security posture online. What Are the Main Benefits & Drawbacks of Using a VPN? When determining whether or not to use a VPN, it is important to first understand the benefits and potential drawbacks you may encounter. Here are the benefits of using a trustworthy VPN. They: Protect your privacy online by disguising your IP, encrypting yourconnection, and making it truly anonymous. Improve security posture by giving the user a new IP address every time they go online, which can be enough to deter doxxing and Distributed Denial of Service (DDoS) attacks. Unblock websites to help you browse the web freely, especially in restrictive countries. Allow for private downloading and help you avoid copyright infringement notices. Help you avoid bandwidth throttling by disguising your traffic type to keep it from being restricted. Reduce the stress of staying up-to-date with the latest cybersecurity trends, as your information is protected from most data and cloud security breaches. Here are the potential drawbacks of using a VPN. You: Eventually, you will experience drops in connection speed despite the VPN’s claims to boost your internet speed. May never have complete data and network security and privacy. Free VPNs tend not to be fully secure. Paid VPNs provide stronger encryption and better security. Are not completely safe from website tracking. If you visit websites where you use session cookies and have to login with your information, companies record your real public IP address rather than your VPN public IP address. Could have difficulty configuring VPNs, which could harm the safety of your online browsing. When it comes to using a VPN on Linux, you may do a command line installation where you need to adjust the server yourself after downloading. Might notice that VPNs do not work as full antivirus and malware software , which means hackers could still bypass security if they are persistent enough. To achieve optimal protection, you should use a VPN in conjunction with a robust antivirus package. If you do experience a malware infection on your Mac, there are great malware removal tools you may wish to use. Do I Need a VPN? VPNs can protect your privacy, guarantee anonymity, and ensure data and network security. While you may not need one, VPNs are a great thing to consider to keep your onlinebehavior and identity away from prying eyes. With government agencies, ISPs, and cybercriminals increasingly threatening data privacy, now is an excellent time to begin using a VPN. Think about the downsides of continuing to operate without a VPN. You could jeopardize your privacy, security, and Internet activity and could be denied access to certain services and websites. This cryptography cybersecurity can be incredibly beneficial to your systems and servers. The decision is yours, but at LinuxSecurity we strongly recommend that you use a VPN! or those looking to enhance anonymity even further, especially across multiple browser identities or accounts, an antidetect browser can offer another powerful layer of protection. Best Browsers with a Built-in VPN Tor Browser Tor Browser is an excellent browser for users looking to protect their privacy and anonymity online. It uses layered encr yption to prevent hackers. ISPs and government surveillance agencies from tracking you. Tor even ensures that you surf the web anonymously. It offers several powerful security and privacy-centric features, including: The No Scripts and HTTPS Everywhere extensions increase your digital privacy. Allowing users to manually or automatically delete cookies and other browsing data stored on their devices. Protection against browser fingerprinting. However, the Tor Browser has two notable drawbacks. Tor doesn’t provide real data encryption but, instead, offers layered encryption that protects the data within an onion network. Beyond the Tor exit node, the data is vulnerable to spying because it is not encrypted anymore. Also, Tor hops your traffic via three relay nodes, which impacts the overall speed, a factor that can be pretty frustrating when browsing the web. Regardless, Tor is overall very effective in protecting digital privacy and ensuring data and network security, factors that cannot be overlooked in the context of today’s threat landscape. Mozilla Firefox Mozilla Firefox is among the most popular browsers. It is user-friendly and offers multiple privacy-focused features, including Enhanced Tracking Protection, Total Cookie Protection, DNS over HTTPS, and Fingerprinting, all of which can help you improve your security posture. The built-in browser VPN is a great option for anyone concerned with their online privacy and security, as Mozilla Firefox: Offers device-level encryption and uses the advanced WireGuard protocol to mask your IP address and encrypt your network activity. Provides for 400 servers in 30 locations, including the United States, Austria, Canada, France, Germany, and the UK. Follows a no-log policy, so you can be confident that your activity and connection logs are not being logged and shared. Comes with no bandwidth restrictions, so you can browse the web at reliable speeds. The VPN built into Mozilla Firefox is available for Linux, Android, Windows, iOS, and Mac. It offers impressive functionality on Linux and is arguably the best browser VPN for Linux users. The Mozilla VPN feature is not free, but it is well worth the small fee! Brave Browser The Brave Browser is a Chromium-based web browser with an intense focus on privacy and security that helps to achieve g reater online anonymity without sacrificing functionality. Brave offers a built-in VPN feature for an additional $9.99 per month and includes: The Brave Firewall + VPN feature blocks trackers, cookies, and malicious scripts from interfering with your browsing experience and threatening your safety. Partial encryption using HTTPS site encryption to ensure data and network security and prevent tracking. Protection against WebRTC leaks. A Brave Shield feature to prevent irrelevant and unwanted ads from being displayed and interrupting your browsing experience. Brave is easy to use, has lightweight cryptography (protection won’t consume much of your space), and offers a sleek user interface, all of which help with data and network securityand strengthen Brave’s privacy-enhancing technology. You can use Brave browser on all popular operating systems, including Linux, Android, iOS, macOS, and Windows. Opera Opera browser is the oldest browser, as it has been in use since 1995. The browser has over 350 million active users and offers