Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
74

Mozilla Firefox Enhancements: Click to Play Blocks Automated Plugins

Mozilla developers are working on a new Firefox feature that will block the automated display of plug-in-based content like Flash videos, Java applets or PDF files, and will protect users from attacks that exploit vulnerabilities in browser plug-ins to install malware on their computers. . Known as "click to play," this feature has been present in the popular NoScript Firefox security extension for many years, as well as in other browsers like Google Chrome and Opera. The link for this article located at Network World is no longer available. . The latest Chrome update introduces measures to prevent automatic content rendering, boosting user security against harmful extensions.. Firefox, Browser Security, Click-to-Play, NoScript, Plugin Exploits. . Alex

Calendar%202 Apr 16, 2012 User Avatar Alex Network Security
83

SQL Injection Attacks: Trends, Stats, and Implications for Security

SQL injections top plenty of lists as the most prevalent means of attacking front-end Web applications and back-end databases to compromise data. According to recent published reports, analysis of the Web Hacking Incidents Database (WHID) shows SQL injections as the top attack vector, making up 19 percent of all security breaches examined by WHID. . Similarly, in the "Breach Report for 2010" (PDF) released by 7Safe earlier this month, a whopping 60 percent of all breach incidents examined involved SQL injections. "One of the reasons we're seeing such an increase in SQL injections is actually sort of what we've dubbed the 'industrialization' of hacking," says Brian Contos, chief security strategist for Imperva. "It's this notion of smart SQL injections leveraging things like Google searches, automation through bots, and various other technologies to carry out sophisticated, automated attacks." SQL injection attacks are generally carried out by typing malformed SQL commands into front-end Web application input boxes that are tied to database accounts in order to trick the database into offering more access to information than the developer intended. Part of the reason for such a huge rise in SQL injection during the past year to 18 months is the fact that criminals are increasingly using automated SQL injection attacks powered by botnets to hit vulnerable systems, Contos says. They use the attacks to both steal information from databases and to inject malicious code into these databases as a means to perpetrate further attacks. The link for this article located at Dark Reading is no longer available. . Similarly, in the 'Breach Report for 2010' (PDF) released by 7Safe earlier this month, a whopping 60. injections, plenty, lists, prevalent, means, attacking, front-end, applicatio. . LinuxSecurity.com Team

Calendar%202 Feb 23, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Enhancing Security: Combatting Automated SSH Attacks on Linux

As many systems administrators will tell you, attacks from automated login scripts specifically targeting common account names with weak passwords have become a substantial threat to system security, especially via SSH (a popular program that allows remote users to log in to a Linux computer and execute commands locally). Here are some common-sense rules to follow that can greatly improve security, as well as several scripts to cut down on the computing resources wasted by these attacks. . Brute-force attackers use so-called dictionary attacks, attempting many different login/password combinations in an attempt to hit on one that matches. In most cases, these scripts use a pre-programmed "dictionary" of often-used account names (such as www, admin, test, or guest). These scripts then attempt common passwords (often just the name of the account or an empty string). When one attempt fails, the script continues on, attempting other entries in its dictionary, until it has exhausted every pair (which can total hundreds of login attempts). The link for this article located at Linux.com is no longer available. . Brute-force attackers use so-called dictionary attacks, attempting many different login/password com. systems, administrators, attacks, automated, login, scripts, specifically. . LinuxSecurity.com Team

Calendar%202 Sep 22, 2005 User Avatar LinuxSecurity.com Team Server Security
83

Impact of Automated Attacks And Bot Networks On Modern Cybercrime

Automated attacks are coming from unexpected quarters--from across the globe, across town, and most creepily, even from across the hall. According to a recent report from anti-virus vendor Symantec, this year's 450 percent increase in the number of attacks on Windows machines is evidence that automation is proving as efficient for 21st-Century hackers as it did for 20th-Century manufacturers. . Automated attacks are coming from unexpected quarters--from across the globe, across town, and most creepily, even from across the hall. According to a recent report from anti-virus vendor Symantec, this year's 450 percent increase in the number of attacks on Windows machines is evidence that automation is proving as efficient for 21st-Century hackers as it did for 20th-Century manufacturers. By including a backdoor component with their worms and viruses, hackers can gain access to infected machines without the owners' knowledge. Once that access is available, the machines become "bots," controlled remotely by hackers to do their nefarious bidding. The latest disturbing trend sees hackers assembling thousands of hijacked computers into huge "bot networks." Such networks both vastly amplify the hackers' ability to wreak havoc, and complicate the task of authorities trying to track down the cybercriminals. Bot networks can be used for any number of criminal activities, ranging from sending out more worms and viruses with more backdoors, to mass-spam mailings, to launching denial of service attacks, to hosting phishing sites that pose as legitimate financial institutions. The 100 percent increase in phishing sites between September and October of this year is viewed by the Anti-Phishing Working Group as evidence that bot networks have been used to send more payload-bearing e-mails and to host scam sites. The link for this article located at securitypipeline.com is no longer available. . Automated attacks are coming from unexpected quarters--from across the globe, across town, and most .across, automated, attacks, coming, unexpected, quarters--from, globe. . LinuxSecurity.com Team

