Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
How a Chinese hacker used my private nickname, personal emails, and sensitive documents to try to blackmail me.. In 2007, I opened an email from an unknown sender. The message greeted me by a nickname known only to family and close friends. I was in Shanghai, unwinding late at night after a long day, pleased to be contacted by someone familiar from across the Pacific. I figured someone close to me must have gotten a new email address. But the note was signed The link for this article located at Slate is no longer available. . In 2007, a faceless individual took advantage of my personal alias and confidential information in a misguided attempt at extortion. Delve into the unsettling specifics.. Chinese Hacker, Privacy Threat, Personal Information, Email Security, Cyber Attack. . LinuxSecurity.com Team
An Adobe security advisory warns of a new critical vulnerability in Flash Player 10.2.153.1 for Windows, Macintosh, Linux and Solaris, Flash Player 10.2.156.12 for Android and the Authplay.dll component in Adobe Reader and Acrobat X 10.0.2 and all earlier versions. . There are already reports that the vulnerability is being exploited using crafted .swf files embedded in Microsoft Word .doc files which are sent as an email attachment. The vulnerability can, when exploited appropriately, allow an attacker to take control of a system. The Krebs on Security blog reports that the vulnerability has been used as part of a targeted spear-phishing campaign disguised as important government documents and launched against organisations or individuals who work for the US government. Another example of the attack shows an email with a title of "Disentangling Industrial Policy and Competition Policy In China" with a supposed copy of an article on that subject attached. The link for this article located at H Security is no longer available. . There are already reports that the vulnerability is being exploited using crafted .swf files embedde. adobe, security, advisory, warns, critical, vulnerability, flash, player. . LinuxSecurity.com Team
The U.S. government has been stepping up its use of smart cards to help lock down its computer networks, but hackers have found ways around them.. Over the past 18 months, security consultancy Mandiant has come across several cases where determined attackers were able to get onto computers or networks that required both smart cards and passwords. In a report set to be released Thursday, Mandiant calls this technique a "smart card proxy." The attack works in several steps. First, the criminals hack their way onto a PC. Often they'll do this by sending a specially crafted e-mail message to someone at the network they're trying to break into. The message will include an malicious attachment that, when opened, gives the hacker a foothold in the network. The link for this article located at PC World is no longer available. . Over the past 18 months, security consultancy Mandiant has come across several cases where determine. government, stepping, smart, cards, computer, netwo. . LinuxSecurity.com Team
The SpamAssassin Milter plug-in which plugs in to Milter and calls SpamAssassin, contains a security vulnerability which can be exploited by attackers using a crafted email to inject and execute code on a mail server. The SpamAssassin Milter plug-in is frequently used to run SpamAssassin on Postfix servers.. In order to exploit the vulnerability, the plug-in must be called with the -x expand flag. For attackers to obtain root privileges, as the author of the security advisory proclaims, the plug-in has to be started as root The link for this article located at H Security is no longer available. . In order to exploit the vulnerability, the plug-in must be called with the -x expand flag. For attac. spamassassin, milter, plug-in, which, plugs, calls, security. . LinuxSecurity.com Team
A break-in targeting State Department computers worldwide last summer occurred after a department employee in Asia opened a mysterious e-mail that quietly allowed hackers inside the U.S. government's network. . In the first public account revealing details about the intrusion and the government's hurried behind-the-scenes response, a senior State Department official described an elaborate ploy by sophisticated international hackers. They used a secret break-in technique that exploited a design flaw in Microsoft software. The link for this article located at Yahoo! News is no longer available. . Explore the incursion at the Treasury Department where cybercriminals exploited vulnerabilities in Adobe systems. Learn additional details!. Email Exploit,Hacker Intrusion,State Department Cybersecurity. . LinuxSecurity.com Team
A bug in Usermin, a widely-used administration console for Unix and Linux, could allow an attacker to run malicious code via a specially-crafted email, according to security researchers. . . .. A bug in Usermin, a widely-used administration console for Unix and Linux, could allow an attacker to run malicious code via a specially-crafted email, according to security researchers. Usermin allows users of Unix and Linux to administer their own accounts on a network via a Web-based interface, including reading email. The tool isn't included in Unix or Linux distributions by default, but is often used with Webmin, one of the most popular system administration tools, which ships with Linux distributions such as Suse, Mandrake and Gentoo. A separate, less serious bug affects both Webmin and Usermin, researchers said. The link for this article located at Matthew Broersma is no longer available. . An issue in Usermin, a popular administrative interface for Unix/Linux systems, has the potential to enable harmful email strategies to run malicious code.. Usermin Bug, Email Exploit, Admin Security. . LinuxSecurity.com Team
In the escalating clash between online scammers and security vendors, the attackers have once again developed new tactics that give them the upper hand in bypassing filters and infiltrating corporate networks, experts say. . . .. The new techniques, which experts began seeing sporadically earlier this year and in large waves in recent weeks, involve the use of a process called steganography, or embedding or hiding text in an image. In the most recent cases, spam and phishing messages have incorporated complex images containing text. In some cases, the image files include hidden code designed to exploit known vulnerabilities in e-mail clients and Web browsers. The most prominent example of the steganography wave is a recent variation on the ubiquitous Citibank phishing scam that attempts to lure recipients into disclosing online banking user names and passwords. Previous versions used text and images, such as authentic-looking Citibank logos and privacy seals. But versions that began surfacing recently are made up of one large image file containing all the text. "We continually modify our systems to enhance safeguards for our customers," said a spokesperson for Citibank, a unit of Citigroup Inc., in New York. "It is also important that consumers be aware of these issues and act appropriately." The link for this article located at Dennis Fisher is no longer available. . The new techniques, which experts began seeing sporadically earlier this year and in large waves in . escalating, clash, between, online, scammers, security, vendors, attackers, again. . LinuxSecurity.com Team
A newly identified snooping technology allows someone sending an e-mail to see what the recipient wrote when it is forwarded on to another user, an Internet privacy group announced Monday. It really is a wiretap and it's "very illegal and very . . . . A newly identified snooping technology allows someone sending an e-mail to see what the recipient wrote when it is forwarded on to another user, an Internet privacy group announced Monday. It really is a wiretap and it's "very illegal and very easy to do," said Richard Smith, chief technology officer for the Privacy Foundation based in Denver, in a column he wrote for the non-profit educational and research organization. The vulnerability exists in mail that uses HTML (HyperText Markup Language). A few lines of JavaScript can be embedded in an e-mail message and allows the recipient's mail to be returned to the original sender. It only works, however, if the recipient's e-mail program is set to read JavaScript. The link for this article located at CNN is no longer available. . A newly identified snooping technology allows someone sending an e-mail to see what the recipient wr. newly, identified, snooping, technology, allows, someone, sending, e-mail, recipient. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.