a faster, smarter, and significantly more secure browsin g experience than other default browsers. Opera comes with a selection of features designed to offer maximum privacy and security, including a built-in ad blocker and protection against tracking, phishing, and malware. Opera protects your Internet traffic within the browser and prevents you from needing to download additional software or browser extensions. The Opera browser built-in VPN offers: An automatic ad and tracker blocker that prevents ads and trackers from disturbing your browsing experience or threatening your privacy. Consistently fast speeds for browsing the web. Servers in five international locations: The United States, Canada, Germany, Singapore, and the Netherlands. A strict no-log policy, so you don’t have to worry about logging your data or infringing on your privacy. The built-in Opera browser VPN provides excellent functionality, robust privacy-enhancing technology, and numerous data and network security controls. However, the VPN comes with a 500MB data limit, which could potentially restrict your activities. Aloha Browser Aloha is an excellent mobile browser for the privacy- and security-conscious user. It allows you to surf the web without le aving any tracebacks., is user-friendly, and has a clean and easy-to-use interface, making it ideal for both advanced and beginner users. The Aloha browser offers an integrated VPN that provides additional online privacy protection and enhances your web browsing experience. The Aloha browser VPN includes benefits like: Encrypting traffic and increasing your anonymity online. Conserve your mobile data and block ads to improve the speed atwhich you can load web pages. Preventing trackers from gathering your data so they cannot log or share browsing data. Using hardware acceleration that loads pages up to two times faster than other browsers. Secure your downloads using the file manager feature and lock your folder with fingerprints or passcodes. A fully-featured media player with a VR feature that allows you to watch movies and listen to music. It is important to note that since Aloha is only a mobile browser, not all users can benefit from it, as more people are focused on the data and network security of their operating systems. Epic Privacy Browser Epic Privacy is a secure Chromium-based browser that blocks intrusive ads, crypto mining, fingerprinting, and trackers. In fact, it blocks over 600 tracking attem pts in an average browsing session! The browser offers an impressive built-in VPN extension that keeps your online activities private and secure. The Epic privacy browser built-in VPN is among the best browser VPNs because: It uses encrypted proxies to hide data and your IP address and allows you to access blocked sites. The “Do Not Track” feature prevents trackers from following you from website to website. None of your browsing history is recorded or sold to third parties. Rather, your browsing data is permanently deleted after each session. It protects from WebRTC leaks to strengthen your online data and network security. The built-in VPN offers server access in eight different locations. Final Thoughts on Our Top Browsers with a Built-in VPN Linux is an excellent OS for privacy- and security-conscious users. That being said, using a VPN is a simple and effective way to strengthen your privacy, security, and anonymity online. The browsers with built-in VPNs that we’ve introduced in this article make using a VPN even more convenient and straightforward. Consider utilizing one of them as a privacy-enhancing technology that can guarantee stronger dataand network security. Are you using one of these built-in browser VPNs? How has your experience been? Comment below- we’d love to hear your thoughts! . Explore top browsers with built-in VPNs that enhance online privacy and security. Learn about features and options.. linux, widely, regarded, great, users, looking, increase, their, safety, online. . Brittany Day

Calendar%202 Apr 03, 2023 User Avatar Brittany Day
102

Guardian Digital EnGarde Secure Linux: Next-Gen Proactive Protection

Award-winning secure operating platform combines ease of management with unsurpassed security as a primary focus.. ALLENDALE, NJ-February 9, 2004 -- Guardian Digital, Inc., the world's premier open source security company, announced an update to the next generation, award-winning platform that delivers features designed to ease the process of building a complete Internet presence and the level of security necessary to prevent system compromise. EnGarde Secure Linux leverages the best open source applications available to provide secure Internet connectivity, user privacy, Web and email functions, and intrusion detection. "The proactive security improvements inherent into its design are one of the primary factors in the success of EnGarde," writes Pete O'Hara, vice president of engineering at Guardian Digital. "Coupled with the most sophisticated open source Web-based management system, EnGarde consistently protects users from even debilitating kernel security vulnerabilities where other Linux vendors fail." EnGarde features secure web-based management of all functions, including Internet edge services (Web, DNS, email), integrated intrusion detection, cryptography, improved authentication and access control, as well as protection from many forms of intrusion such as buffer overruns and denial of service attacks. Enhanced availability and access control mechanisms delivers a potent combination suitable for the largest enterprise. "Security management is an essential component of any successful online operation. Mitigating security risks through the use of a dynamic, rapidly-evolving development process bolstered by collaboration of the open source community provides the most efficient form of protection," writes PaulBrisson, orthopedic spinal surgeon, New York Spinal Care. "EnGarde Secure Linux and its secure-by-design approach combined with the security benefits engineered by Guardian Digital offer the best in proactive protection," continues Brisson. EnGarde Secure Linux features the Guardian Digital WebTool, a web-based interface used to securely manage network and server operations. Emphasizing increased security, performance, and an available 2.6 Linux kernel, EnGarde Secure Linux features include: Simple and secure web-based management. Core Internet services including Web, DNS, and email system management. Unlimited virtual domains. Comprehensive backup/recovery system. Sophisticated access control mechanisms. Integrated