Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
81

Seven Innovative Anti-Phishing Projects and Emerging Trends in Security

Seven anti-phishing projects, I especially find the browser recon and countermeasures one as a trendy concept, as phishers are already taking advantage of vulnerabilities allowing them to figure out a browser's history, thus establish a more reputable communication with the victim -- adaptive phishing. . The link for this article located at Dancho Danchev is no longer available. . The link for this article located at Dancho Danchev is no longer available.. seven, anti-phishing, projects, especially, browser, recon, countermeasures, trend. . LinuxSecurity.com Team

Calendar%202 Oct 06, 2006 User Avatar LinuxSecurity.com Team Privacy
67

Smartcard Protection Strategies Against Differential Power Analysis

I was at CardTech/SecurTech 2006 recently and had a meeting with Cryptography Research, a company focused on securing smartcards. I spoke to Kit Rodgers, VP, and Ken Warren, Manager, about smartcard tamper resistance with differential power analysis countermeasures. Listen to the interview with Cryptography Research Listen Now. The link for this article located at InfoWorld is no longer available. . The link for this article located at InfoWorld is no longer available. . cardtech/securtech, recently, meeting, cryptography, research, company. . LinuxSecurity.com Team

Calendar%202 May 15, 2006 User Avatar LinuxSecurity.com Team Cryptography
74

Future Worms Evasion Research and Impact on Internet Sensors

Future worms could evade a network of early-warning sensors hidden across the Internet unless countermeasures are taken, according to new research. In a pair of papers presented at the Usenix Security Symposium here Thursday, computer scientists said would-be attackers can locate such sensors, which act as trip wires that detect unusual activity. That would permit nefarious activities to take place without detection. . Internet sensor networks, such as the University of Michigan's Internet Motion Sensor and the SANS Internet Storm Center, are groups of machines that monitor traffic across active networks and chunks of unused IP space. The sensor networks generate and publish statistical reports that permit an analyst to track the traffic, sniff out malicious activity and seek ways to combat it. Just as surveillance cameras are sometimes hidden, the locations of the Internet sensors are kept secret. "If the set of sensors is known, a malicious attacker could avoid the sensors entirely or could overwhelm the sensors with errant data," a team of computer scientists from the University of Wisconsin wrote in its award-winning paper titled "Mapping Internet Sensors with Probe Response Attacks." But the Wisconsin researchers discovered that the sensor maps furnish just enough information for someone to create an algorithm that can map the location of the sensors "even with reasonable constraint on bandwidth and resources," John Bethencourt, one of the paper's authors, said in his presentation.. Analysis indicates that emerging malware may bypass cybersecurity frameworks, necessitating advanced protective strategies.. Internet Sensor Networks, Evasion Techniques, Cybersecurity Research. . Brittany Day

Calendar%202 Aug 05, 2005 User Avatar Brittany Day Network Security
74

Understanding Spyware Risks and Protection for Enterprise Networks

Spyware is challenging spam and viruses for the top spot on IT worry lists. Spyware poses considerable threats and risks to enterprise networks and remediation and countermeasures are now being regarded as critical to network security. . How Spyware Threatens Enterprises Spyware is defined as covertly installed software that hijacks web browsers, invades Internet user privacy, displays unsolicited and offensive advertising, and impedes PC performance. The most commonly cited spyware issues worrying enterprise IT staff are loss of productivity and increased helpdesk costs; liability associated with privacy violations; intellectual property theft, information and premature disclosure; and loss of credibility and damage to brand. The link for this article located at Dave Piscitello is no longer available. . How Spyware Threatens Enterprises Spyware is defined as covertly installed software that hijacks web. spyware, challenging, viruses, worry, lists, poses, considerab. . Joe Shakespeare

Calendar%202 Jan 11, 2005 User Avatar Joe Shakespeare Network Security
81

AT&T Anti-Spam Patent: Disrupting Filtering Technologies

Citing an "arms race" in the ongoing spam wars, AT&T defended its patenting of a technology to thwart antispam filters. The patent, awarded to AT&T on Nov. 4, describes a "system and method for counteracting message filtering." The patent . . . . Citing an "arms race" in the ongoing spam wars, AT&T defended its patenting of a technology to thwart antispam filters. The patent, awarded to AT&T on Nov. 4, describes a "system and method for counteracting message filtering." The patent details a way to trick filters that compare digital messages to known pieces of spam, altering each message so that no two are exactly the same. "In this way, spam countermeasures based upon duplicate detection schemes are foiled," according to the patent. AT&T's patent wins approval as spam and software patents separately preoccupy the Internet. Opponents, pointing to patent-infringement judgments like that won by Eolas Technologies at Microsoft's expense, say software patents have created a siege mentality in the industry. And the spam problem has resulted in a host of proposed solutions in the software, standards and legislative arenas. . Citing an 'arms race' in the ongoing spam wars, AT&T defended its patenting of a technology to thwar. citing, 'arms, race', ongoing, at&, defended, patenting, technology, thwar. . LinuxSecurity.com Team

