Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
83

Advanced Perl CGI Techniques for Comprehensive Security Testing

This works on the perl pipe bug. It'll take an arg that's the address of a website and it's cgi script with some args to the script then figure out if it can exploit it and how. It's worked on everything I've tried it on, though I have limited test boxes. It's pretty dirty but it works. . . This utility cleverly takes advantage of the Python subprocess vulnerability in web scripts by focusing on designated endpoints.. Perl Exploitation, CGI Bugs, Security Testing Tools, Web App Attacks. . LinuxSecurity.com Team

Calendar%202 Jun 21, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Immunity Canvas 6.47: Cloudburst Attack Unleashes VM Host Threat

'Cloudburst' memory-corruption exploit released with Immunity's new version of Canvas penetration testing software. Researchers for some time have demonstrated the possibility of one of virtualization's worst nightmares -- a guest virtual machine (VM) infiltrating and hacking its host system. Now another commercial tool is offering an exploit that does exactly that.. The newest version of Immunity's Canvas commercial penetration testing tool, v6.47, includes the so-called Cloudburst attack module, which was developed by Immunity researcher Kostya Kortchinsky to exploit a VMWare vulnerability (CVE-2009-1244) in VMware Workstation that lets a user or attacker in a "guest" VM break into the actual host operating environment. VMware issued a patch for the bug in April. "Companies and administrators tend to trust that breaking out of a VM is not possible," says Nick Selby, director of the enterprise security practice at The 451 Group. "A lot of people consider this to be just another proof-of-concept. They don't understand that is a commercially available exploit." The link for this article located at Dark Reading is no longer available. . Defense's Palette v5.83 unveils Thunderstorm, enabling GZ to infiltrate server networks through buffer overflow vulnerability.. Immunity Canvas, Cloudburst Attack, Exploit Tool, Virtual Machine Exploit, Penetration Testing. . LinuxSecurity.com Team

Calendar%202 Jun 08, 2009 User Avatar LinuxSecurity.com Team Vendors/Products
83

Sqlninja 0.2.3 Enhances Automated SQL Injection for MS SQL Server

Sqlninja is a tool written in PERL to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main goal is to provide a remote access on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to help and automate the process of taking over a DB Server when a SQL Injection vulnerability has been discovered. Being able to upload 'netcat.exe' as 100% plain ASCII GET/POST requests and no FTP? Evasion techniques, code obfuscation, and DNS-tunneld pseudo shells? Sounds like an SQL Injection tool to check out!. . Sqlninja is a tool written in PERL to exploit SQL Injection vulnerabilities on a web application tha. sqlninja, written, exploit, injection, vulnerabilities, application. . LinuxSecurity.com Team

Calendar%202 May 30, 2008 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

Sqlninja 0.2.2: Advanced Tool for SQL Injection Exploits

Sqlninja is a tool to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main goal is to provide a remote shell on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to help and automate the process of taking over a DB Server when a SQL Injection vulnerability has been discovered. With features such as evasion techniques, a more sophisticated upload module, and automatic URL-encoding, why not take a look at Sqlninja and see if your DB is secure today?. The link for this article located at Darknet.org is no longer available. . The link for this article located at Darknet.org is no longer available.. sqlninja, exploit, injection, vulnerabilities, application, microsoft. . LinuxSecurity.com Team

Calendar%202 Apr 15, 2008 User Avatar LinuxSecurity.com Team Security Projects
83

Mpack Exploit Toolkit Focuses on Addressing Web Security Vulnerabilities

Exploit frameworks have become more focused and specialized, sniper scoping specific vulnerabilities in popular applications such as Apple's Quicktime Movie viewer and even Mozilla's Firefox web browser. This is a constant reminder to me of how diligent one must be to run a secure environment - not only your primary OS, but ALL third party applications! Read on as the Washington Post fills us in on a tool called 'Mpack', a script kiddie's dream with Web interface and point / click / root abilities that have been spotted on over 10,000 web sites thus far. . Researchers have been charting the rise in threats created by a new software exploit tool known as "Mpack," a virtual attack kit designed to be embedded in hacked or malicious Web sites. It targets security holes in multiple software products, including Apple's QuickTime media player, and outdated Windows plug-ins for Mozilla's Firefox and Opera Web browsers. . The Mpack exploit framework is a powerful toolkit designed to exploit vulnerabilities in popular web applications, enabling unauthorized access and malicious activities. Exploit Tool, Web Security Threats, Application Vulnerabilities, Mpack Tool. . LinuxSecurity.com Team

Calendar%202 Jun 19, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

IIS: Secret Exploit Tool Creates High Risk For Administrators

Security professionals are concerned that a program used by hackers to exploit a flaw in Microsoft IIS webserver has not been made public. They fear that the hackers are keeping the tool secret in a bid to launch further damaging IIS . . . . Security professionals are concerned that a program used by hackers to exploit a flaw in Microsoft IIS webserver has not been made public. They fear that the hackers are keeping the tool secret in a bid to launch further damaging IIS attacks. The latest in a long line of vulnerabilities in IIS was discovered last week, when it was revealed that a remote buffer overflow in all versions of IIS Internet Services API could be exploited to give an attacker complete control of a system. But the security community is worried that hackers may be hanging on to the tool used for exploiting this hole, rather than releasing it for analysis so that a patch can be developed. Typically, when a hole is discovered, a tool capable of exploiting the glitch appears within 48 hours, encouraging administrators to patch their systems quickly. But so far, no such tool has appeared to push administrators into gear, although rumour has it that hackers are in possession of such a program, potentially leaving the six million users of IIS at risk. Security firm @stake warned that administrators are less likely to react to an advisory if there is no exploit tool available. Hackers thrive on a lack of awareness in security and, by keeping the exploit tool underground, network administrators could be lulled into a false sense of security. [ All of article content ] The link for this article located at vnunet is no longer available. . Security professionals are concerned that a program used by hackers to exploit a flaw in Microsoft I. security, professionals, concerned, program, hackers, exploit, microsoft. . LinuxSecurity.com Team

Calendar%202 Jun 25, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200