network and host intrusion detection Guardian Digital Secure Network to provide easy access to security and system updates. Mandatory Access Control (MAC) using the Linux Intrusion Detection System to provide sophisticated access control and prevent Trojan horse attacks. Latest cryptography tools including built-in web-based key management for building secure Web sites. Hardened kernel and user tools providing highly resilient protection from intruders. Gateway firewalling using stateful packet inspection. Security Control Center to monitor system activity. Upgraded core components including Linux kernel 2.4.22 and development tool chain. Unparalleled protection from the latest Internet threats including denial of service, Trojan horse, spoofing, Microsoft worms. Other new features in EnGarde Secure Linux include new executive summary reportingfunctionality that allows IT Managers to receive and deliver comprehensive graphic reports on server activity and security alerts, scalability improvements, and enhanced journaling filesystem support. See Guardian Digital Makes Email Safe For Business - Microsoft 365, Goo.... for a complete overview of features and information on Guardian Digital enterprise products. Pricing and Availability EnGarde Secure Linux is now available for download from Guardian Digital and includes a free 30-day subscription to the Guardian Digital Secure Network to obtain system and security updates. An annual subscription to the GDSN is available for $229 per year and includes thirty days of email installation and configuration support. About Guardian Digital, Inc. Guardian Digital, the premier open source security company, offers the first secure, open source Internet infrastructure system. Based on Guardian Digital's operating system platform, EnGarde, the company provides enterprises with the software and services necessary for secure computing on the Internet. By leveraging the merits of the collaborative open source design model, coupled with the company's security and Internet expertise, Guardian Digital solutions maintain the highest degree of security and reliability. Founded in 1999, Guardian Digital is headquartered in Allendale, New Jersey. For additional information, please visit Guardian Digital Makes Email Safe For Business - Microsoft 365, Goo.... or call 1-866-GD-LINUX . Contact: Alison Parker Guardian Digital, Inc. Corporate Communications 201-934-9230 This email address is being protected from spambots. You need JavaScript enabled to view it. . SafeNet Technologies unveils Fortify Secure OS, a powerful open-sourcesolution dedicated to user-friendly management and enhanced protection.. Secure Linux, Open Source Platform, Network Protection, Email Security, Intrusion Detection. . Brittany Day

Calendar%202 Feb 10, 2004 User Avatar Brittany Day
102

Guardian Digital Customers Securely Protected From Kernel Flaw

Guardian Digital, the world's premier open source Internet security company, announced today that its customers were not impacted by the recent kernel security vulnerability that afflicted other open source vendors and their customers.. ALLENDALE, NJ -- December 4, 2003 -- Guardian Digital, the world's premier open source Internet security company, announced today that its customers were not impacted by the recent kernel security vulnerability that afflicted other open source vendors and their customers. As a result of the planning and secure design of EnGarde Secure Linux, the company's flagship product, Guardian Digital customers are securely protected from a vulnerability that lead to the complete compromise of several high-profile open source projects, including those belonging to the Debian Project. "Through a coordinated effort with the open source community and the early warning system developed by Guardian Digital, the kernel currently in use by our customers is not affected," writes Ryan W. Maple, lead security architect at Guardian Digital. Engineered from the ground up with specific regard to security, EnGarde Secure Linux incorporates intrusion alert capabilities, mail and network management services, improved authentication and access control, strong cryptography, and complete SSL secure Web-based administration capabilities. As is shown by this recent vulnerability, proper Internet security design is critical to the reliable operation of business today. A recent report Internet Security Systems', a leading security research firm, revealed that compared to the previous three months, the number of security threats have risen 9 percent in the third quarter, and the more serious incidents, confirmed attacks or those thatpresented an unusual risk, rose by 15 percent. "When learning of the latest Linux kernel vulnerability and speaking with Guardian Digital security advisors, I was assured that our systems were safe. My confidence in Guardian Digital continues to grow and I am once again reminded of why I purchased Guardian Digital software in the first place," writes Scott DeKramer, IT Director, Implex Corporation. Recovering from a security event is significantly more costly than preventing it from happening. Guardian Digital software provides a level of assurance that online assets will remain secure. David Dittrich, senior security engineer for University of Washington's Computing & Communications Department, recently did a study estimating the cost of computer security breaches. His finding reported that it can cost companies nearly $5,000 to investigate the cause of a single security incident. He advised that being prepared for such an occurrence can significantly reduce attacks resulting in a much less financial burden. About Guardian Digital Guardian Digital, the premier open source security company, offers the first secure, open source Internet infrastructure system. Based on Guardian Digital's operating system platform, EnGarde, the company provides enterprises with the software and services necessary for secure computing on the Internet. By leveraging the merits of the collaborative open source design model, coupled with the company's security and Internet expertise, Guardian Digital solutions maintain the highest degree of security and reliability. Founded in 1999, Guardian Digital is headquartered in Allendale, New Jersey. For additional information, please visit https://guardiandigital.com/ or call 1-866-GD-LINUX . Contact: Alison Parker Guardian Digital, Inc. Corporate Communications 201-934-9230 This email address is being protected from spambots. You need JavaScript enabled to view it. . Sentinel Tech shields its users from a critical vulnerability in the Linux kernel by employing robust architecture and anticipatory strategies.. Kernel Security Flaw, Open Source Protection, Internet Security Solutions. . Brittany Day

