Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security HOWTOs

Filter%20icon Refine HOWTOs
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security HOWTOs

We found 13 articles for you...
167

Offline Password Cracking With John The Ripper: A Step-By-Step Guide

Password crackers are essential tools in any pen tester's toolbox. This step-by-step tutorial explains how to use John the Ripper, an open source offline password-cracking tool. . Red teams and blue teams use password cracking to gain access to systems and to detect weak user passwords or test defenses during red team-blue team exercises. Password crackers can be online or offline. Online password crackers, such as Hydra , are used when brute-forcing online network protocols and HTML forms. Situations where online brute forcing might be impractical include a remote system that limits the rate of sign-in attempts or a system that locks users out indefinitely after a predefined number of invalid login attempts. In these scenarios, an offline password cracker attempts to gain access to a password where it is stored instead of using a brute-force attack strategy. Since systems and applications rarely store passwords without cryptographic protection, passwords must be cracked to make use of them. A popular offline password cracker is John the Ripper. This tool enables security practitioners to crack passwords, regardless of encrypted or hashed passwords, message authentication codes ( MACs ) and hash-based MACs ( HMACs ), or other artifacts of the authentication process. . Discover effective techniques for leveraging John the Ripper in penetration testing and cybersecurity evaluations to enhance your password recovery processes.. Password Cracking, John the Ripper, Pen Tester Tools. . Brittany Day

Calendar%202 May 06, 2023 User Avatar Brittany Day How to Secure My Network
166

Scan Web Apps For XSS With Pwn XSS Tool: A Comprehensive Guide

Pwn XSS is a powerful tool that is commonly used by malicious hackers as well as security professionals today. The term "pwn" comes from "own", as in "to have power or mastery over (someone)." Pwn XSS is an open source cross site scripting vulnerability scanner made in python 3.7. This tool is used to find vulnerabilities in websites and web apps that can be compromised and allow a hacker to exploit for malicious reasons. It can also be used by security professionals to test their own websites to be sure it's free from any cross-site scripting vulnerabilities, as well as cybersecurity students, learning about how cross-site scripting works, why it can be a potential security risk, and ideas for how security and protection against these attacks can be improved. . In addition some of the main features of Pwn XSS consist of: Crawling all links on a website POST and GET forms are supported Advanced error handling Multiprocessing support To explore the features of Pwn XSS you would simply need to install the tool within your linux machine using the commands pip install bs4 pip install requests git clone GitHub - pwn0sec/PwnXSS: PwnXSS: Vulnerability (XSS) scanner exploit chmod 755 -R PwnXSS cd PwnXSS python3 pwnxss.py -help Once installed for basic usage of the tool you would simply run: python3 pwnxss.py -u Home of Acunetix Art (target website) After executing the code you will begin to see the scan take place and any vulnerabilities will begin to populate and show the areas of exploitation that exist. . Explore Pwn CSRF, a freely available resource designed for probing online applications and websites for cross-site request forgery weaknesses.. XSS Scanner, Open Source Tool, Web Security, Penetration Testing. Terrence Bragg. Brittany Day

Calendar%202 Jan 23, 2023 User Avatar Brittany Day How to Learn Tips and Tricks
160

Explore Pika Backup: Efficient Open Source Data Protection Tool

Pika Backup, an open-source graphical backup utility created by Sophie Herold , promises to keep your data safe and make the entire process easier than ever. . If you care about your personal data, you need to have a backup, and Pika Backup is one of those tools that you configure the way you like it and forget about it. “Doing backups the easy way” – that’s the motto of Pick Backup, but the great thing about this utility is that it saves you time and disk space by not copying the entire data over and over. The link for this article located at 9 to 5 Linux is no longer available. . Safeguard your information with Pika Restore, a community-driven tool crafted for seamless and reliable data preservation.. Pika Backup, Backup Utility, Data Protection, Open Source Software, Graphical Tool. . Brittany Day

Calendar%202 May 25, 2022 User Avatar Brittany Day How to Harden My Filesystem
166

Conducting a Linux Systems Security Audit Using the Lynis Tool

Your system's security should always be your topmost concern. Here's how to perform a security audit on a Linux system with Lynis. . Whether you're a Linux administrator or user, having a secure server or PC should be a top priority. Although Linux is a secure operating system, it is also susceptible to attacks or security breaches just like other OSes. In this guide, you'll learn how to audit and scan for security vulnerabilities and loopholes on your Linux machine using Lynis. Lynis is an open-source tool and is available on most Unix-based operating systems such as Linux, macOS, Solaris, FreeBSD, etc. . Keep your Linux environment safe by conducting essential assessments with Lynis to handle weaknesses proficiently.. Lynis Audits, Security Management, Linux System Security, Vulnerability Scanning. . Brittany Day

