Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Server Security - Page 28

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Server Security News

Enhancing Linux Security With SELinux, RSBAC, And Other MAC Projects

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Some in the security industry say that Linux is inherently insecure, that the way Linux enforces security decsions is fundamentally flawed, and the only way to change this is to redesign the kernel. Fortunately, there are a few projects aiming to solve this problem by providing a more robust security model for Linux by adding Mandatory Access Control (MAC) to the kernel.

Guardian Digital's Enhanced Email Security Tool Against Spam Threats

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Guardian Digital, the world’s premier open source Internet security company today announced the availability of the first anti-spam software tool designed specifically to diminish the threat of Trojan zombie attacks. Responsible for a high volume of successful spam attacks, this latest email threat is causing serious problems within corporate email infrastructures. Known to take over unsuspecting computers and utilize its resources to send out spam messages, zombie-type attacks use the domain name of the victimized computers ISP to send messages that appear as if they are coming directly from the ISP, making it very difficult for customary anti-spam solutions to block them.

Examining Immediate Improvements for Linux Kernel Security

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

During the disclosure of some recent vulnerabilities in the Linux kernel, I learned some things about Linux kernel security that was truly shocking. The way security in the Linux kernel is handled is broken, and it needs to be fixed right now. I'm a big proponent of open source software. Although personally I'm a huge follower of BSD-based operating systems, I keep an open and analytical mind when looking at any OS. Unfortunately, I was totally blown away with some of the things that I learned about Linux kernel security during the release of some recent vulnerabilities in the kernel code.

The Importance of Security Certifications in Open Source Growth

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Only a few open-source vendors have borne the time and expense of having their software EAL-certified. Red Hat and Novell's SuSE Linux attained EAL3+ ratings in the last year, but many other vendors have yet to do the same. This raises a fundamental question: Does open-source software need security certifications to win global acceptance?

Email Security and Compliance Role in Corporate Governance

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Corporate governance and regulation were one of the dominant themes of 2004 and look set to continue to be so throughout 2005. Corporate governance relates to how an organisation is run, and has repercussions for almost every department – particularly Finance, HR, Auditing, Procurement and IT. Due to the nature of the potential content of email, ranging from a simple customer query to financial projections, the use of this application demands particular attention to ensure that its management helps to secure regulatory compliance.

Comprehensive Guide to SSH Port Forwarding for Secure Connections

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

SSH is typically used for logging into remote servers so you have shell access to do maintenance, read your email, restart services, or whatever administration you require. SSH also offers some other native services, such as file copy (using scp and sftp) and remote command execution (using ssh with a command on the command line after the hostname).

Linux Distros: xpdf Critical Advisory for Remote Code Execution

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

iDEFENSE has discovered a flaw in Xpdf, an open-source viewer for Portable Document Format (PDF) files included in most Linux distros. iDEFENSE has confirmed the existence of this vulnerability in version 3.00 of xpdf. It is suspected that previous versions may also be vulnerable. Remote exploitation of the buffer overflow vulnerability in the xpdf PDF viewer could allow attackers to execute arbitrary code as the user viewing a PDF file.

Detecting Kernel Modifications with GDB Tool Techniques

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This article is intended to outline useful ways of detecting hidden modifications to a Linux kernel. Often known as a rootkit, this stealthy type of malware gets installed in the kernel of an operating system and requires special techniques by Incident handlers and Linux system administrators to be detected. . . .

Assessing OS Security: Linux Versus Mac OS Control Mechanisms

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

At the end of the day this isn't about which OS is best. And it isn't about security through obscurity. OS makers need to continue to strive for perfection, for multiple layers of protection, to block hackers from gaining the ultimate prize of full control of resources and to include alerting and management tools which make monitoring penetrations easier and which make dealing with them less of a chore. . . .

Your message here