Calendar%202 Dec 04, 2003 User Avatar Brittany Day
102

Comprehensive Guide To Internet Security Risk Assessment Methodologies

This article is the second in a series that is designed to help readers to assess the risk that their Internet-connected systems are exposed to. In the first installment, we established the reasons for doing a technical risk assessment. In this installment, we'll start discussing the methodology that we follow in performing this kind of assessment.. This article is the second in a series that is designed to help readers to assess the risk that their Internet-connected systems are exposed to. In the first installment, we established the reasons for doing a technical risk assessment. In this installment, we'll start discussing the methodology that we follow in performing this kind of assessment. Why all the fuss about a Methodology? If you ever read anything SensePost publishes on assessments, or if you attend our training, you'll notice that we tend to go on a bit about methodology. The methodology is the set of steps we follow when performing a certain task. We try and work according to methodologies with just about everything we do. We're not fanatical about it, and the methodologies change and adapt to new and different environments, but they always play a big role in the way we approach our work. Why such a big fuss then? There are a few good reasons for performing assessments according to a strict methodology: Firstly, it gives us a game plan . Rather then stare blankly at a computer screen or a network diagram, an analyst now has a fixed place to start and a clear task to perform. This takes the whole "guru" element out what we do. The exact steps that we will follow are clear, both to us, and to the customer, from the outset. Secondly, a methodology ensures that our work is consistent and complete . I've worked on projects where the target organization has in excess of 150 registered DNS domains. Can you imagine how many IP addresses that eventually translates to. I don't have to imagine - I know it was almost 2000. Consider how hard it must be to keeptrack of every DNS domain, every network and every IP to ensure that you don't miss something. Consider also what happens when the actual "hacking" starts (we'll get to this later) and the analyst's heart is racing. A strict methodology ensures that that we always cover all the bases and that our work is always of the same quality. This holds true, no matter how big all small the environment is that you're assessing. Finally, our methodology gives our customers something to measure us against . Remember, to date there are really no norms or standards for technical assessment work. How does the customer know that she's getting what she paid for? This is an especially pertinent question when the assessment findings are (how can I put this?) dull. By working strictly according to a sensible methodology with clear deliverables at each stage we can verify the quality of the assessment even when there's very little to report. A Methodology that Works I'm completely sure that, when it comes to security assessment, there's more then one way to skin the cat. What follows is a description of a methodology that we like to use when performing security assessments over the Internet. It's certainly not the only way to approach this task, but it's one way that works, I believe. 1. Intelligence Gathering The first thing we do when we begin an assessment is to try and figure out who the target actually is. Primarily we use the Web for this. Starting with the customer's own Web site(s), we mine for information about the customer that might be helpful to an attacker. Miscellaneous tidbits of useful data aside, our primary objective is to derive the DNS domain names that the target uses. If you're assessing your own infrastructure, you may already have this information but if the organization is big, it can be a fascinating exercise. Later, these domain names will be mapped to the IP addresses we will actually analyze. Some companies have a small Internet presence, anddiscovering the DNS names they use may be simple. Other companies we've worked with have hundreds of domains, and discovering all of them is no mean feat. How do we get the DNS domain names? Well, usually we have an e-mail address, the company's name or some other logical place to begin. From there we have a number of techniques: We use search engines to search all instances of the company's name. This not only provides links to the company's own site (from which DNS domain information can be easily derived), we also obtain information about mergers and acquisitions, partnerships and company structure that may be useful. We use a tool like httrack to dump all the relevant Web sites to disk. We then scan those files to extract all mail and HTTP links, which are then parsed again to extract more DNS domains. Then, we use the various domain registries. Tools like geektools.com, register.com and the like are simple and can often be used in one of two ways: To help verify whether the domains we have identified actually belong to the organization we are assessing. To extract any additional information that may be recorded in a specific domain's record. For example, you'll often find that the technical contact for a given domain has provided an e-mail address at a different domain. The second domain then automatically falls under the spotlight as a potential part of the assessment. Many of the registries provide for wildcard searches. This allows us to search for all domains containing a certain string, like "*abc*". I would use such a search to identify all the domains that may be associated with the company ABC Apples Inc , for example. Then, we need to apply some human intelligence - using the information we read on Web sites, company reports and news items we attempt to make logical jumps to other domains that may be relevant to our analysis. The output of this phase is a comprehensive list of DNS domains that are relevant to the targetcompany. You'll notice that the next phase of the assessment may provide additional domain names that weren't found during this phase. In that case, those domains are used as inputs during this phase and the entire process is repeated. Phases 1 and 2 may recur a number of times before we've located all the relevant domains. Typically, we'll check this list with the customer once we're done to ensure that we haven't missed anything or included something inappropriate. 