Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 427
Alerts This Week
Warning Icon 1 427

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
67

Google: Weak Cryptographic Key Risk Allows Email Spoofing

So he wondered if the e-mail might have been spoofed . Then he noticed something strange. Google was using a weak cryptographic key to certify to recipients that its correspondence came from a legitimate Google corporate domain. Anyone who cracked the key could use it to impersonate an e-mail sender from Google, including Google founders Sergey Brin and Larry Page. The link for this article located at Wired is no longer available. . Microsoft employed a vulnerable authentication method, risking the chance of online account breaches and personal data exposure.. Email Spoofing, Google Security, Cyber Threats, Cryptographic Key. . LinuxSecurity.com Team

Calendar%202 Oct 24, 2012 User Avatar LinuxSecurity.com Team Cryptography
81

Understanding Email Headers: Essential Guide to Spoofing Detection

This document is intended to provide a comprehensive introduction to the behavior of email headers. It is primarily intended to help victims of unsolicited email ("email spam") attempting to determine the real source of the (generally forged) email that plagues them; it should also help in attempts to understand any other forged email. It may also be beneficial to readers interested in a general-purpose introduction to mail transfer on the Internet. Although the document intentionally avoids "how-to-forge" discussions, some of the information contained in it might be turned to that purpose by a sufficiently determined mind. The author explicitly does not endorse malicious or deceptive falsification of email, of course, and any use for such purposes of the information contained in this document is contrary to its purpose. . The link for this article located at StopSpam.org is no longer available. . The link for this article located at StopSpam.org is no longer available. . document, intended, provide, comprehensive, introduction, behavior, email, headers. . LinuxSecurity.com Team

Calendar%202 Jun 14, 2006 User Avatar LinuxSecurity.com Team Privacy
81

Email Spoofing Nightmare: Andy Markley's Labor Day Challenge

Andy Markley was really looking forward to a work-free Labor Day weekend far away from his computer. But he made the mistake of checking his inbox before he left for his planned holiday. Hundreds of e-mails greeted Markley that Saturday . . . . Andy Markley was really looking forward to a work-free Labor Day weekend far away from his computer. But he made the mistake of checking his inbox before he left for his planned holiday. Hundreds of e-mails greeted Markley that Saturday morning, most of them reporting an undeliverable message sent from his e-mail account. And interspersed with those bounced messages were angry rants accusing Markley of sending out spam offering pharmaceuticals without a prescription. Markley isn't a spammer, he's a graphic artist. He was the victim of a con artist who sent thousands of spam messages carefully crafted to appear as if they had originated from Markley's domain. The scam almost cost Markley his business, his reputation, his website and his sanity. His Internet service provider wouldn't help him, despite the fact that his computer and his e-mail account were being overwhelmed by an avalanche of spam-spew that made it impossible to do business or even collect his personal e-mail. The link for this article located at Wired is no longer available. . Emily Thompson unveils the hidden costs of unused subscriptions and cluttered inboxes as autumn approaches. This October, she's ready to declutter!. Spam Awareness, Email Spoofing, Cybersecurity Tips. . LinuxSecurity.com Team

Calendar%202 Oct 02, 2003 User Avatar LinuxSecurity.com Team Privacy
81

Amazon Takes Legal Action Against Eleven Groups for Email Spoofing Issues

Amazon.com has sued 11 entities in the United States and Canada for forging its domain name in their e-mail spam messages, the company has announced. The lawsuits represent the latest salvo in Amazon's fight to suppress and eradicate such spoofing. . .. Amazon.com has sued 11 entities in the United States and Canada for forging its domain name in their e-mail spam messages, the company has announced. The lawsuits represent the latest salvo in Amazon's fight to suppress and eradicate such spoofing . The company filed suit in seven U.S. federal district courts and in the Ontario Superior Court of Justice in Canada, seeking millions of dollars in punitive damages as a deterrent to other spammers. Companies cited in the legal action include Rockin Time Holdings and Matrix Consulting Group LLC, both sellers of "Gain Pro Penile Pills"; several unidentified defendants hawking human growth hormone through Healthproductsnow.net; Cheapfilter.com, seller of a pay-per-view scam device; and GrantGiveaways.com, purveyor of "Free Cash Grants, Never Repay." "The actions taken today by Amazon.com and by the state of New York will send a strong message that [this conduct] will not be tolerated," David Zapolsky, Amazon vice president and associate general counsel, said. After all, although Amazon has expanded its offerings over the last couple of years, the company has yet to begin selling human growth hormone, free cash grants or devices that allow users to receive free pay-per-view channels. The link for this article located at eCommerceTimes is no longer available. . Amazon.com has sued 11 entities in the United States and Canada for forging its domain name in their. amazon, entities, united, states, canada, forging, domain, their. . LinuxSecurity.com Team

Calendar%202 Aug 28, 2003 User Avatar LinuxSecurity.com Team Privacy
81

Email Spoofing Case Study: Steve Long's Joe Job Incident

Late last year, Steve Long opened up his e-mail account and got a huge surprise: A ton of rejected or redirected e-mails he didn't write. "I thought, 'Oh, I wrote in the wrong address.' 137 (e-mails) later I realized something's wrong," he said. . .. Late last year, Steve Long opened up his e-mail account and got a huge surprise: A ton of rejected or redirected e-mails he didn't write. "I thought, 'Oh, I wrote in the wrong address.' 137 (e-mails) later I realized something's wrong," he said . That "something wrong" turned out to be what the anti-spam industry calls a "Joe job." It's a simple way of making spam look like it didn't come from the original sender. A Joe job is one of the oldest, and easiest, spamming tricks in the book, said spam consultant Ben Westbrook, chief executive officer of Mail-Filters.com. The link for this article located at ABCNews is no longer available. . Maria Smith found herself bewildered by a sudden surge of denied applications, triggered by a false persona—an identity theft scheme.. Email Spoofing, Joe Job, Cybersecurity Case Studies. . LinuxSecurity.com Team

Calendar%202 Jan 28, 2003 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200