Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
One in every 24 Googlebots is a imitation spam-flinging denial of service villain that masquerades as Mountain View to sneak past web perimeter defences, according to security chaps at Incapsula. Villains spawn the "evil twins" to hack and crack legitimate websites and form what amounted to the third most-popular type of DDoS attack to scourge the internet.. Incapsula detected 50 million unwanted visits by the fake bots which made up four percent of all legitimate Googlebot HTTPS user-agents. The link for this article located at The Register UK is no longer available. . Incapsula detected 50 million unwanted visits by the fake bots which made up four percent of all leg. every, googlebots, imitation, spam-flinging, denial, service, villain, masquerades. . LinuxSecurity.com Team
Microsoft has taught version 4.0 of the Windows mitigation tool EMET some new tricks. It now detects attacks that attempt to eavesdrop on encrypted connections and is better at thwarting return-oriented programming (ROP) attacks. . The biggest change, however, is more cosmetic The link for this article located at H Security is no longer available. . Microsoft's EMET 4.0 enhances threat identification by introducing capabilities aimed at safeguarding encrypted transactions.. Microsoft EMET, SSL Detection, Security Enhancement, ROP Attack Mitigation. . LinuxSecurity.com Team
At the Black Hat security conference in Las Vegas, Mandiant security researchers Peter Silberman and Steve Davis are releasing a new forensic framework on Wednesday that will make it possible to detect whether or not a host was hit by Metapsloit's meterpreter. The new tool could change the game when it comes to Metasploit-based attacks that previously could not be identified on the target machine.. "Metasploit's meterpreter has been around since 2004 and it's a memory resident host exploitation module and because it's memory resident it breaks traditional disk forensics and the attacker leave no trace of the attack on the disk," Silberman said. "Our talk is how we can use memory forensics to reconstruct what an attacker has done with meterpreter to give analysts some idea of what has occurred." In concert with the talk, the Mandiant researchers will release an open source tool called the Metasploit Forensic Framework. The goal of the tool is to make the undetectable, detectable. Metasploit itself is an open source vulnerability testing framework, but with meterpreter it has the stealth to evade most common security exploit detection mechanism. The link for this article located at Internet News is no longer available. . 'Metasploit's meterpreter has been around since 2004 and it's a memory resident host exploitation mo. security, black, conference, vegas, mandiant, researchers, peter, silberman. . LinuxSecurity.com Team
Breach Security announced the release of the ModSecurity version 2.0 open source Web application firewall. ModSecurity version 2.0 provides greater flexibility, enhanced attack detection, and support for XML and Web Services. At the same time, Breach Security is releasing the ModSecurity Console for monitoring multiple sensors and ModSecurity Core Rules that together provide easy-to-deploy baseline Web application security. . The link for this article located at Help Net Security is no longer available. . Uncover the updated functionalities of ModSecurity 2.0, boosting web application protection and threat identification techniques.. ModSecurity 2.0, Web Application Firewall, Open Source Security, Web Security, Attack Detection. . LinuxSecurity.com Team
UK company Secerno has devised an innovative way to detect when a database is being attacked using the SQL (Structured Query Language) injection hacking technique. . The databases at the heart of internet applications are vulnerable to this relatively straightforward type of attack, which is difficult to detect and block because it uses carefully crafted standard SQL commands. The technique used by Secerno to determine whether database queries are valid was discovered by company founder and chief technology officer Steve Moyle while he was researching his PhD in computer learning at Oxford University. . The databases at the heart of internet applications are vulnerable to this relatively straightforwar. company, secerno, devised, innovative, detect, database, being, attacked, using. . LinuxSecurity.com Team
If it were on public display, this portion of our Firewall Blowout would be the geek equivalent of the Chicago Auto Show. Our Chicago Neohapsis partner labs focused on the muscle cars: enterprise-class, gigabit-capable network firewall appliances and turnkey systems that support high-availability stateful failover, VPNs and centralized management as well as DI (deep inspection), which we define as having the ability not only to perform stateful packet filtering, but also to inspect packet payloads higher up the OSI model using specific attack signatures and Layer 7 protocol engines. . Historically, firewalls have been assigned blue-collar access-control duties while IDSs (intrusion-detection systems) take on the sexier task of inspecting data traffic for signs of attack or anomalous packets. But over the past couple of years we've seen rebuilds in the firewall space reminiscent of old rods being retrofit with superchargers and nitrous oxide. Gone are the days of sedate firewall packet filters; now only the fast and the furious can compete. The streets are owned by smart firewall appliances at various metamorphic stages of incorporating intrusion-detection and intrusion-prevention functionality. When we set out to investigate the pros and cons of buying the latest and greatest firewall muscle, our scenario was deceptively simple: We built a three-tiered architecture with an Internet, a DMZ and an internal network. Because we were simulating an enterprise setting, we asked vendors to send redundant hardware. We tested VPN throughput with two identical firewalls in a site- to-site gateway configuration. All other testing was performed in high-availability mode with dual firewalls in active-passive configuration. We specified 500-Mbps throughput and the ability to manage and perform under 50, 250 and 500 firewall rules. The link for this article located at Security Pipeline is no longer available. . Historically, firewalls have been assigned blue-collar access-control duties while IDSs (intrusion-d.public, display, portion, firewall, blowout, would, equivalent. . Brittany Day
Leading global telecommunications companies, ISPs, and network operators will begin sharing information on Internet attacks as members of a new group called the "Fingerprint Sharing Alliance," according to a published statement from the new group. . The companies, including EarthLink, Asia Netcom, British Telecommunications, and MCI, will share detailed profile information on attacks launched against their networks. Information to be shared will include the source of attacks. The alliance will make it easier for ISPs and network operators to crack down on global Internet attacks more quickly, according to Tom Schuster, president of Arbor Networks, which launched the new alliance. The link for this article located at infoWorld is no longer available. . International internet service providers band together to defend against online assaults by exchanging comprehensive attack data and origins.. Internet Attack Profiles, Collaborative Defense, ISP Network Security. . Brittany Day
Similar to a firewall, SQL Guard's filtering rules alert security managers to traffic from defined sources and users or to traffic that includes particular commands, such as excessive logons, one-user/one-IP, clients executing administrative commands, SQL overflows and SQL injection attacks. . Databases have a tremendous amount of built-in security to protect data. What they lack is the ability to defend their underlying code and engines from external attacks and internal misuse. Guardium's SQL Guard is part of the emerging class of security devices that sit in front of databases, monitoring traffic for illegal and malicious activity. Its robust features maintain detailed audit logs and can alert security managers at the first sign of trouble. Built on a Linux appliance, SQL Guard supports all leading database implementations: Oracle, IBM, Sybase and Microsoft. Its passive monitoring won't impede database performance, though Guardium rates throughput at 400 requests per second. It captures traffic type, source, requests and user names to determine whether the activity is authorized and for forensic analysis in the event of a breach. The link for this article located at TechTarget.com is no longer available. . Data repositories possess inherent safeguards yet fall short in counteracting intrusions. SQL Sentinel delivers crucial oversight.. SQL Guard, Database Protection, Security Monitoring, Threat Detection. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.