Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Image spam is a serious and growing problem, not least because of its ability to circumvent traditional email spam filters to clog servers and inboxes. In just half a year, the problem of image spam has become general enough to be representative of 35 per cent of all junk mail. Not only this, but image spam is taking up 70 per cent of the bandwidth bulge on account of the large file sizes every single one represents. . The link for this article located at Net-Security.org - LogError is no longer available. . The link for this article located at Net-Security.org - LogError is no longer available.. image, serious, growing, problem, least, because, ability, circumvent, traditio. . LinuxSecurity.com Team
You manage a heterogeneous network and want to provide different Quality of Service agreements and network restrictions based on the client operating system. With pf and altq, you can now limit the amount of bandwidth available to users of different operating systems, or force outbound web traffic through a transparent filtering proxy. This article describes how to install pf, altq, and Squid on your FreeBSD router and web proxy to achieve these goals. . In an ideal environment, there would be no need for bandwidth shaping, OS fingerprint-based filtering, or even Quality of Service (QoS). Several factors in the real world require a change of game plan. Bandwidth is not free, and many ISPs charge customers based on bandwidth usage. Worms, viruses, and compromised systems can all lead to higher bandwidth costs. In the wake of the W32.Slammer worm, which saturated the connections of infected networks, many companies saw their monthly connectivity bills skyrocket due to the worm's traffic. Filtering your connections based on operating system can go partway to helping keep such situations from running away. While I will focus on filtering traffic from Windows systems, this process can equally apply to BSD, Linux, Mac OS, or a host of other operating systems listed in the pf.os file on your system. This may be especially useful to people running older versions of OSes that have not or cannot be patched but still require some network connectivity. . In an ideal environment, there would be no need for bandwidth shaping, OS fingerprint-based filterin. manage, heterogeneous, network, provide, different, quality, service, agreements. . Brittany Day
You manage a heterogeneous network and want to provide different Quality of Service agreements and network restrictions based on the client operating system. With pf and altq, you can now limit the amount of bandwidth available to users of different operating systems, or force outbound web traffic through a transparent filtering proxy. This article describes how to install pf, altq, and Squid on your FreeBSD router and web proxy to achieve these goals. . The U.S. Department of Homeland Security is drafting regulations, expected by August, that will define how to implement more-stringent security, required under the Real ID Act for state-issued driver's licenses and other ID cards. The rules, which go into effect in May 2008, may push some agencies toward chip-based cards. Indeed, Blair said, "any security features could become obsolete in two years." The link for this article located at Security Pipeline is no longer available. . The U.S. Department of Homeland Security is drafting regulations, expected by August, that will defi. manage, heterogeneous, network, provide, different, quality, service, agreements. . Brittany Day
The "p2pwall" project has developed a GPL add-in for iptables based firewalls that allows blocking of traffic to and from "Fast-Track" software such as "Kazaa", Kazaa-lite, iMesh and grokster. The software is designed for use in "permissive" firewall configurations where . . . . The "p2pwall" project has developed a GPL add-in for iptables based firewalls that allows blocking of traffic to and from "Fast-Track" software such as "Kazaa", Kazaa-lite, iMesh and grokster. The software is designed for use in "permissive" firewall configurations where home-net hosts are permitted more or less unlimited access to the public internet, but are protected from in-bound connections. Ftwall adds logic to such systems to block all fast-track traffic, thus protecting precious network bandwidth and reducing the risk of legal action resulting from the downloading of copyright material by network users. The link for this article located at Lowth.com is no longer available. . The 'p2pblocker' initiative offers a free software extension for iptables designed to efficiently prevent LimeWire data flow.. P2Pwall Add-in, Iptables Firewall, Kazaa Traffic Blocking, Network Management. . Anthony Pell
Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to control and keep safe. Now, a host of new management and security options are springing up as Wi-Fi penetrates corporate environments. Read on . . . . Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to control and keep safe. Now, a host of new management and security options are springing up as Wi-Fi penetrates corporate environments. Read on to find out what's in store. As Wi-Fi hardware becomes a corporate standard, vendors are rolling out increasingly sophisticated management, security, and software development options. Some of the newer Wi-Fi products are designed to boost network management capabilities, offering features comparable to those for tried-and-true networking options like Ethernet. Vendors are offering software suites designed to hook wired networks into wireless networks seamlessly, integrating key wired functions into the Wi-Fi network and providing bandwidth-management and identity controls. Other next-generation enterprise Wi-Fi products are designed to quell ongoing security fears. Many vendors are moving away from the Wired Equivalent Privacy (WEP) standard, whose static, shared encryption keys might linger long enough to be cracked by hostile outsiders, and toward the Wi-Fi Protected Access (WPA) protocol. The link for this article located at IBM is no longer available. . Wi-Fi networks have, up until this point, been a bit like the Wild West: exciting, but difficult to . wi-fi, networks, until, point, exciting, difficult. . Anthony Pell
Focusing on the near-Herculean task network executives face in keeping patches current on their Microsoft, Macintosh and Linux software, BigFix last week introduced tools to help with the heavy lifting. With Version 3.0 of its Patch Manager, the company has . . . . Focusing on the near-Herculean task network executives face in keeping patches current on their Microsoft, Macintosh and Linux software, BigFix last week introduced tools to help with the heavy lifting. With Version 3.0 of its Patch Manager, the company has added integration with Active Directory, controls to ensure proper downloads and throttle bandwidth consumption, and the ability to assign responsibility for certain machines to individual administrators. The link for this article located at Network World Fusion is no longer available. . Explore the revolutionary features of BigFix's latest Patch Manager solutions that simplify the challenge of keeping software current across diverse systems.. Patch Management Software, Bandwidth Control, System Administration. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.