Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Seven anti-phishing projects, I especially find the browser recon and countermeasures one as a trendy concept, as phishers are already taking advantage of vulnerabilities allowing them to figure out a browser's history, thus establish a more reputable communication with the victim -- adaptive phishing. . The link for this article located at Dancho Danchev is no longer available. . The link for this article located at Dancho Danchev is no longer available.. seven, anti-phishing, projects, especially, browser, recon, countermeasures, trend. . LinuxSecurity.com Team
I was at CardTech/SecurTech 2006 recently and had a meeting with Cryptography Research, a company focused on securing smartcards. I spoke to Kit Rodgers, VP, and Ken Warren, Manager, about smartcard tamper resistance with differential power analysis countermeasures. Listen to the interview with Cryptography Research Listen Now. The link for this article located at InfoWorld is no longer available. . The link for this article located at InfoWorld is no longer available. . cardtech/securtech, recently, meeting, cryptography, research, company. . LinuxSecurity.com Team
Future worms could evade a network of early-warning sensors hidden across the Internet unless countermeasures are taken, according to new research. In a pair of papers presented at the Usenix Security Symposium here Thursday, computer scientists said would-be attackers can locate such sensors, which act as trip wires that detect unusual activity. That would permit nefarious activities to take place without detection. . Internet sensor networks, such as the University of Michigan's Internet Motion Sensor and the SANS Internet Storm Center, are groups of machines that monitor traffic across active networks and chunks of unused IP space. The sensor networks generate and publish statistical reports that permit an analyst to track the traffic, sniff out malicious activity and seek ways to combat it. Just as surveillance cameras are sometimes hidden, the locations of the Internet sensors are kept secret. "If the set of sensors is known, a malicious attacker could avoid the sensors entirely or could overwhelm the sensors with errant data," a team of computer scientists from the University of Wisconsin wrote in its award-winning paper titled "Mapping Internet Sensors with Probe Response Attacks." But the Wisconsin researchers discovered that the sensor maps furnish just enough information for someone to create an algorithm that can map the location of the sensors "even with reasonable constraint on bandwidth and resources," John Bethencourt, one of the paper's authors, said in his presentation.. Analysis indicates that emerging malware may bypass cybersecurity frameworks, necessitating advanced protective strategies.. Internet Sensor Networks, Evasion Techniques, Cybersecurity Research. . Brittany Day
Spyware is challenging spam and viruses for the top spot on IT worry lists. Spyware poses considerable threats and risks to enterprise networks and remediation and countermeasures are now being regarded as critical to network security. . How Spyware Threatens Enterprises Spyware is defined as covertly installed software that hijacks web browsers, invades Internet user privacy, displays unsolicited and offensive advertising, and impedes PC performance. The most commonly cited spyware issues worrying enterprise IT staff are loss of productivity and increased helpdesk costs; liability associated with privacy violations; intellectual property theft, information and premature disclosure; and loss of credibility and damage to brand. The link for this article located at Dave Piscitello is no longer available. . How Spyware Threatens Enterprises Spyware is defined as covertly installed software that hijacks web. spyware, challenging, viruses, worry, lists, poses, considerab. . Joe Shakespeare
Citing an "arms race" in the ongoing spam wars, AT&T defended its patenting of a technology to thwart antispam filters. The patent, awarded to AT&T on Nov. 4, describes a "system and method for counteracting message filtering." The patent . . . . Citing an "arms race" in the ongoing spam wars, AT&T defended its patenting of a technology to thwart antispam filters. The patent, awarded to AT&T on Nov. 4, describes a "system and method for counteracting message filtering." The patent details a way to trick filters that compare digital messages to known pieces of spam, altering each message so that no two are exactly the same. "In this way, spam countermeasures based upon duplicate detection schemes are foiled," according to the patent. AT&T's patent wins approval as spam and software patents separately preoccupy the Internet. Opponents, pointing to patent-infringement judgments like that won by Eolas Technologies at Microsoft's expense, say software patents have created a siege mentality in the industry. And the spam problem has resulted in a host of proposed solutions in the software, standards and legislative arenas. . Citing an 'arms race' in the ongoing spam wars, AT&T defended its patenting of a technology to thwar. citing, 'arms, race', ongoing, at&, defended, patenting, technology, thwar. . LinuxSecurity.com Team
