Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Protecting databases is hardly an easy task, but it is often the attacks that go after the simplest vulnerabilities that are most successful. Enterprises that stick to the basics will generate the most bang for their database security bucks. . According to Alex Rothacker, manager of AppSec's Team SHATTER (Security Heuristics of Application Testing Technology for Enterprise Research), his team has found that are 10 common database vulnerabilities that keep plaguing organizations over and over again. The common thread in this list is that databases rarely ship security-ready, and their configuration is not a fire-and-forget operation for database administrators. Organizations must continually assess packages to determine if they are really necessary and disable those they don't need to reduce attack surfaces. They need to be vigilant about keeping on the lookout for default or weak log-in credentials. They have to put sound privilege and authentication practices into play. And most important, they need to patch regularly. The link for this article located at Dark Reading is no longer available. . Organizations face database vulnerabilities that can lead to breaches. Discover 10 common issues and key practices for risk mitigation today. Database Security, Vulnerability Assessment, Configuration Management, Authentication Practices. . LinuxSecurity.com Team
When asked about security on a multi-user Linux system, a wise man once said "everyone is root if you allow them to login as a user." There is plenty of truth in that, but embracing imminent compromise isn't always acceptable. Let's take a look at how you can limit your exposure while letting unknown and untrusted users login with a shell. There are two groups of people who typically want to heavily restrict login users. First, the collaborators: possibly two separate organizations that have been forced to work together. Second, people who wish to allow some shady characters access to a shell but believe they may attempt to compromise security. If at all possible, the best policy is to simply not give access out, and if you do, make sure patches are applied daily. . The link for this article located at Enterprise Networking is no longer available. . The link for this article located at Enterprise Networking is no longer available.. asked, about, security, multi-user, linux, system, 'everyone. . LinuxSecurity.com Team
While senior technology editor Curt Franklin was hard at work testing authentication tokens for this issue's cover story, I coincidentally ran into some questionable authentication policies and practices as a user. In lectures I've given and in classes I teach to network admins, I emphasize that people should never give their passwords to anyone. Your password and user name identify you to the network or servers. They are your digital ID and as such should be hidden through irreversible cryptography and protected from unauthorized alteration. But alas, as a customer I have dealt with two organizations, which will remain anonymous, that don't follow either principle. . . .. While senior technology editor Curt Franklin was hard at work testing authentication tokens for this issue's cover story, I coincidentally ran into some questionable authentication policies and practices as a user. In lectures I've given and in classes I teach to network admins, I emphasize that people should never give their passwords to anyone. Your password and user name identify you to the network or servers. They are your digital ID and as such should be hidden through irreversible cryptography and protected from unauthorized alteration. But alas, as a customer I have dealt with two organizations, which will remain anonymous, that don't follow either principle. Customer reps at my cell phone service provider always ask for my account password--the same password used to access my online account and authorize cell-phone plan, equipment and software purchases. I cringe every time I give it, fearing phone phreaks are tapping the call centers and gathering passwords. One of the banks with which I do business just completed a migration from one online account system to another, which required a re-enrollment of all users to synchronize credentials. Of course, my re-enrollment didn't go smoothly, so there I was, again, reading off my vitals over the phone. Only this time, anyone capturing my banking information could have had much more fun. The link for this article located at securitypipeline.com is no longer available. . While senior technology editor Curt Franklin was hard at work testing authentication tokens for this. while, senior, technology, editor, franklin, testing, authentication, tokens. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.