With npm v12, dependency preinstall, install, and postinstall scripts will no longer execute automatically during package installation. Script execution will require explicit approval through new controls such as npm approve-scripts, with the change ...
Just three years after Sun Microsystems paid $2 billion in stock for server appliance maker Cobalt Networks, Sun has killed off the Cobalt product line. The move marks the end of the Cobalt brand of Linux servers at Sun, although Sun will continue to resell Linux operating systems from Red Hat and SuSE Linux on x86 servers. Sun also sells Linux for the desktop in the shape of the Sun Java Desktop, but its own server line now runs Solaris exclusively. . . .
Beginning January 1, 2004, Progeny will offer software updates for users of Red Hat® Linux® 7.2, 7.3, and 8.0, with support for 9 starting May 1, 2004. This service is based on Progeny's Platform Services technology and will provide a flexible . . .
Backed by big name partners, SUSE Linux and Red Hat are each putting their security systems through the rigorous paces of Common Criteria Scheme (CCS) testing, with ultimate plans to reach the same security ratings already achieved by Microsoft and Unix players. The Common Criteria stamp of approval "reduces the investment risk and also provides more trust" in Linux, according to Roman Drahtmueller, a member of SUSE's security team.. . .
Some people would have you believe this is monumental or out of the ordinary -- a group that distributes software experiencing a compromise, then letting everybody know about it and warning of the potential risks. Those that prance about in Penguin-embroidered cheerleader tops and yellow and black tutus suggest between pom-pom waves that no commercial vendor would ever be as candid.. . .
While Linux users have retracted accusations that SCO made up its claims it was a victim of a distributed denial-of-service attacks, doubts about those claims linger.. . .
The Internet Productivity Suite from Guardian Digital, which builds its security software atop open source code, combines a range of application within an appliance built atop the firm's EnGarde hardened Linux operating system platform. The Internet Productivity Suite includes gateway . . .
Things got pretty exciting in the Linux world recently, when the Debian Linux distribution announced that a cracker had broken in to four debian.org machines, escalated privileges to root, and installed rootkits on several of the servers.. . .
Several Cisco wireless access points (APs) are susceptible to a previously undetected security breach, the company said in an advisory issued this week.. . .
PHLAK 0.2 has been released. With many bug fixes and an overall better feel and look, 0.2 will deliver what we had hoped 0.1 would have. Head over to to grab your copy and start testing. PHLAK . . .
Having provided security-relevant fixes for version 7.3 of our home user product, SuSE Linux, for two years, we would like to inform you that SuSE Linux 7.3 will be discontinued for all architectures. Vulnerabilities found after December 15th 2003 will not . . .
Late summer brought a rude awakening for those network managers who felt secure in their virus-containment strategies. W32/ Blaster, W32/Welchia and Sobig.F waltzed through the Internet in rapid succession, leaving billions of dollars in damage in their wake.. . .
Red Hat (Quote, Chart) is on the verge of completing a crucial certification process that could help it extend the tendrils of its enterprise Linux operating system further in the government sector, where multi-billion dollar budgets abound.. . .
On December 2nd at approximately 03:45 UTC, one of the servers that makes up the rsync.gentoo.org rotation was compromised via a remote exploit. At this point, we are still performing forensic analysis. However, the compromised system had both an IDS and a file integrity checker installed and we have a very detailed forensic trail of what happened once the box was breached, so weare reasonably confident that the portage tree stored on that box wasunaffected.. . .
Immunix 7+ is no longer available for purchase. Security patches will continue to be produced for this release until February 29, 2004. Beyond that date, we will cooperate with Immunix community users in hosting security patches for Immunix 7+, but we no longer commit to delivering timely patches.. . .
Welcome back! The first article in this two-part series covered a few different methods of getting into the target router. This article will focus on what we can do once we've gotten in. For the remainder of this article, we'll assume . . .
Red Hat is pushing to have its commercial Enterprise Linux software certified under the Common Criteria (CC) Scheme worldwide, and has anticipated the OS solution will gain accreditation by the end of this year. The CC Scheme is designed to test . . .
Linux vendors spend money building security bug fixes. How much longer will they give them away for free, writes SecurityFocus columnist Hal Flynn.. . .