I am presently working on creating a taxonomy of information assurance, based on the three aspects of: Security services Information states Security countermeasures These three aspects of Information Assurance (IA) were highlighted by John McCumber [1] as well as a team . . . . I am presently working on creating a taxonomy of information assurance, based on the three aspects of: Security services Information states Security countermeasures These three aspects of Information Assurance (IA) were highlighted by John McCumber [1] as well as a team of West Point researchers [2] as a component of works that define an integrated approach to security. Within the next 6 months, I would like to create a taxonomy that graphically depicts the relationships of these three aspects. My intent is that this taxonomy could be used by the academic community, industry, and government in improving the precision of communication used in discussing information assurance/security topics. I have searched the Internet widely for a taxonomy of IA, but I have not found anything that is sufficiently detailed for application with real world problems. I am posting my initial results here in hopes that an open collaboration process (much like the open source software movement) will yield a useful tool for the security community to use in addressing information assurance issues. The link for this article located at Abe Usher is no longer available. . I am presently working on creating a taxonomy of information assurance, based on the three aspects o. presently, working, creating, taxonomy, information, assurance, based, three, aspects. . LinuxSecurity.com Team
Buffer overflow problems always have been associated with security vulnerabilities. In the past, lots of security breaches have occurred due to buffer overflow. This article attempts to explain what buffer overflow is, how it can be exploited and what countermeasures can be taken to avoid it. . . .. Buffer overflow problems always have been associated with security vulnerabilities. In the past, lots of security breaches have occurred due to buffer overflow. This article attempts to explain what buffer overflow is, how it can be exploited and what countermeasures can be taken to avoid it. Knowledge of C or any other high level language is essential to this discussion. Basic knowledge of process memory layout is useful, but not necessary. Also, all the discussions are based on Linux running on x86 platform. The basic concepts of buffer overflow, however, are the same no matter what platform and operating system is used. The link for this article located at Linux Journal is no longer available. . Buffer overflow problems always have been associated with security vulnerabilities. In the past, lot. buffer, overflow, problems, always, associated, security, vulnerabilities. . LinuxSecurity.com Team
One-third of the 30 billion e-mails sent worldwide each day are spam. That's 10 billion daily pitches for herbal Viagra, Nigerian scams, and genital-enlarging creams piling up in our inboxes. Neither legislation nor litigation against spammers has stemmed the tide, and they're not going to have much of an effect in the future. . .. One-third of the 30 billion e-mails sent worldwide each day are spam. That's 10 billion daily pitches for herbal Viagra, Nigerian scams, and genital-enlarging creams piling up in our inboxes. Neither legislation nor litigation against spammers has stemmed the tide, and they're not going to have much of an effect in the future , either. It's time to give up: Despite the best efforts of legislators, lawyers, and computer programmers, spam has won. Spam is killing e-mail. ...Or at least it's about to destroy the e-mail we're used to: the tool that lets a stranger respond to something you posted on your Web site or that lets a potential client contact you after reading an article you wrote. E-mail is pervasive because it's simple to use, remarkably flexible, and it reaches everyone. The trouble is that e-mail is too good at that third task. Because e-mail inboxes are open to anyone, longtime Internet users now receive hundreds of spams per day, making e-mail virtually unusable without countermeasures. SPAMMERS AND FILTERS The most common countermeasure, server-side filtering, has serious limitations. No automated system can identify spam as well as a human can. Internet service providers certainly try: They block known spammer addresses and use algorithms to identify spam based on an e-mail's contents, subject line, or other headers. AOL and MSN both trumpet spam filtering systems like this in their latest software, and Yahoo! and Microsoft's Hotmail offer junk-mail filters for their Web-based e-mail services. But the filters are running out of gas. The spammers keep multiplying, and they keep finding clever ways to fool the systems designed to stop them. Promising newcomers suchas CloudMark, which taps the collective power of e-mail recipients to identify spam, may improve things for a while. But there will always be a trade-off between catching all the spam and ensuring that every piece of legitimate e-mail gets through. RISE OF `WHITELISTS' So, sophisticated Internet users are turning to a new approach. Instead of trying to block spam while allowing everything else, these users employ software that blocks everything except messages from already known, accepted senders. These systems, called "whitelists," change e-mail from an open system to a closed one. Whitelist applications available today include MailFrontier , ChoiceMail from DigiPortal, Vanquish, and the freeware Tagged Message Delivery Agent. There's also a whitelist option built into Hotmail, known as the "exclusive" setting. Though it's hidden in the preferences menu (click "Options," then "Junk Mail Filter"), more than 10 percent of Hotmail users reportedly invoke it. Before long, expect all e-mail applications to offer this function. Whitelists typically allow e-mail from everyone in a user's existing address book. Other, unknown senders receive an automated reply, asking them to take further action, such as explain who they are. Or senders may be asked to identify a partially obscured image of a word. A person can make out the word, but automated spammer software can't. The link for this article located at MSNBC is no longer available. . One-third of the 30 billion e-mails sent worldwide each day are spam. That's 10 billion daily pitches overtaking inboxes.. Spam Management, Communication Security, Email Disruption. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.