2. Foot Printing At the start of phase two we have a list DNS domains - things like apples.com, apples-inc.com, applesonline.com, apples.co.uk, etc. The reasons these domains exist is to provide Internet users with a simple way of reaching and using the resources they require. For example, instead of typing , a user simply needs to remember https://sensepost.com/. Within a domain, therefore, there are a number of records - specific mappings between machine names and their actual Internet Protocol (IP) numbers. The objective of this phase is to identify as many of those IP/name mappings as we possibly can in order to understand which address spaces on the Internet are actually being used by the target organization. There are a few different techniques for identifying these mappings. Without going into too much detail, these techniques are all derived from the same assumptions, namely: Some IP/name mapping must exist for a domain to be functional. These include the name server records (NS) and the mail exchanger records (MX). If a company is actually using a domain then you will be able to request these two special entries. Immediately you have one or more actual IP addresses to work with. Some IP/name mappings are very likely to exist on an active domain. For example, "www" is a machine that exists in just about every domain. Names like "mail", "firewall" and "gateway" are also likely candidates. We have a long list of common names that we test. This is by no means a watertight approach butone is more often lucky then not. An organization's machines usually live close together. This means that if we've found one IP address, we have a good idea of where to look for the rest of the addresses. The Name -> IP mapping (the forward lookup), and the IP -> Name mapping (the reverse lookup) need not necessarily be the same. The technology is fundamentally verbose. DNS, as a technology, was designed for dissemination of what is essentially considered "public" information. With one or two simple tricks we can usually extract all the information there is to be had. The DNS zone transfer - a feature of DNS literarily designed for the bulk transfer of DNS records - is a fine example of this. Other, craftier, techniques fall beyond the scope of this paper. Once we have all the relevant DNS names we can find, we attempt to identify the distinct network "blocks" in which the target organization operates. As stated previously, IPs tend to be grouped together. The nature of IP networking is to group addresses together in what are known as subnets. The expected output of this phase is a list of all the IP subnets in which the target organization has machines active. At this stage, our broad reasoning is that if we find even a single IP in a given subnet we include that entire subnet in the list. The technically astute among you will already be crying "False assumption! False assumption!" and you'd be right. But bear with me. At this stage we tend rather to over-estimate then to under-estimate. Later, we will do our best to prune the list to a more accurate depiction of what's actually there. 3. Vitality We ended the last phase with a list of IP subnets in which we believe the target organization to have a presence and a horde of technocrats objecting loudly to our assumptions about the subnet size. Let's quickly make a list of the some of the facts we need to know before we can move on with the process: An organization does not need to own the entire subnetin which it operates. IP addresses can be lent, leased or shared. Nor do all an organization's IPs have to be grouped together, they can be as widely spread across the Internet as they wish. Just because a Name / IP mapping exists for a machine, doesn't mean that machine actually exists. Conversely, just because a Name / IP mapping doesn't exist for a machine, doesn't mean the machine doesn't exist. There are thousands of nameless addresses on the Internet. Yes, it's sad, but true nevertheless. Without a route to describe how an IP address can be reached, that address can never be used on the Internet So we see that, although DNS gives us a logical starting point for our search, it by no means provides a comprehensive list of potential targets. This is why we work with the rather loose subnet definitions we derived in the previous phase. The objective of the "Vitality" phase of the assessment is to determine, within the subnet blocks that we have, which IP addresses are actually active and being used on the Internet. We now leave the wonderful world of DNS behind us, and begin to concentrate solely on the IP address space. So how does one determine if an address is active on the Internet or not? Well, let's recall the third "fact" from our list above. If there's no route to a given IP subnet, that subnet is as good as dead. Various core routers on the Internet graciously allow technicians and administrators to query them regarding routes to any given address. At the time of writing, one such router is route-views.oregon-ix.net . Such a router can't tell us that an IP address is alive. If there's no route for a subnet on the core routers, however, then we can conclude that all the IPs in that subnet are dead. The next, and probably most the obvious technique is the famous IP "ping". Pinging works just like sonar. You send a ping to a specific address and the machine responds with a "pong" indicating that it is alive and received your request. Ping is astandard component of the Internet Protocol (IP), and machines that talk IP are compelled to respond when they receive a ping request. With simple and freely available tools we are able to ping an entire subnet. This is know as a "ping scan". Without going into too much detail, the response of such a ping scan can be interpreted as follows: A reply from an IP address indicates that the address is probably in use and accessible from the Internet. Multiple replies from a single IP address indicate that the address is probably actually a subnet address or a broadcast address and suggest a subnet border. No reply can only be interpreted to mean that the machine is not replying to IP ping requests. I realize that the latter point is a bit vague, but that really is the only conclusion that can be drawn from the information available. I said that all machines that speak IP are obliged to respond to ping requests. Why not simply conclude