Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 9 articles for you...
74

Sendmail Configurations for ILOVEYOU Worm Protection Guide

Included here is information that can be added to your sendmail configuration to protect your internal users from the ILOVEYOU worm from spreading, as well as more information from this bugtraq post. Be sure to note that variations . . . . Included here is information that can be added to your sendmail configuration to protect your internal users from the ILOVEYOU worm from spreading, as well as more information from this bugtraq post. Be sure to note that variations are already appearing. This bugtraq post points out a variation, as well as a procmail filter, filters for Postfix, ideas from Sendmail.com, and other great information to put this damn thing to rest. The link for this article located at Jose Nazario / bugtraq is no longer available. . Protect your sendmail setup against the ILOVEYOU worm by modifying MIME settings, filtering attachments, enhancing access control, and educating users. sendmail configurations, ILOVEYOU worm, email security measures. . Anthony Pell

Calendar%202 Nov 10, 2023 User Avatar Anthony Pell Network Security
83

2006 Wal-Mart Breach: Internal Development Team Targeted

Wal-Mart was the victim of a serious security breach in 2005 and 2006 in which hackers targeted the development team in charge of the chain. Internal documents reveal for the first time that the nation The link for this article located at Wired is no longer available. . Internal documents reveal for the first time that the nationThe link for this article located at Wir. wal-mart, victim, serious, security, breach, which, hackers, targeted. . LinuxSecurity.com Team

Calendar%202 Oct 28, 2009 User Avatar LinuxSecurity.com Team Hacks/Cracks
72

Configuring A Linux DMZ: Essential Setup For Secure Networking

(The)Demilitarized zone, used to secure an internal network from external access. You can use Linux firewall to create DMZ easily. There are many different ways to design a network with a DMZ. The basic method is to use a single Linux firewall with 3 Ethernet cards. The following simple example discusses DMZ setup and forwarding public traffic to internal servers. There's a little advanced know-how required here and he recommends a couple good firewalls to set up such functionality just in case this very useful guide doesn't fit the bill. If you are looking to set up a Linux Demilitarized zone a couple of options include EnGarde, IpCop and others. . The link for this article located at is no longer available. . Learn to create a secure Linux DMZ effectively, safeguarding your internal network while managing public-facing services and threats. Linux DMZ, Network Optimization, Firewall Setup, Secure Network, IP Forwarding. . Brittany Day

Calendar%202 Dec 17, 2007 User Avatar Brittany Day Firewalls
67

OpenPGP Enhances Internal Email Security For IT Managers

PGP, or Pretty Good Privacy, is a security program that allows users to encrypt and decrypt e-mail, as well as incorporating the added protection of digital signatures for user verification. OpenPGP builds upon PGP with enhanced PGP standards, military-grade security and an increased number of encryption algorithms. Michael W. Lucas, author of PGP & GPG: E-mail for the Practical Paranoid recommends that IT managers take advantage of easy-to-use OpenPGP to add an extra layer of internal security that can prevent tampering from within an organization. The most difficult part is not installation or using OpenPGP but educating users. . OpenPGP puts control of security in the hands of the IT manager. Even if you only use it internally amongst your IT staff, it provides a layer of security that's difficult to achieve otherwise. One common problem in computer security is 'who watches the watchmen?' Your e-mail administrator has the ability to view and edit any e-mail message that passes through the system. When I'm troubleshooting a network problem, I often must use a packet sniffer. At that point, I will see the contents of e-mail messages unless I take specific steps to prevent it. Even your helpdesk staff has access to people's personal data. All of these people can change that data, or even create entirely fraudulent data, files and messages and attribute them to other people. The link for this article located at TechTarget is no longer available. . OpenPGP puts control of security in the hands of the IT manager. Even if you only use it internally . pretty, privacy, security, program, allows, users, encrypt, decrypt, e-mail. . LinuxSecurity.com Team

Calendar%202 May 10, 2006 User Avatar LinuxSecurity.com Team Cryptography
74

Understanding the Risks of Insider Attacks Faced by Organizations Today

For many years external security threats received more attention than internal security threats, but the focus has changed. While viruses, worms, Trojans and DoS are serious, attacks perpetrated by people with trusted insider status—employees, ex-employees, contractors and business partners—pose a far greater threat to organizations in terms of potential cost per occurrence and total potential cost than attacks mounted from outside. The reason insider attacks "hurt" disproportionately is that insiders can and will take advantage of two important rights: trust and physical access. . The link for this article located at CSO Online is no longer available. . The hidden threat of insider risks exposes critical vulnerabilities from trusted individuals within an organization, necessitating increased vigilance to protect sensitive data. Insider Threats, Employee Risks, Security Measures, Access Control. . Benjamin D. Thomas