Calendar%202 Jan 11, 2022 User Avatar Brittany Day How to Learn Tips and Tricks
166

Croc File Transfer: Securely Move Data Between Computers

Croc is a free and open-source command line tool that enables computers to easily and securely transfer files and folders using code phrases. Learn how to install and use croc in this tutorial. . There are lots of ways to transfer files between two or more computers. Today, we will discuss about yet another utility named Croc. This tutorial we’ll show you how to install Croc and how to use it to transfer files between computers. Croc is a file transfer system that sends files securely using end-to-end encryption, via a file transfer relay. If you are curious about the name, it is inspired by the fable of the frog and the crocodile. The Croc key advantages are speed, security, and simplicity, all-in-one. Transferring data using Croc is faster, because it acts as a relay server between the systems. It creates a full-duplex real-time communication layer between the two computers, so the “uploading” and “downloading” tasks occur simultaneously between those computers. . Delve into Croc, a public-source solution designed for safeguarding file exchanges across devices, utilizing end-to-end encryption for enhanced security.. Croc File Transfer, Safe File Sharing, Open Source Security. . Brittany Day

Calendar%202 May 14, 2021 User Avatar Brittany Day How to Learn Tips and Tricks
166

Secure File Transfers With Croc: Efficient and Simple Guide

Croc is a free and open-source command line tool that enables computers to easily and securely transfer files and folders using code phrases. Learn how to install and use croc in this tutorial. . There are lots of ways to transfer files between two or more computers. Today, we will discuss about yet another utility named Croc. This tutorial we’ll show you how to install Croc and how to use it to transfer files between computers. Croc is a file transfer system that sends files securely using end-to-end encryption, via a file transfer relay. If you are curious about the name, it is inspired by the fable of the frog and the crocodile. The Croc key advantages are speed, security, and simplicity, all-in-one. Transferring data using Croc is faster, because it acts as a relay server between the systems. It creates a full-duplex real-time communication layer between the two computers, so the “uploading” and “downloading” tasks occur simultaneously between those computers. . Learn to safely transmit files with Croc, the open-source application designed for easy file sharing, featuring built-in encryption for enhanced security.. Croc File Transfer, Secure File Sharing, Command Line Utility. . Brittany Day

Calendar%202 May 14, 2021 User Avatar Brittany Day How to Learn Tips and Tricks
166

Installing Fail2ban On Fedora 33 To Prevent Unwanted Logins

Fail2ban is one of the most popular open-source tools for the banning of unwanted logins on a Linux system. In this TechRepublic tutorial, Jack Wallen demonstrates how to install and configure fail2ban on the latest release of Fedora Linux. . Since IBM/Red Hat has decided to ring the death knell for the CentOS we know and love, many of you might be considering making the switch to Fedora or Fedora Server . Because of that, you might want to know how to get a crucial system like fail2ban installed and running. For those that might not know, fail2ban is one of the most popular open source tools for the banning of unwanted logins on a Linux system. Fail2ban monitors specific log files for failed login attempts and, when an attempt to compromise is detected, it blocks the IP address from further attack or attempted logins. . This tutorial delves into setting up fail2ban on Fedora, aimed at enhancing your security by preventing unauthorized login attempts.. Fail2ban Installation,Fedora Login Security,Open Source Protection,System Hardening. . Brittany Day

Calendar%202 Dec 11, 2020 User Avatar Brittany Day How to Learn Tips and Tricks
166

Track COVID-19 Statistics Using Command Line Tools on Linux

Are you a Linux user trying to stay up-to-date on the Coronavirus pandemic? Learn how to track COVID-19 statistics from Commandline using Corona-cli, Coronavirus-tracker-cli and COVID-19 Tracker CLI in this helpful tutorial. . It is very difficult time for the entire World! The deadly Coronavirus (COVID-19) is spreading very fast across the Globe. All countries are taking various precautions including lock-down and curfew and trying their best to control this infectious disease. The World Health Organization (WHO) website provides many resources, current situation reports, travel advice, protective measures & awareness and answers for all questions related to the Coronavirus disease outbreak. Besides WHO, many NGOs, individuals and volunteers are doing their part by developing tools and apps to track the Novel Coronavirus statistics. This guide explains how to track Coronavirus disease 2019 (COVID-19) statistics from Commandline using Corona-cli, Coronavirus-tracker-cli and COVID-19 Tracker CLI on Linux. The link for this article located at OS TechNix is no longer available. . Keep informed about the COVID-19 outbreak using handy CLI utilities to monitor data from your Linux terminal.. COVID-19, Command Line Tool, Linux Tutorial, Health Tracking, Open Source Tool. . Brittany Day

Calendar%202 Mar 27, 2020 User Avatar Brittany Day How to Learn Tips and Tricks
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200