that if the IP doesn't respond, it isn't being used? The confusion is introduced by modern network security products like firewalls and screening routers. In the real world, one often sees networks configured in such a way that the IP ping packet is blocked by the firewall before the packet reaches the machine. Thus the machine would respond if it could, but it's prevented from doing so. So we haul out the heavy artillery. Just about every machine on the Internet works with a series of little Internet "post boxes" called ports. Ports are used to receive incoming traffic for a specific service or application. Each port on a machine has a number and there are 65536 possible port numbers. A modern machine that is connected to the Internet and actually functioning is almost certain to be using at least one port. Thus, if an IP address does not respond to our ping request, we can further probe it using a tool called a "port scanner". Port scanners are freely available software utilities that attempt to establish a connection to every possibleport within a specified range. If we can find just one port that responds when probed, we know that the IP is alive. Unfortunately, the amount of work required to probe all 65,000 plus ports is often prohibitive. Such an exercise can takes hours per single IP address and days or even weeks for an entire range. So we're forced to make yet another assumption: If an IP address is active on the Internet, then it's probably there for a reason. And there are only so many reasons to connect a machine to the Net: The machine is a Web server (and thus uses port 80 or 443) The machine is a mail server (and thus uses port 25) The machine is a DNS server (and thus uses port 53) The machine is another common server - FTP, database, time, news, etc) The machine is a client. In this case it is probably a Microsoft machine and uses port 139. Thus, we can now modify our scan to search for only a small number of commonly used ports. This approach is called a "host scan". It is by no means perfect, but it generally delivers accurate results and is efficient enough to be used with large organizations. The common ports we scan for can be adjusted to better suite the nature of the organization being analyzed, if required. The nmap network utility (available from https://insecure.org/ ) is a powerful tool that serves equally well as ping scanner and a port scanner. Thus, by the end of this phase we have fine-tuned our list of IP subnets and generated a list of actual IP addresses that we know to be "alive" and that therefore qualify as targets for the remainder of the process. At this point, our findings are usually presented to the customer to ensure that we're still on the right track. Conclusion That concludes the first part of our discussion of Internet assessment methodology. In the next installment in this five-part series on Internet Risk Assessments, we will continue to discuss methodology, including: visibility, vulnerability scanning, and analyses ofWeb applications. . Uncover effective strategies for online risk evaluation aimed at assessing safe networks and enhancing your protection protocols.. Internet Security Assessment,Risk Evaluation Methods,Methodology for Security. . Brittany Day

Calendar%202 Jul 18, 2002 User Avatar Brittany Day
102

BINDv9: Paul Vixie And David Conrad Discuss Security Enhancements

In this interview, Paul Vixie and David Conrad talk about the Internet Software Consortium, the changes in the latest major version of bind, the security features designed into it, and the future of Internet security. . R ecently I had an opportunity to speak with Paul Vixie and David Conrad, two Internet veterans and developers of the Berkeley Internet Name Daemon (BIND), the software that translates Internet host names to IP addresses. LinuxSecurity.com: Can you give us a brief description of your background? How did you become involved with BIND and eventually come to form the ISC? Paul Vixie: I started working on BIND in 1988 while employed at Digital Equipment Corp. (DEC) which was later bought by Compaq. My job was to run their corporate internet gateway (DECWRL) in Palo Alto, and also to run the servers for the DEC.COM zone and work with other parts of the company to allocate subdomains on a global basis (we had about 400, which was a lot at that time.) One of the biggest sources of operational instability in my (DEC's) gateway was the sleazy, icky, rotten code produced by U C Berkeley in the previous decade, and I quickly found myself up to my armpits in Sendmail and BIND muck. Eventually it became known that I had a stable version of BIND running at DECWRL, and folks who heard about this asked me for copies. I published kits on my FTP server and folks started not only picking up my kits but running them and submitting patches (both enhancements and bug fixes). Soon it was time for UCB to ship another BSD tape (4.3-Reno, I think) and they included my version of BIND rather than their own. UCB BIND was dead, and DECWRL BIND had taken its place. In 1993 I left DECWRL to return to my private consulting practice. I found that the BIND community expected me to "take BIND with me" -- it was clear that noone remaining at DECWRL had any interest in it. So I continued to publish new BIND kits independently. Rick Adams, then of UUNET, evidenced a *very*strong desire that BIND be worked on, and had the "old nonprofit" part of UUNET issue me a grant to do just that. In 1994, Rick and I decided that other companies should also be helping to fund this piece of critical infrastructure (since it was by that time clear that ISO was dead and that TCP/IP would be the basis for all public data networking), and we founded ISC as a funding clearinghouse to support BIND and similar software. David Conrad: Started working with the Internet around 1983 as team leader of a joint IBM/University of Maryland project for the development of a commercial TCP/IP on the IBM PC product. Leaving UMD in 1990, I worked as a researcher at the University of Hawaii on the PACCOM project, providing the first Internet connectivity to various Asia Pacific countries. I moved to Japan in 1992 and helped start up the first commercial ISP in Japan, Internet Initiative Japan, Inc. In 1994, I was asked to create and run the Asia Pacific Network Information Center, the Regional Internet Registry for the Asia and Pacific Rim region which I did until 1998. Returning to the US in 1998, I became the Executive Director of ISC and helped set up (what became) Nominum with Paul. My involvement