Calendar%202 Dec 01, 2004 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Protect Your Computer From Automated Break-Ins And Cyber Hijacking

Simply connecting to the Internet -- and doing nothing else -- exposes your PC to non-stop, automated break-in attempts by intruders looking to take control of your machine surreptitiously. . . . . Simply connecting to the Internet -- and doing nothing else -- exposes your PC to non-stop, automated break-in attempts by intruders looking to take control of your machine surreptitiously. While most break-in tries fail, an unprotected PC can get hijacked within minutes of accessing the Internet. Once hijacked, it is likely to get grouped with other compromised PCs to dispense spam, conduct denial-of-service attacks or carry out identity-theft scams. Those are key findings of a test conducted by USA TODAY and Avantgarde, a San Francisco tech marketing and design firm. The experiment involved monitoring six "honeypot" computers for two weeks -- set up to see what kind of malicious traffic they would attract. Once breached, the test computers were shut down before they could be used to attack other PCs. The link for this article located at Byron Acohido and Jon Swartz is no longer available. . Accessing the web unprotected may result in instant breaches, jeopardizing your computer's security.. PC Hijacking, Automated Attacks, Internet Security. . LinuxSecurity.com Team

Calendar%202 Nov 30, 2004 User Avatar LinuxSecurity.com Team Server Security
82

U.S. Army Cyber Incident Response: Follow-Up Actions After Cyberwar

Shortly after a military surveillance plane collided with a Chinese fighter last April, a two-week ÒcyberwarÓ began, and U.S. Army Web sites took numerous hits. More than 50 Web pages were defaced by an automated attack launched by supporters or agents of the PeopleÕs Republic of China. The hackers placed anti-American sentiments in English and Chinese characters on some of the sites. . . .. Shortly after a military surveillance plane collided with a Chinese fighter last April, a two-week ÒcyberwarÓ began, and U.S. Army Web sites took numerous hits. More than 50 Web pages were defaced by an automated attack launched by supporters or agents of the PeopleÕs Republic of China. The hackers placed anti-American sentiments in English and Chinese characters on some of the sites. But most of the attacks could have been prevented if published fixes, identified in Information Assurance Vulnerability Alerts, were in place on the hacked machines, said Lt. Col. John Quigg, chief of the ArmyÕs network security improvement program in the serviceÕs chief information office. An IAVA is a digital list of computer vulnerabilities. They are reported monthly to the chairman of the Joint Chiefs of Staff, Quigg said. The alerts are also posted on Army networks and warn of basic security measures needed to ward off viruses, worms or hackers. The link for this article located at ComputerUser is no longer available. . Shortly after a military surveillance plane collided with a Chinese fighter last April, a two-week . shortly, military, surveillance, plane, collided, chinese, fighter, april, two-week. . Anthony Pell

Calendar%202 May 14, 2002 User Avatar Anthony Pell Government
83

2001 Internet Threats Overview: Key Risks And Trends Identified

Internet-based threats rose significantly in 2001 and continued to climb through the early months of 2002, according to a new report. Traditional incidents such as virus and Denial of Service attacks remained at or above previous levels, but automated scripts against common vulnerabilities are now the most significant online risk, said Internet Security Systems (ISS).. . .. Internet-based threats rose significantly in 2001 and continued to climb through the early months of 2002, according to a new report. Traditional incidents such as virus and Denial of Service attacks remained at or above previous levels, but automated scripts against common vulnerabilities are now the most significant online risk, said Internet Security Systems (ISS). The threats will continue to increase until fundamental internet risk factors are dealt with, the company said in its Internet Risk Impact Summary Report for the first quarter of 2002. "Attacks are now global in scope and round-the-clock in incidence," said ISS. The link for this article located at vnunet is no longer available. . The year 2001 saw a notable increase in online dangers, underscoring newly identified vulnerabilities within the realm of digital security.. Cybersecurity Trends, Internet Threats, Risk Assessment. . LinuxSecurity.com Team

Calendar%202 Apr 08, 2002 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here