Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several remotely exploitable security issues were found in the Bind Internet Domain Name Server. It was discovered that Bind incorrectly handled the cache size limit (CVE-2023-2828) and the recursive-clients quota (CVE-2023-2911). With a low attack complexity and a high availability impact, these bugs have received a National Vulnerability Database severity rating of “High”. . A remote attacker could possibly use these issues to consume memory or to cause Bind to crash, resulting in a denial of service (DoS). An important Bind security update that fixes these DoS bugs has been released. We strongly recommend that all impacted users apply the Bind updates issued by their distro(s) now to prevent downtime due to an attack. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Online assailants may take advantage of vulnerabilities in Bind software leading to system failures or service interruptions. Install the latest security patches to address these threats.. Remote Exploit, Bind DNS, DoS Attacks, Security Issues, High Severity. . Brittany Day
Security experts are urging Microsoft and Juniper to patch a year-old IPv6 vulnerability so dangerous it can freeze any Windows machine on a LAN in a matter of minutes.. Microsoft has downplayed the risk because the hole requires a physical connection to the wired LAN. Juniper says it has delayed a patch because the hole only affects a small number of its products and it wants the IETF to fix the protocol instead. The vulnerability was initially discovered in July 2010 by Marc Heuse, an IT security consultant in Berlin. He found that products from several vendors were vulnerable, including all recent versions of Windows, Cisco routers, Linux and Juniper The link for this article located at Network World is no longer available. . Authorities recommend that Microsoft and Juniper swiftly address a critical IPv6 denial-of-service flaw impacting various platforms.. IPv6 Exploit, DoS Attack Protection, Microsoft Patching, Juniper Security Fix. . LinuxSecurity.com Team
Joseph Idziorek, graduate in electrical and computer engineering, has been researching computer security. The study conducts research on sites that have been experiencing denial of service attacks, in which hackers try to get unauthorized access and hinder them.. An example of this is WikiLeaks, where the site was hacked after releasing documents of U.S. State Department cables that were considered classified information. "The purpose of such an attack is to bring down the website so nobody can use it," Idziorek said. "These have been quite prevalent throughout the Internet for the last 15 years since the Internet has been around." The link for this article located at iowa State Daily is no longer available. . The growing threat of cyber attacks, especially Denial of Service (DoS), jeopardizes internet security and the reliability of crucial information platforms. DoS Attack, Internet Threats, Cybersecurity Research. . LinuxSecurity.com Team
Great coverage on the Twitter/FB DDoS on CIO. CNET also has several articles The denial of service (DOS) attacks which knocked Twitter offline and slowed down Facebook response times yesterday may have been designed to target just one individual. . Max Kelly, chief security officer at Facebook, said the problems experienced by those trying to access the two sites, as well as LiveJournal and Blogger, may have been motivated by efforts to silence a Georgian blogger on the one-year anniversary of Georgia's invasion of South Ossetia. The blogger, who has accounts on all four of the sites under the name 'Cyxymu', was an outspoken critic of the 2008 South Ossetia War, also known as the Russia-Georgia War, which began on August 7 2008. The link for this article located at CIO is no longer available. . Max Kelly, Facebook's chief of security, discusses the recent DDoS attacks on a well-known Georgian blogger, revealing the struggle against online censorship today. DDoS Attack,Cyber Threats,Blogger Incident,Social Media Safety,Security Analysis. . Anthony Pell
Forget spam, viruses, worms, malware and phishing. These threats are apparently old school when compared to a new class of denial-of-service (DOS) attacks that threaten wireless data networks. The latest wireless network threats were outlined in a talk here Thursday by Krishan Sabnani, vice president of networking research at Bell Labs, at the Cyber Infrastructure Protection Conference at City College of New York. . Sabnani said the latest wireless data network threats are the result of inherent weaknesses in Mobile IP, a protocol that uses tunneling and complex network triangulation to allow mobile devices to move freely from one network to another. The link for this article located at Network World is no longer available. . Emerging DOS attacks focus on exploiting weaknesses in Mobile IP, jeopardizing the integrity of wireless communications.. Dos Attack, Wireless Network Threat, Mobile IP Security, Network Defense, Cyber Threats. . Dave Wreski
This week, experts sent two drafts to the Internet Engineering Task Force (IETF)the technical standards-setting body for the Internet proposing different ways of fixing a problem in the way that Internet Protocol version 6 (IPv6) allows the source of network data to determine its path through the network. The drafts recommend that the IPv6 feature should either be eliminated or, at the very least, disabled by default. . The specification, known as the Type 0 Routing Header (RH0), allows computers to tell IPv6 routers to send data by a specific route. Originally envisioned as a way to let mobile users to retain a single IP for their devices, the feature has significant security implications. During a presentation at the CanSecWest conference on April 18, researchers Philippe Biondi and Arnaud Ebalard pointed out that RH0 support allows attackers to amplify denial-of-service attacks on IPv6 infrastructure by a factor of at least 80. The link for this article located at SecurityFocus is no longer available. . Specialists recommend additional strategies to mitigate IPv6 RH0 vulnerabilities that intensify DoS threats compromising cyber defense.. IETF Standards, IPv6 Security, DoS Attack Mitigation, Network Routing Issues, RH0 Fix Proposal. . Bill Locke
Many of Estonia's government agencies are still unreachable via the Web today after hackers launched denial-of-service attacks that rendered many of their sites useless over the weekend. . The DOS attacks are presumed to be extensions of Russian nationalists' protests against the Estonian government, which have resulted in one death, more than 150 injuries, and 1,100 arrests over the last few days. The link for this article located at Dark Reading is no longer available. . The DOS attacks are presumed to be extensions of Russian nationalists' protests against the Estonian. estonia's, government, agencies, still, unreachable, today, hackers, launched. . Brittany Day
A Spanish hacker who launched a denial of service attack that hobbled the net connections of an estimated three million users has been jailed for two years and fined €1.4m. Santiago Garrido, 26, (AKA Ronnie and Mike25) launched the attack using a computer worm in retaliation for been banned from the popular "Hispano" IRC chat room for breaking its rules. . The link for this article located at TheRegister.co.uk is no longer available. . The link for this article located at TheRegister.co.uk is no longer available.. spanish, hacker, launched, denial, service, attack, hobbled, connections. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.