Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
81

Impact of Image Spam on Email Security and Bandwidth Management

Image spam is a serious and growing problem, not least because of its ability to circumvent traditional email spam filters to clog servers and inboxes. In just half a year, the problem of image spam has become general enough to be representative of 35 per cent of all junk mail. Not only this, but image spam is taking up 70 per cent of the bandwidth bulge on account of the large file sizes every single one represents. . The link for this article located at Net-Security.org - LogError is no longer available. . The link for this article located at Net-Security.org - LogError is no longer available.. image, serious, growing, problem, least, because, ability, circumvent, traditio. . LinuxSecurity.com Team

Calendar%202 Jan 05, 2007 User Avatar LinuxSecurity.com Team Privacy
74

FreeBSD: Efficient Bandwidth Control Using OS Filtering with pf

You manage a heterogeneous network and want to provide different Quality of Service agreements and network restrictions based on the client operating system. With pf and altq, you can now limit the amount of bandwidth available to users of different operating systems, or force outbound web traffic through a transparent filtering proxy. This article describes how to install pf, altq, and Squid on your FreeBSD router and web proxy to achieve these goals. . In an ideal environment, there would be no need for bandwidth shaping, OS fingerprint-based filtering, or even Quality of Service (QoS). Several factors in the real world require a change of game plan. Bandwidth is not free, and many ISPs charge customers based on bandwidth usage. Worms, viruses, and compromised systems can all lead to higher bandwidth costs. In the wake of the W32.Slammer worm, which saturated the connections of infected networks, many companies saw their monthly connectivity bills skyrocket due to the worm's traffic. Filtering your connections based on operating system can go partway to helping keep such situations from running away. While I will focus on filtering traffic from Windows systems, this process can equally apply to BSD, Linux, Mac OS, or a host of other operating systems listed in the pf.os file on your system. This may be especially useful to people running older versions of OSes that have not or cannot be patched but still require some network connectivity. . In an ideal environment, there would be no need for bandwidth shaping, OS fingerprint-based filterin. manage, heterogeneous, network, provide, different, quality, service, agreements. . Brittany Day

Calendar%202 Feb 21, 2006 User Avatar Brittany Day Network Security
82

RFID Adoption Strategies Amid Security Regulation Changes

You manage a heterogeneous network and want to provide different Quality of Service agreements and network restrictions based on the client operating system. With pf and altq, you can now limit the amount of bandwidth available to users of different operating systems, or force outbound web traffic through a transparent filtering proxy. This article describes how to install pf, altq, and Squid on your FreeBSD router and web proxy to achieve these goals. . The U.S. Department of Homeland Security is drafting regulations, expected by August, that will define how to implement more-stringent security, required under the Real ID Act for state-issued driver's licenses and other ID cards. The rules, which go into effect in May 2008, may push some agencies toward chip-based cards. Indeed, Blair said, "any security features could become obsolete in two years." The link for this article located at Security Pipeline is no longer available. . The U.S. Department of Homeland Security is drafting regulations, expected by August, that will defi. manage, heterogeneous, network, provide, different, quality, service, agreements. . Brittany Day

Calendar%202 Feb 20, 2006 User Avatar Brittany Day Government
72

Effective Kazaa Traffic Blocking Using P2PWall on IPTables Firewalls

The "p2pwall" project has developed a GPL add-in for iptables based firewalls that allows blocking of traffic to and from "Fast-Track" software such as "Kazaa", Kazaa-lite, iMesh and grokster. The software is designed for use in "permissive" firewall configurations where . . . . The "p2pwall" project has developed a GPL add-in for iptables based firewalls that allows blocking of traffic to and from "Fast-Track" software such as "Kazaa", Kazaa-lite, iMesh and grokster. The software is designed for use in "permissive" firewall configurations where home-net hosts are permitted more or less unlimited access to the public internet, but are protected from in-bound connections. Ftwall adds logic to such systems to block all fast-track traffic, thus protecting precious network bandwidth and reducing the risk of legal action resulting from the downloading of copyright material by network users. The link for this article located at Lowth.com is no longer available. . The 'p2pblocker' initiative offers a free software extension for iptables designed to efficiently prevent LimeWire data flow.. P2Pwall Add-in, Iptables Firewall, Kazaa Traffic Blocking, Network Management. . Anthony Pell

Calendar%202 Aug 29, 2003 User Avatar Anthony Pell Firewalls
74

Advancements In Corporate Wi-Fi Management and Enhanced Security Protocols

Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to control and keep safe. Now, a host of new management and security options are springing up as Wi-Fi penetrates corporate environments. Read on . . . . Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to control and keep safe. Now, a host of new management and security options are springing up as Wi-Fi penetrates corporate environments. Read on to find out what's in store. As Wi-Fi hardware becomes a corporate standard, vendors are rolling out increasingly sophisticated management, security, and software development options. Some of the newer Wi-Fi products are designed to boost network management capabilities, offering features comparable to those for tried-and-true networking options like Ethernet. Vendors are offering software suites designed to hook wired networks into wireless networks seamlessly, integrating key wired functions into the Wi-Fi network and providing bandwidth-management and identity controls. Other next-generation enterprise Wi-Fi products are designed to quell ongoing security fears. Many vendors are moving away from the Wired Equivalent Privacy (WEP) standard, whose static, shared encryption keys might linger long enough to be cracked by hostile outsiders, and toward the Wi-Fi Protected Access (WPA) protocol. The link for this article located at IBM is no longer available. . Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to . wi-fi, networks, until, point, exciting, difficult. . Anthony Pell

Calendar%202 Jun 24, 2003 User Avatar Anthony Pell Network Security
78

BigFix 3.0: New Tools for Patch Management and Bandwidth Control

Focusing on the near-Herculean task network executives face in keeping patches current on their Microsoft, Macintosh and Linux software, BigFix last week introduced tools to help with the heavy lifting. With Version 3.0 of its Patch Manager, the company has . . . . Focusing on the near-Herculean task network executives face in keeping patches current on their Microsoft, Macintosh and Linux software, BigFix last week introduced tools to help with the heavy lifting. With Version 3.0 of its Patch Manager, the company has added integration with Active Directory, controls to ensure proper downloads and throttle bandwidth consumption, and the ability to assign responsibility for certain machines to individual administrators. The link for this article located at Network World Fusion is no longer available. . Explore the revolutionary features of BigFix's latest Patch Manager solutions that simplify the challenge of keeping software current across diverse systems.. Patch Management Software, Bandwidth Control, System Administration. . LinuxSecurity.com Team

Calendar%202 Jun 10, 2003 User Avatar LinuxSecurity.com Team Vendors/Products
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200