with BIND came with the job (ED of ISC), however I used and administered BIND (of various versions) at pretty much every job I had. LinuxSecurity.com: BINDv9 is a 'major rewrite' from previous versions. Can you explain to us the reason for this rewrite and what new features have been added with regard to security? Paul Vixie: Because every bit of effort I ever put into BIND, from version 4 to version 8, was patchwork. The basic sleazeware produced in a drunken fury by a bunch of U C Berkeley grad students was still at the core of BIND. In 1998, Jerry Scharf, who was the Executive Director of ISC, convinced the remaining UNIX vendors and a few government agencies that the only way to support all of the new DNS protocol enhancements was tototally rewrite BIND. That work is substantially complete as of last month. The major feature isn't security as much as it is robustness. BIND9 was written by a large team of professional software developers who had enough time and enough money to "get it right." BIND9 is auditable in ways which BIND8 and BIND4 never were. It will support the next generation of DNS protocol evolution, as well as back end database support, security (both transactional and authenticity), portability, abstract user and management interfaces, SNMP, and everything else that's needed to be a robust commercial product in the Internet of Y2K and beyond. Nominum, Inc., was founded in 1999 to carry the DNS torch commercially, since ISC as a nonprofit was not able to move aggressively enough. David Conrad: Actually, BINDv9 is a complete rewrite. There is no significant code shared between BINDv8 and BINDv9. BIND version 8 evolved almost organically over about 17 years with little thought given to coherence or design. It is architecturally unsuited to further development of any significance, particularly given the complexity of the new standards being produced by the IETF in the areas of IPv6 and DNS security enhancements. For example, one of the requirement of the new version of BIND was that it scale with multi-processor machines. Putting multi-processor support into BIND version 8 would likely have taken more effort than it took to implement the entirety of BIND version 9 due to the requirements of data locking, concurrency control, etc. Security was a key consideration in design -- BINDv9 was designed to run without privileges (where possible) and in a chrooted environment. We used a "programming by contract" paradigm during implementation which helps insure that parameters to all routines are verified for correctness. We've also done several audits of the code, in particular those areas of the code that deal with network input. On the standards front, BIND version 9supports the full DNSSEC standard (with the exception of supporting wildcards in signed zones) and IETF standardized TSIG (HMAC-MD5) and all the other security related RRs. Both of these enhancements will enable the DNS infrastructure to be more secure which will permit additional services and applications to be built on top of the DNS. LinuxSecurity.com: Can you explain exactly what DNSSEC is and why a site would want to use it? Paul Vixie: DNSSEC is a data authenticity model. In the normal insecure DNS, a client has no way to "prove" that the answer it has received actually came from the owner of the zone it purports to be part of. (A zone is like a parent domain.) With DNSSEC, the protocol has been amended to support distributed keys and signatures in the "public key cryptography" model so that a client who wants to be *sure* that an answer is "authentic" has a means of doing so. David Conrad: The only thing I'd add would be that we're beginning to see the development of applications for DNSSEC, such as LADON ( ). LinuxSecurity.com: Are there any features that you expect to be more fully implemented as we continue through the 9.x version? Paul Vixie: That depends on the market. I've listed some of the things I know folks want, earlier above. The point of BIND9 was to make it once again possible to add features to BIND. BIND8 was "full." David Conrad: The requirements we've heard so far are support for Microsoft's GSS-TSIG (a not-yet-standard private key transaction protocol that Microsoft is using in Win2K), support for multi-lingualization of the DNS, and support for building/running BIND version 9 without pthreads. There are still a couple of areas where we're deficient in support of standards, e.g., we don't support using DNSSEC with wildcards and a BIND version 9.0.0 slave does not forward dynamic updates to the master as it should according to the RFCs. Our intent is to fully implement the standards(and/or help revise the standards to make them more useful to the Internet community). Another area that we know needs some work is in the resolver. Due to the requirements of DNSSEC and A6 support, we chose to create a "lightweight resolver daemon" with get*by*() routines which call this resolver daemon (similar in concept to Sun's "ncsd"). However there are a few areas that this can be improved and we're looking at this right now. LinuxSecurity.com: Why is nslookup going away? When do you expect this to happen? Can you give us an example of how to use 'dig' or 'host' as a substitute? Paul Vixie: nslookup's functionality will probably return in some form, since a lot of people seem to like it. The existing BIND8 implementation of nslookup is very closely bound to the internal API of BIND8, which does not exist in BIND9. Generally, "dig NAME RRTYPE" is all most people need to know, but if it's important to direct a query to a particular server then the syntax is "dig NAME RRTYPE @SERVERADDRESS". Lastly, if what you want is a zone transfer (which nslookup implemented in its "ls" command), the syntax is "dig NAME axfr @SERVERADDRESS", in other words, use an RRTYPE of "axfr". David Conrad: The behavior of nslookup is suboptimal in many areas, giving weird or un-useful error messages, however it is difficult to simply fix nslookup as many people rely on the weird behavior (particularly in scripts). The functionality provided by nslookup will likely continue (given how many people have written scripts that require and are used to using nslookup), but we didn't have time to do the full revision we wanted, so we give a warning suggesting people use dig instead. LinuxSecurity.com: Some other DNS server implementations state one of their primary development goals is to be as secure as possible. Specifically, Dan Bernstein has posted a $500 reward to the first person that can find a security hole with his name