Calendar%202 Nov 19, 2003 User Avatar LinuxSecurity.com Team Privacy
79

Developing A Detailed Information Assurance Framework For Security Services

I am presently working on creating a taxonomy of information assurance, based on the three aspects of: Security services Information states Security countermeasures These three aspects of Information Assurance (IA) were highlighted by John McCumber [1] as well as a team . . . . I am presently working on creating a taxonomy of information assurance, based on the three aspects of: Security services Information states Security countermeasures These three aspects of Information Assurance (IA) were highlighted by John McCumber [1] as well as a team of West Point researchers [2] as a component of works that define an integrated approach to security. Within the next 6 months, I would like to create a taxonomy that graphically depicts the relationships of these three aspects. My intent is that this taxonomy could be used by the academic community, industry, and government in improving the precision of communication used in discussing information assurance/security topics. I have searched the Internet widely for a taxonomy of IA, but I have not found anything that is sufficiently detailed for application with real world problems. I am posting my initial results here in hopes that an open collaboration process (much like the open source software movement) will yield a useful tool for the security community to use in addressing information assurance issues. The link for this article located at Abe Usher is no longer available. . I am presently working on creating a taxonomy of information assurance, based on the three aspects o. presently, working, creating, taxonomy, information, assurance, based, three, aspects. . LinuxSecurity.com Team

Calendar%202 Aug 29, 2003 User Avatar LinuxSecurity.com Team Security Projects
77

In-Depth Guide To Buffer Overflow Attacks And Prevention Strategies

Buffer overflow problems always have been associated with security vulnerabilities. In the past, lots of security breaches have occurred due to buffer overflow. This article attempts to explain what buffer overflow is, how it can be exploited and what countermeasures can be taken to avoid it. . . .. Buffer overflow problems always have been associated with security vulnerabilities. In the past, lots of security breaches have occurred due to buffer overflow. This article attempts to explain what buffer overflow is, how it can be exploited and what countermeasures can be taken to avoid it. Knowledge of C or any other high level language is essential to this discussion. Basic knowledge of process memory layout is useful, but not necessary. Also, all the discussions are based on Linux running on x86 platform. The basic concepts of buffer overflow, however, are the same no matter what platform and operating system is used. The link for this article located at Linux Journal is no longer available. . Buffer overflow problems always have been associated with security vulnerabilities. In the past, lot. buffer, overflow, problems, always, associated, security, vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Mar 10, 2003 User Avatar LinuxSecurity.com Team Server Security
81

Email Disruption One-Third Spam Flooding Inboxes - Challenges and Solutions

One-third of the 30 billion e-mails sent worldwide each day are spam. That's 10 billion daily pitches for herbal Viagra, Nigerian scams, and genital-enlarging creams piling up in our inboxes. Neither legislation nor litigation against spammers has stemmed the tide, and they're not going to have much of an effect in the future. . .. One-third of the 30 billion e-mails sent worldwide each day are spam. That's 10 billion daily pitches for herbal Viagra, Nigerian scams, and genital-enlarging creams piling up in our inboxes. Neither legislation nor litigation against spammers has stemmed the tide, and they're not going to have much of an effect in the future , either. It's time to give up: Despite the best efforts of legislators, lawyers, and computer programmers, spam has won. Spam is killing e-mail. ...Or at least it's about to destroy the e-mail we're used to: the tool that lets a stranger respond to something you posted on your Web site or that lets a potential client contact you after reading an article you wrote. E-mail is pervasive because it's simple to use, remarkably flexible, and it reaches everyone. The trouble is that e-mail is too good at that third task. Because e-mail inboxes are open to anyone, longtime Internet users now receive hundreds of spams per day, making e-mail virtually unusable without countermeasures. SPAMMERS AND FILTERS The most common countermeasure, server-side filtering, has serious limitations. No automated system can identify spam as well as a human can. Internet service providers certainly try: They block known spammer addresses and use algorithms to identify spam based on an e-mail's contents, subject line, or other headers. AOL and MSN both trumpet spam filtering systems like this in their latest software, and Yahoo! and Microsoft's Hotmail offer junk-mail filters for their Web-based e-mail services. But the filters are running out of gas. The spammers keep multiplying, and they keep finding clever ways to fool the systems designed to stop them. Promising newcomers suchas CloudMark, which taps the collective power of e-mail recipients to identify spam, may improve things for a while. But there will always be a trade-off between catching all the spam and ensuring that every piece of legitimate e-mail gets through. RISE OF `WHITELISTS' So, sophisticated Internet users are turning to a new approach. Instead of trying to block spam while allowing everything else, these users employ software that blocks everything except messages from already known, accepted senders. These systems, called "whitelists," change e-mail from an open system to a closed one. Whitelist applications available today include MailFrontier , ChoiceMail from DigiPortal, Vanquish, and the freeware Tagged Message Delivery Agent. There's also a whitelist option built into Hotmail, known as the "exclusive" setting. Though it's hidden in the preferences menu (click "Options," then "Junk Mail Filter"), more than 10 percent of Hotmail users reportedly invoke it. Before long, expect all e-mail applications to offer this function. Whitelists typically allow e-mail from everyone in a user's existing address book. Other, unknown senders receive an automated reply, asking them to take further action, such as explain who they are. Or senders may be asked to identify a partially obscured image of a word. A person can make out the word, but automated spammer software can't. The link for this article located at MSNBC is no longer available. . One-third of the 30 billion e-mails sent worldwide each day are spam. That's 10 billion daily pitches overtaking inboxes.. Spam Management, Communication Security, Email Disruption. . LinuxSecurity.com Team

Calendar%202 Nov 18, 2002 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200