Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Attackers have used a freely available exploit to target a number of 64-bit Linux machines, according to a Linux patch management software firm.. The exploit is particularly pernicious, as it can leave a backdoor on systems that have workarounds deployed, according to rebootless Linux security update company Ksplice. The stack pointer underflow weakness has been given a common vulnerability code of CVE-2010-3081. "In the last day, we've received many reports of people attacking production systems using an exploit for this vulnerability, so if you run Linux systems, we recommend that you strongly consider patching this," said Ksplice chief executive Jeff Arnold in a blog post on Saturday. The link for this article located at ZDNet UK is no longer available. . The exploit is particularly pernicious, as it can leave a backdoor on systems that have workarounds . attackers, freely, exploit, target, number, 64-bit, linux, machines, accordin. . LinuxSecurity.com Team
The FBI is advising users of the open source VoIP package Asterisk to upgrade to the latest version, but has so far provided very little evidence on what vulnerability it has detected. The FBI's warning as published at the Internet Crime Complaint Center (IC3) is vague at best. The warning states: "The recent attacks were conducted by hackers exploiting a security vulnerability in Asterisk software. Asterisk is free and widely used software developed to integrate PBXii systems with Voice over Internet Protocol (VoIP), digital Internet voice calling services; however, early versions of the Asterisk software are known to have a vulnerability." Do you use Asterisk for your VoIP? If so you might want to upgrade to the latest version because the FBI stated that they have found an vulnerability in the earlier versions of the software.. The link for this article located at Arstechnica is no longer available. . The link for this article located at Arstechnica is no longer available.. advising, users, source, package, asterisk, upgrade, latest, version. . Bill Locke
X-Force, the research and development (R&D) team of Internet Security Systems (ISS), has warned that hackers are planning an online attack-fest this coming Christmas. The attacks, if they occur, will take the form of distributed denial of service (DDOS) invasions, a . . . . X-Force, the research and development (R&D) team of Internet Security Systems (ISS), has warned that hackers are planning an online attack-fest this coming Christmas. The attacks, if they occur, will take the form of distributed denial of service (DDOS) invasions, a hacker flooding technique used earlier this year - and since - to effectively flood out a major Web site and prevent normal users from gaining access, ISS said. The technique was used in February of this year when Amazon, Buy.com, CNN Interactive, eBay and a number of other high-profile sites were downed by hackers, apparently using DDOS applications known as "Trinoo," "Stacheldraht" and "TFN2K." The link for this article located at NewsBytes is no longer available. . CyberShield alerts of possible holiday DoS strikes aimed at prominent platforms, sparking digital safety alarms.. DDoS Attack, Online Threats, Website Security, Christmas Cyber Attacks. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.