server implementation. Wassecurity a primary design goal for BIND? Paul Vixie: No, it was an indirect goal. We wanted to produce a rock solid, commercial grade, open source DNS implementation in the tradition of BIND and with high compatibility with BIND. One important side effect of all that is security. David Conrad: I can't speak to earlier versions of BIND (I wasn't involved in their design), but security was among the core requirements of the BIND version 9 project. LinuxSecurity.com: Can you explain how security fit in to the new implementation? Do you have any feelings on how the two development processes differ? Paul Vixie: Nothing really comes to mind here, except that Bernstein's software does not support either DNSSEC or TSIG, and as far as I know there are no plans to implement either one. BIND implements both. Even Microsoft implements TSIG. David Conrad: According to Bernstein's definition of "security hole", yes. Of course, $500 will almost certainly be in the noise compared to the cost of recovering from a breach that would meet Bernstein's definition. Generalizing, BIND version 8 has been hacked on forever and it is really unpleasant to work on. I don't think there is anyone that would choose to work on it except under some form of duress :-). As for working on BIND version 9, it was funded by a bunch of organizations and the development was outsourced to Nominum, Inc. with the requirement that the results of the development be Open Source. As a result, the development of BINDv9 was more along the lines of a traditional large scale development project with a set of requirements specified by customers (funders/ISC) which we at Nominum did our best to meet. These requirements significantly constrained the design. In particular, BIND version 8 backwards compatibility, DNSSEC and A6 support, full RFC conformance, and performance considerations (i.e., thousands of queries per second) implied the architecture that resulted. In the case of an individual, acting alone, no such constraints apply and entirely different architectural decisions can be made. I will note that Bernstein's djbdns does not support DNSSEC, A6, DNAME, bitstring labels, Dynamic DNS, outgoing AXFR, IXFR, and other of the more modern features of the DNS. We did not have the luxury(?) of ignoring IETF standards and prefer to work and play well with others. LinuxSecurity.com: What are your thoughts on the recent RSA patent expiration? How will that affect commerce on the Internet, companies relying on that algorithm, and programs that use it, such as OpenSSL ? Paul Vixie: It will allow BIND to be used in more places, since some redistributors were forced by this patent to edit BIND's sources to remove the cryptographic features. It's unlikely that this will change the rate of DNSSEC's adoption. David Conrad: I look forward to seeing significantly increased use and interest in developing applications based on the RSA algorithm. Hopefully, the easing of US crypto controls earlier this year doesn't mean that someone has figured out how to factor large primes trivially... :-) LinuxSecurity.com: What do you see as the most significant trends or developments in computer security in the next few years? Paul Vixie: We have to make the technology more available and more usable to end users. Security has to be end to end, and the endpoints right now are very weak since end-user security is either expensive, complex/unusable, fragile, or all three. Usually it's all three. I expect DNSSEC to be used as a key distribution platform for other applications, including shell access, e-mail, and file exchange. Eventually we have to make good security ubiquitous or the "haves" will continually raid and control the "have nots". David Conrad: Seeing computer security as primarily risk assessment and management instead of site or application hardening. LinuxSecurity.com: Do youthink Linux has a place in the data center as a secure platform for commerce in the state that it's currently in? What do you think needs to change with regards to security and Linux? Are there any root servers that run Linux or other Open Source platforms? Paul Vixie: Some versions of Linux have become remarkably mature in the last few years. Now that there's a growing stable of companies providing commercial support, I think we'll see Linux become a respected component of enterprise information management strategies alongside BSD/OS and FreeBSD. Both Linux and BSD have already proven their strengths in the front end, and when they filter out to the back end I think we'll see the end of the historic ABI/API captivity strategies of the big iron vendors, not to mention Microsoft. I also note that Mac OS X is BSD-based. This means we've finally gotten our point across, and open source is viable in both the long and immediate term. David Conrad: Linux most assuredly currently has a place in the data center as a secure platform for commerce. There is a fine line to be drawn between usability and security. I personally feel that Linux (or rather, the popular distributions) may err on the side of allowing too many applications and services to exist and/or default to on. From my experience, it is difficult to fully audit contributed code (the BIND v8.2 & v8.2.1 NXT bug that has caused such difficulties was a result of a bug in code donated to us, ironically enough, from a large firm that focuses on computer security) and Linux is, almost by definition, contributed code (from FSF, ISC, etc.). Simplifying distributions would probably tend to increase security (while possibly decreasing usability, at least for somebody). Each root server operator makes their own decision about what architecture/OS/nameserver is used. None that I'm aware of run Linux. A couple run FreeBSD, I believe. LinuxSecurity.com: What are some of the biggest challenges you facewhen dealing with security? Paul Vixie: No comment comes to mind. David Conrad: The complexity of the recent IETF standards results in a lot of complexity in the code which increases the potential for bugs (security related or otherwise). Standards bloat, in combination with feeping creaturism demanded of us by our funders or users, results in software bloat which is probably our most significant challenge. . Megan Smith and John Doe discuss advancements in DNS architecture and the evolving landscape of cybersecurity protocols.. BIND, DNS Management, Open Source Security, Internet Security. . Brittany Day

Calendar%202 Oct 03, 2000 User Avatar Brittany Day
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200