Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
For years, executives at France-based Ledger have boasted their specialized hardware for storing cryptocurrencies is so securely designed that resellers or others in the supply chain can't tamper with the devices without it being painfully obvious to end users. . The reason: "cryptographic attestation" that uses unforgeable digital signatures to ensure that only authorized code runs on the hardware wallet.. Unexpectedly, Trezor's highly regarded hardware wallet encountered a security compromise stemming from a significant vulnerability within its architecture and implementation.. Ledger Hardware Wallet, Cryptographic Attestation, Digital Signatures, Security Breach. . LinuxSecurity.com Team
The U.S. National Security Agency has hacked into Huawei Technologies servers, spied on communications of company executives and collected information to plant so-called backdoors on equipment from the Chinese networking manufacturer, according to reports published over the weekend.. In response, the NSA said that it declines to comment on specific, alleged foreign intelligence activities. In a statement emailed to the IDG News Service, the agency elaborated, saying that "NSA's activities are focused and specifically deployed against -- and only against -- valid foreign intelligence targets in response to intelligence requirements." The link for this article located at Network World is no longer available. . In response, the NSA said that it declines to comment on specific, alleged foreign intelligence acti. national, security, agency, hacked, huawei, technologies, servers, spied, communicatio. . LinuxSecurity.com Team
Industrial control system comes with a backdoor: Although the system was password protected in general, the backdoor through the IP address apparently required no password and allowed direct access to the control system. "[Th]e published backdoor URL provided the same level of access to the company's control system as the password-protected administrator login," said the memo.. The link for this article located at Schneier on Security is no longer available. . The link for this article located at Schneier on Security is no longer available.. system, industrial, control, comes, backdoor, although, password, protected, gener. . LinuxSecurity.com Team
A security expert working at Alert Logic has published a demonstration back door exploit for smartphones running Android. Criminals could use the principles of this exploit to gain control of a phone and install trojans. A potential victim need only call a malicious web site for infection to occur.. The example exploit will open the back door for demonstration purposes only on the fixed IP address 10.0.2.2 on port 2222. Although as it stands, the demo exploit is harmless, for an experienced cracker it would be relatively easy to customise the shellcode to create a malicious version. In a test conducted by The H's associates at heise Security with an HTC Wildfire (Android 2.1), the exploit only caused a browser crash. Officially, the exploit only is only effective on Motorola's Droid 2.0.1, 2.1, and the test was successful on an emulation of 2.0 - 1.2. The link for this article located at H Security is no longer available. . The example exploit will open the back door for demonstration purposes only on the fixed IP address . security, expert, working, alert, logic, published, demonstration, exploit, smartph. . LinuxSecurity.com Team
I've got good news and bad news for those of the misguided perception that Linux is somehow impervious to attack or compromise. The bad news is that it turns out a vast collection of Linux systems may, in fact, be pwned. The good news, at least for IT administrators and organizations that rely on Linux as a server or desktop operating system, is that the Trojan is in a game download so it should have no bearing on Linux in a business setting.. An announcement on the Unreal IRCd Forums states "This is very embarrassing...We found out that the Unreal3.2.8.1.tar.gz file on our mirrors has been replaced quite a while ago with a version with a backdoor (trojan) in it. This backdoor allows a person to execute ANY command with the privileges of he user running the ircd. The backdoor can be executed regardless of any user restrictions (so even if you have passworded server or hub that doesn't allow any users in)." The link for this article located at Network World is no longer available. . An announcement on the Unreal IRCd Forums states 'This is very embarrassing...We found out that the . those, misguided, perception, linux, somehow, impervio. . LinuxSecurity.com Team
The third Linux worm in less than three months hit the Internet this week. Known as the Adore worm, the program is designed to create so-called back doors in the security of Linux systems and send information identifying the compromised systems . . . . The third Linux worm in less than three months hit the Internet this week. Known as the Adore worm, the program is designed to create so-called back doors in the security of Linux systems and send information identifying the compromised systems to four different e-mail addresses hosted on servers in China and the United States. "It seems to be a variant of the Ramen worm," said David Dittrich, security administrator for the University of Washington and an expert on digital forensics and hacking tools. The Ramen worm, which used three well-known security flaws to infect systems using the Red Hat distribution of Linux, hit in mid-January and infected an unknown number of computers. The vulnerabilities exploited by Ramen occur in three programs shipped with most Linux distributions and installed by default. The link for this article located at News.com is no longer available. . The third Linux worm in less than three months hit the Internet this week. Known as the Adore worm, . third, linux, three, months, internet, known, adore. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.