Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
74

GeoIP Filtering With Nftables For Improved Linux Network Security

This LinuxSecurity.com article featured on the frontpage of Slashdot examines the concept of geo filtering and how it could add a valuable layer of security to your firewall , and explores how the Geolocation for nftables project is leveraging Open Source to provide intuitive, customizable geo filtering on Linux. . What if you could block connections to your network in real-time from countries around the world such as Russia, China and Brazil where the majority of cyberattacks originate? What if you could redirect connections to a single network based on their origin? As you can imagine, being able to control these things would reduce the number of attack vectors on your network, improving its security. You may be surprised that this is not only possible, but straightforward and easy, by implementing GeoIP filtering on your nftables firewall with Geolocation for nftables . . Geo filtering enhances Linux network security by restricting access based on location. Using nftables, admins can block foreign connections, enhancing safety.. GeoIP Filtering, Nftables Security, Network Defense. . Brittany Day

Calendar 2 Feb 15, 2021 User Avatar Brittany Day Network Security
72

Soldered Spy Chips Present Serious Risks to Firewall Protection

The tiny ATtiny85 chip doesn’t look like the next big cyberthreat facing the world, but sneaking one on to a firewall motherboard would be bad news for security were it to happen. Learn more in an interesting Naked Security article: . In fact, this has already happened as part of a project by researcher Monta Elkins, designed to prove that this sort of high-end hardware hack is no longer the preserve of nation-states. Elkins soldered the 5mm x 5mm ATtiny85 chip from an Arduino board to his test firewall’s circuit board just in front of the system’s serial port. The link for this article located at Naked Security is no longer available. . Monta Elkins reveals the vulnerability of firewall defenses through the use of inexpensive espionage microchips, questioning standard assumptions.. Spy Chips, Firewall Security, Cybersecurity Threats, Hardware Attacks, Arduino Awareness. . Brittany Day

Calendar 2 Oct 14, 2019 User Avatar Brittany Day Firewalls
74

Hardening Network Routing and Data Protection for Security

In today’s world we are constantly reminded of the day to day dangers that exist in our society. According to statistics people are becoming the victims of Identity Theft at an alarming rate, it is estimated that 246,570 people had their identities stolen in 2004 alone. Businesses are taking every precaution imaginable to protect the privacy of their consumers. We live in an electronic age, things like paying bills, shopping, ordering clothing, and banking are done online. Yes; it is a very convenient way to do business! It is also very dangerous! . The preferred method of protecting information is a combination of encryption, tunneling, packet filtering, encapsulation, and firewall use. The link for this article located at InfoSec Writers is no longer available. . Investigate strategies for protecting your information using encryption techniques and firewalls to achieve strong cybersecurity.. Network Hardening, Data Protection, Encryption Techniques, Firewall Security. . Brittany Day

Calendar 2 Jun 16, 2006 User Avatar Brittany Day Network Security
83

New York Financial CIO Data Breach: Recovery and Security Challenges

A VETERAN CIO of a New York city-based financial services company learned in july 2002 that several vital files had vanished from one of his company's 25 servers. An employee had tried to find some information and failed. That's when IS . . . . A VETERAN CIO of a New York city-based financial services company learned in july 2002 that several vital files had vanished from one of his company's 25 servers. An employee had tried to find some information and failed. That's when IS discovered that there was, in fact, no company information on that particular server at all. Panicked, the CIO and his staff went into emergency mode. They soon discovered that a hacker had found his way through their firewall and wiped out all the production files on the server, leaving chaos and a couple of strangely labeled files in his wake. Two frantic days--and 15 hours of work--later, the alien files were deleted and the missing data restored through backup tapes. But it took an additional two weeks to be sure that the hacker hadn't accessed and tainted any of the company's 24 other servers. The link for this article located at CSO Online is no longer available. . A tech CEO encountered an unexpected cybersecurity incident, prompting recovery initiatives as essential information vanished from databases.. Data Breach Response, Financial IT Security, Disaster Recovery, Backup Solutions, Server Security. . LinuxSecurity.com Team