Calendar%202 Apr 13, 2006 User Avatar Benjamin D. Thomas Network Security
74

Firewalls And IDS Create False Sense Of Internal Security

In an effort to boost sales and generate revenue, one U.S. multinational energy company recently embraced the Internet to bolster external communication and internal collaboration. In addition to creating a corporate web site, the firm deployed hundreds of intranet applications for . . . . In an effort to boost sales and generate revenue, one U.S. multinational energy company recently embraced the Internet to bolster external communication and internal collaboration. In addition to creating a corporate web site, the firm deployed hundreds of intranet applications for procurement, expense reporting and other processes. Numerous departments and branch offices worldwide also set up specialized web sites for partners, customers and even project management. Though the company has achieved its strategic goals for the web, by leveraging valuable communication and management tools that lower costs and streamline processes, it has, unwittingly, set itself up for malicious intrusion. The decentralized and ad hoc intranet application deployment has created a fragmented, multi-platform mosaic that raises important security questions (see boxout below). Clearly for internal or external web applications, security is the biggest concern today. The dramatic number of attacks is expected by CERT to double again this year to almost 100,000. It is estimated by Gartner Group that as many as 70 to 80 percent of these attacks are coming in through ports 80 and 443, commonly used by web applications. Such attacks can be costly and detrimental to corporate credibility. Privileged customer, financial and operational information or valuable intellectual property can be damaged or stolen during the average hacker intrusion of 15 minutes or less. The average loss is more than $2 million among those willing to quantify losses, according to an FBI/CSI survey. Downtime alone can potentially cost tens of thousands of dollars per minute. "There is much more illegal and unauthorized activity going on in cyberspace than corporations admit totheir clients, stockholders and business partners or report to law enforcement. Incidents are widespread, costly and commonplace," the survey concluded. The link for this article located at SCMagazine is no longer available. . Explores how firewalls and intrusion detection systems (IDS) can foster a false sense of security in organizations, despite the growing cyber threat landscape. Network Security,Cyber Threats,Intrusion Detection,Internal Security. . Anthony Pell

Calendar%202 Aug 29, 2002 User Avatar Anthony Pell Network Security
81

U.K. Cyberlaws: Assessing Whether Company Data Is An Asset Or Threat

Is your company data an asset or a threat? The issue will be discussed with particular reference to the U.K. Information is a commodity. Indeed, for many companies it's the most valuable asset they possess, especially when it comes to customer relationships. . .. Is your company data an asset or a threat? The issue will be discussed with particular reference to the U.K. Information is a commodity. Indeed, for many companies it's the most valuable asset they possess, especially when it comes to customer relationships . The more a company knows about its customers, the easier it is to reach out and touch them. Now though, governments across Europe are under pressure to develop legislation in response to the growing consensus that businesses should be made accountable for how personal information is stored, used and distributed. Consequently, a raft of new laws have emerged which codify privacy rights for the digital age. The Data Protection Act (DPA) and the Regulation of Investigatory Powers Act (RIPA) are, in the United Kingdom, the first in this new wave of 'cyberlaws' - legislation designed to reinforce privacy rights threatened by the unregulated dissemination of information, in a world where everything from birth records to shopping habits are stored electronically. Much of the thinking behind cyberlaw is so new however, that the majority of companies are unaware it even exists, let alone realize they must now comply. And yet, unless business leaders take formal action to protect the integrity of their data, it could become a major threat rather than an important asset. The link for this article located at SCM is no longer available. . Evaluate your organization's information to determine if it is a valuable asset or a potential risk, especially in light of recent UK cyber laws and privacy regulations. Cybersecurity Legislation, Data Protection Act, Compliance, IT Security. . LinuxSecurity.com Team

Calendar%202 Jul 29, 2002 User Avatar LinuxSecurity.com Team Privacy
74

Telco Security: Challenges in Internal Network Safeguards and DDoS Risks

Searching for relief from the pressures of abundant capacity and intense competition for their core services, carriers such as WorldCom Inc. and Sprint Corp. are rushing headlong into the managed security services business. But the plans are drawing fire from security experts and customers, who say the carriers should look internally and secure their networks before offering external services. . . .. Searching for relief from the pressures of abundant capacity and intense competition for their core services, carriers such as WorldCom Inc. and Sprint Corp. are rushing headlong into the managed security services business. But the plans are drawing fire from security experts and customers, who say the carriers should look internally and secure their networks before offering external services. Although for years many carriers have employed large staffs of security professionals, most providers still lack basic security safeguards such as DDoS (distributed-denial-of-service) protection on their data networks. Indeed, Telus Corp., a Canadian company, last week became the first North American carrier to install an anti-DDoS system. Preventing and mitigating DDoS attacks is a challenge in that it requires cooperation among the victim, its ISP and, often, the attacker's ISP. But such cooperation is nearly impossible if providers aren't prepared for an attack. The link for this article located at eWeek is no longer available. . Providers face intense rivalry, prompting them to seek outside security solutions while neglecting to fortify their own infrastructures initially.. Telco Security, Network Protection, DDoS Mitigation, Internal Safeguards. . Anthony Pell

Calendar%202 May 22, 2002 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200