Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -1 articles for you...
81

Email Spoofing Case Study: Steve Long's Joe Job Incident

Late last year, Steve Long opened up his e-mail account and got a huge surprise: A ton of rejected or redirected e-mails he didn't write. "I thought, 'Oh, I wrote in the wrong address.' 137 (e-mails) later I realized something's wrong," he said. . .. Late last year, Steve Long opened up his e-mail account and got a huge surprise: A ton of rejected or redirected e-mails he didn't write. "I thought, 'Oh, I wrote in the wrong address.' 137 (e-mails) later I realized something's wrong," he said . That "something wrong" turned out to be what the anti-spam industry calls a "Joe job." It's a simple way of making spam look like it didn't come from the original sender. A Joe job is one of the oldest, and easiest, spamming tricks in the book, said spam consultant Ben Westbrook, chief executive officer of Mail-Filters.com. The link for this article located at ABCNews is no longer available. . Maria Smith found herself bewildered by a sudden surge of denied applications, triggered by a false persona—an identity theft scheme.. Email Spoofing, Joe Job, Cybersecurity Case Studies. . LinuxSecurity.com Team

Calendar%202 Jan 28, 2003 User Avatar LinuxSecurity.com Team Privacy
67

SSH Connections: Gateway Hosts In Corporate Networks Explained

In the corporate world, companies commonly require all outgoing connections to pass through a proxy server or gateway host : a machine connected to both the company network and the outside. Although connected to both networks, a gateway host doesn't act as a router, and the networks remain separated.. . .. In the corporate world, companies commonly require all outgoing connections to pass through a proxy server or gateway host : a machine connected to both the company network and the outside. Although connected to both networks, a gateway host doesn't act as a router, and the networks remain separated. Rather, it allows limited, application-level access between the two networks. In this case study, we discuss issues of SSH in this environment: Connecting transparently to external hosts using ssh Making scp connections Running SSH-within-SSH by port forwarding . In the corporate world, companies commonly require all outgoing connections to pass through a proxy . corporate, world, companies, commonly, require, outgoing, connections, through, proxy. . LinuxSecurity.com Team

Calendar%202 Mar 29, 2002 User Avatar LinuxSecurity.com Team Cryptography
83

The Intriguing Case Study of Raphael Gray in Cybersecurity

Can you remember your last hacking experience? Perhaps it was carving a pathway through the Amazonian rain forest during your gap-year trek? Or was it a Sunday morning spent wrestling with the shears in an effort to make your garden-privet resemble . . . . Can you remember your last hacking experience? Perhaps it was carving a pathway through the Amazonian rain forest during your gap-year trek? Or was it a Sunday morning spent wrestling with the shears in an effort to make your garden-privet resemble a cockerel? If you were teenager Raphael Gray, then your last hacking endeavour was certainly memorable. Why? Because it resulted in American FBI agents rapping on the door of his home in deepest Wales, one frosty morn in March. The young fool's crime was to hijack the details of some 23,000 credit cards from the databases of numerous online retailers using nothing more than a basic home computer and a modem. Gray considered himself a "saint of e-commerce" whose mission was to expose online security holes, but the media were quick to label him a hacker - and it stuck The link for this article located at VNUNet is no longer available. . Reflect on your recent cyber adventures and delve into the notorious incidents involving Raphael Gray's maneuvers in the realm of digital security.. Hacking Experience, Cybercrime Stories, Online Security Awareness. . LinuxSecurity.com Team

Calendar%202 Nov 22, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Small Business Case Study: Cost-Effective VPN for Remote Offices

It was a common enough problem for a small business: AMT Asset Management, a Marlboro, New Jersey-based brokerage with six employees, needed a way to connect its Boca Raton, Florida office to headquarters. The goal was to provide the smaller office . . . . It was a common enough problem for a small business: AMT Asset Management, a Marlboro, New Jersey-based brokerage with six employees, needed a way to connect its Boca Raton, Florida office to headquarters. The goal was to provide the smaller office access to the Web-based securities-pricing information that amt was already receiving at its New Jersey location. That way, amt could avoid having to subscribe to a separate outside data provider just for the Florida office--for upwards of $1,200 a month. The obvious solution would have been a secure virtual private network--in this case, essentially a broadband pipe through a telecommunications carrier--linking the two sites. But when amt president Jeffrey Gerstel, who doubles as the company's technical support, explored this alternative, he saw that it wasn't really an option at all. Quotes that ranged as high as several thousand dollars each month scared him off. "We spoke to a few network companies, and the solutions were very expensive," says Gerstel. A vpn was simply too pricey for his tiny company. The link for this article located at ZDNet is no longer available. . Discover how ABC Corp. developed a budget-friendly VPN solution to boost secure remote access for its offices while ensuring user satisfaction and security. VPN Solutions, Small Business Networking, Secure Connections. . Anthony Pell

Calendar%202 Feb 06, 2001 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200