Calendar 2 Dec 10, 2002 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

SmoothWall Security Advisory: Encrypted Password Hash Risk Details

Update: Project founder responds below . "SmoothWall does not use shadowed passwords in their firewall implementation. While this is not inherently dangerous as firewall systems are not designed as multi-user, an unauthorized user gaining access to the system via exploitation . . . . Update: Project founder responds below . "SmoothWall does not use shadowed passwords in their firewall implementation. While this is not inherently dangerous as firewall systems are not designed as multi-user, an unauthorized user gaining access to the system via exploitation of an unprivileged process may be able to gain administrative access by copying the password hash, and launching a brute force cracking program against it." It seems several smoothwall developers have developed an attitude towards accepting criticizm from other security professionals and don't feel this is an issue that deserves their attention. The issue escalated when the lead person responsible for the project called it "Trench Warfare." It seems he doesn't take criticism too well? Is the state of the project in jeopardy? Is there a battle going on between the people developing the project and attitude towards their users? Are there other security holes that aren't being fixed? Users interested in a system not succeptible to this security vulnerability might try Slackware. Users interested in a web-managable secure solution might try EnGarde. Update 13:49 EST - Richard Morell, smoothwall project founder, responded to LinuxSecurity.com with the following email. It certainly wasn't our intention to mislead. We report, you decide. There is also a page on their site now that provides their perspective. Subject: Factual reporting of the article you posted Date: Fri, 18 Jan 2002 17:13:49 +0000 From: Richard Morrell To: This email address is being protected from spambots. You need JavaScript enabled to view it. Dave, I really really really wish a site of the standing of Linux Security would check its sources. Its really appalling. You've made sweeping statements about ourproject that if you please fix then I'd be grateful. Juergen Schmidt is a noise, an unpleasant but effective noise, a radical without a cause - he loves stirring it - can't write effective journalism and hates being made to look what he is - half witted and unable to do basic research at shell level. Lawrence Manning the code leader behind SmoothWall responded to Juergen throughout but Juergen forgot to mention that we twice made him look a dork by finding flaws in his research, your article today made us look like we don't care when we do and we work long hours so please correct this once you've read Lawrences OWN response. Richard Morrell Project Manager, Founder AND FUNDER The link for this article located at SecurityFocus is no longer available. . TechSecure is dealing with issues regarding the compromise of hashed user passwords. The founder of the initiative has released a statement concerning the security breach.. SmoothWall Security, Password Hash Exposure, Firewall Risk. . LinuxSecurity.com Team

Calendar 2 Jan 18, 2002 User Avatar LinuxSecurity.com Team Vendors/Products
72

Linux 2.4: IPTables Advisory for FTP PORT Flaw Reported Unauthorized Access

Firewalls using Linux Kernel 2.4.x with IPTables could potentially be compromised as a result of bad logic in the FTP PORT processing. "There is a security flaw in the manner in which the PORT command is interpreted and processed. Essentially, you . . . . Firewalls using Linux Kernel 2.4.x with IPTables could potentially be compromised as a result of bad logic in the FTP PORT processing. "There is a security flaw in the manner in which the PORT command is interpreted and processed. Essentially, you can pass any IP/port in an FTP PORT commmand, and the module will not validate these parameters, adding an entry to the RELATED ruleset allowing connections from the FTP server, any source port, to the specified destination IP and port. In most cases, people make stringent security rules and have lax firewall rules regarding RELATED connections, allowing the attacker to connect to anywhere. This can be used, for example, for the FTP server to connect to any TCP port on the firewall, or any other node protected by the firewall. Even though there may be rules normally denying this type of traffic, it would pass through the firewall, because of the rule allowing RELATED. The attacker does not even need to have a valid login in the FTP server, as the PORT command is interpreted by the module independently of any authentication procedures (USER and PASS)." The link for this article located at Tempest Security is no longer available. . Linux Kernel versions 2.4.x firewalls could encounter vulnerabilities stemming from issues related to FTP PORT handling, which may result in possible security violations.. Linux 2.4 IPTables, FTP PORT Security, Firewall Flaws. . Anthony Pell

Calendar 2 Apr 17, 2001 User Avatar Anthony Pell Firewalls
72

Impersonation Attacks: Protecting Firewalls Against Deceptive Intrusions

Lately, hackers have discovered they can sneak into your computer by sending look-alike imposters to the firewall's gate. The hackers simply rename a snooping program or a virus so that it has the same file name as your browser or e-mail . . . . Lately, hackers have discovered they can sneak into your computer by sending look-alike imposters to the firewall's gate. The hackers simply rename a snooping program or a virus so that it has the same file name as your browser or e-mail program, and your firewall program will wave it right through the gate. A report, published last month in eWeek, says the deception works with software firewalls made by Sygate Technologies (Personal Firewall) and by Symantec Corp. (Norton Personal Firewall). The trade publication then confirmed the problem by duplicating it in its own labs. The trouble with a vulnerability like this is that it doesn't take a brain surgeon to bring it off. All a hacker has to do is rename his own program and send it along the way. So if you worry that --- by writing about this --- I'm giving hackers new ideas, stop worrying. This unattended back door is well-known in hacking circles, and some of the first do-it-yourself hacking programs already are taking advantage of it. The link for this article located at Atlanta Journal-Constitution is no longer available. . Discover how cybercriminals utilize deceptive replicas to evade network defenses and jeopardize your safety.. firewall protection,hacker tactics,cybersecurity best practices,impersonation attack. . Anthony Pell

Calendar 2 Jan 29, 2001 User Avatar Anthony Pell Firewalls
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here