Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 6 articles for you...
81

Techniques by MIT Researchers Unmask Tor Anonymity Risks

MIT researchers have developed digital attacks which can unmask Tor services in the Deep Web with a high degree of accuracy.. As reported by Net Security, a team from the Massachusetts Institute of Technology (MIT) have developed attacks which can be used to identify an anonymous hidden service, clients and potentially servers. The link for this article located at ZDNet Security is no longer available. . A team from MIT has created methods capable of exposing Tor hidden services, jeopardizing the privacy of users on the Deep Web.. Tor Service Attacks, MIT Research, Deep Web Anonymity, Digital Security Risks. . LinuxSecurity.com Team

Calendar%202 Jul 31, 2015 User Avatar LinuxSecurity.com Team Privacy
83

Samy Kamkar's OpenSesame: Quick Garage Door Access Method

It may be time to upgrade your garage door opener. Security researcher Samy Kamkar has developed a new technique that enables him to open almost any garage door that uses a fixed code. The attack Kamkar devised, known as OpenSesame, reduces the amount of time it takes to guess the fixed code for a garage door from several minutes down to less than 10 seconds. The link for this article located at ThreatPost is no longer available. . Explore how Kamkar's OpenSesame reduces the time required for guessing garage door codes to mere seconds, significantly boosting security measures.. Garage Door Attack, OpenSesame Technique, Samy Kamkar. . LinuxSecurity.com Team

Calendar%202 Jun 08, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

SANS Conference 2015: Six Dangerous New Attack Techniques

Experts with the SANS Institute convened at RSA Conference for their annual threats panel, this time dishing on the six most dangerous new attack techniques. Led by SANS Director John Pescatore, the panel featured Ed Skoudis, SANS faculty fellow and CEO of CounterHack Challenges, Johannes Ullrich, dean of research for SANS, and Michael Assante, SANS project lead for Industrial Control System (ICS) and Supervisory Control and Data Acquisition (SCADA) security. . Each offered up thoughts on how they've seen threats evolving and which techniques they expect to gain steam over the next year. According to Skoudis, more organizations will need to face the prospect of attackers not only getting savvy in how they steal information, but also in how they disseminate it, particularly if they're looking to publicly humiliate their targets. The link for this article located at Dark Reading is no longer available. . Each offered up thoughts on how they've seen threats evolving and which techniques they expect to ga. experts, institute, convened, conference, their, annual, threats, panel. . LinuxSecurity.com Team

Calendar%202 Apr 23, 2015 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Redirecting Website Traffic: New Hacktivism Tactics With DNS Hijacking

Hacktivists have added a new tactic to their arsenal: redirecting all of the traffic from a target company's website.. According to a blog written by security expert Lars Harvey of IID, politically motivated attackers are now using DNS hijacks, which redirect all the traffic from a victim's legitimate website (and often all the email and back-end transactions, too) to a destination of the attacker's choosing. The link for this article located at Dark Reading is no longer available. . Hacktivism is transforming as activists use DNS hijacking to divert users from legitimate sites, critiquing corporate practices and social issues while exploiting vulnerabilities.. DNS Hijacking, Hacktivism Techniques, Attack Strategies. . LinuxSecurity.com Team

Calendar%202 Jan 26, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Exploring Pervasive Memory Scraping Threats And Their Security Risks

What's "pervasive memory scraping" and why is it considered by SANS Institute security researchers to be among the most dangerous attack techniques likely to be used in coming the coming year?. Simply put, pervasive memory scraping is used by attackers who have gained administrative privileges to successfully get hold of personally identifiable information (PII) and other sensitive data held encrypted in a file system, according to Ed Skoudis, senior security consultant at InGuardians who is also an instructor at SANS events. Evidence of this attack is coming up again and again in data breach cases, he said. "Data is encrypted in a file system where it's stored," said Skoudis, who joined with Johannes Ullrich, chief research officer at SANS Technology Institute, to speak at the RSA Conference last week on dangerous attack techniques that appear to be on the rise. Though stored encrypted, the data has to be processed by some application and "if you're processing that data it will be processed in that system unencrypted," Skoudis pointed out. The link for this article located at Tech World is no longer available. . Simply put, pervasive memory scraping is used by attackers who have gained administrative privileges. what's, 'pervasive, memory, scraping', considered, institute, security, researchers. . LinuxSecurity.com Team

Calendar%202 Feb 23, 2011 User Avatar LinuxSecurity.com Team Cryptography
74

BGP Exploit Demonstrates Stealthy Traffic Interception Vulnerability

Two security researchers have demonstrated a new technique to stealthily intercept internet traffic on a scale previously presumed to be unavailable to anyone outside of intelligence agencies like the National Security Agency. The tactic exploits the internet routing protocol BGP (Border Gateway Protocol) to let an attacker surreptitiously monitor unencrypted internet traffic anywhere in the world, and even modify it before it reaches its destination. Find out about a new exploit that uses a weakness in the design of the internet's Border Gateway Protocol (BGP) to re-direct traffic to an eavesdropper. How do you think ISPs will respond to defending against this new technique? Check it out in the article below. . The link for this article located at Wired is no longer available. . A serious vulnerability in the Border Gateway Protocol (BGP) poses risks of secret traffic interception, allowing attackers to hijack and manipulate data flow globally. BGP Exploit, Traffic Interception, Eavesdropping Risk, Internet Protocol, Network Security. . Brittany Day

Calendar%202 Aug 27, 2008 User Avatar Brittany Day Network Security
83

Understanding Security Risks of PHP's Weak Random Number Generators

PHP comes with two random number generators named rand() and mt_rand(). The first is just a wrapper around the libc rand() function and the second one is an implementation of the Mersenne Twister pseudo random number generator. Both of these algorithms are seeded by a single 32 bit dword when they are first used in a process or one of the seeding functions srand() or mt_srand() is called. This is a great article by Stefan Esser on attacking php PRNG. He explains the attack in such a way that it's easy to understand. . The link for this article located at suspekt is no longer available. . Analyzing PHP's inadequate random number generators reveals vulnerabilities and risks of exploitation.. PHP Random Numbers, mt_rand Attack, PRNG Security, PHP Security Risks. . LinuxSecurity.com Team

Calendar%202 Aug 20, 2008 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Juniper Networks: New Attack Technique Compromises Embedded Devices

A Juniper Networks security researcher says he's discovered a new type attack that can compromise embedded devices such as routers and mobile phones. The vulnerability lies in the Arm and XScale microprocessors, two chips that are widely used in these devices. "There are interesting quirks in the ARM and XScale architectures that make things very easy for an attacker," said Juniper's Barnaby Jack. . The technique he has developed is "100 percent reliable, and it results in code execution on the device," he said. A successful attacker could run unauthorized software on a device connected to the network. In theory, criminals could use the attack to steal sensitive information from mobile phones or redirect Internet traffic on routers, say from a user's online bank account to a phishing site. The link for this article located at TECHWORLD is no longer available. . The technique he has developed is '100 percent reliable, and it results in code execution on the dev. juniper, networks, security, researcher, attack, compromise. . LinuxSecurity.com Team

Calendar%202 Apr 06, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200