Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Included here is information that can be added to your sendmail configuration to protect your internal users from the ILOVEYOU worm from spreading, as well as more information from this bugtraq post. Be sure to note that variations . . . . Included here is information that can be added to your sendmail configuration to protect your internal users from the ILOVEYOU worm from spreading, as well as more information from this bugtraq post. Be sure to note that variations are already appearing. This bugtraq post points out a variation, as well as a procmail filter, filters for Postfix, ideas from Sendmail.com, and other great information to put this damn thing to rest. The link for this article located at Jose Nazario / bugtraq is no longer available. . Protect your sendmail setup against the ILOVEYOU worm by modifying MIME settings, filtering attachments, enhancing access control, and educating users. sendmail configurations, ILOVEYOU worm, email security measures. . Anthony Pell
Wal-Mart was the victim of a serious security breach in 2005 and 2006 in which hackers targeted the development team in charge of the chain. Internal documents reveal for the first time that the nation The link for this article located at Wired is no longer available. . Internal documents reveal for the first time that the nationThe link for this article located at Wir. wal-mart, victim, serious, security, breach, which, hackers, targeted. . LinuxSecurity.com Team
(The)Demilitarized zone, used to secure an internal network from external access. You can use Linux firewall to create DMZ easily. There are many different ways to design a network with a DMZ. The basic method is to use a single Linux firewall with 3 Ethernet cards. The following simple example discusses DMZ setup and forwarding public traffic to internal servers. There's a little advanced know-how required here and he recommends a couple good firewalls to set up such functionality just in case this very useful guide doesn't fit the bill. If you are looking to set up a Linux Demilitarized zone a couple of options include EnGarde, IpCop and others. . The link for this article located at is no longer available. . Learn to create a secure Linux DMZ effectively, safeguarding your internal network while managing public-facing services and threats. Linux DMZ, Network Optimization, Firewall Setup, Secure Network, IP Forwarding. . Brittany Day
PGP, or Pretty Good Privacy, is a security program that allows users to encrypt and decrypt e-mail, as well as incorporating the added protection of digital signatures for user verification. OpenPGP builds upon PGP with enhanced PGP standards, military-grade security and an increased number of encryption algorithms. Michael W. Lucas, author of PGP & GPG: E-mail for the Practical Paranoid recommends that IT managers take advantage of easy-to-use OpenPGP to add an extra layer of internal security that can prevent tampering from within an organization. The most difficult part is not installation or using OpenPGP but educating users. . OpenPGP puts control of security in the hands of the IT manager. Even if you only use it internally amongst your IT staff, it provides a layer of security that's difficult to achieve otherwise. One common problem in computer security is 'who watches the watchmen?' Your e-mail administrator has the ability to view and edit any e-mail message that passes through the system. When I'm troubleshooting a network problem, I often must use a packet sniffer. At that point, I will see the contents of e-mail messages unless I take specific steps to prevent it. Even your helpdesk staff has access to people's personal data. All of these people can change that data, or even create entirely fraudulent data, files and messages and attribute them to other people. The link for this article located at TechTarget is no longer available. . OpenPGP puts control of security in the hands of the IT manager. Even if you only use it internally . pretty, privacy, security, program, allows, users, encrypt, decrypt, e-mail. . LinuxSecurity.com Team
For many years external security threats received more attention than internal security threats, but the focus has changed. While viruses, worms, Trojans and DoS are serious, attacks perpetrated by people with trusted insider status—employees, ex-employees, contractors and business partners—pose a far greater threat to organizations in terms of potential cost per occurrence and total potential cost than attacks mounted from outside. The reason insider attacks "hurt" disproportionately is that insiders can and will take advantage of two important rights: trust and physical access. . The link for this article located at CSO Online is no longer available. . The hidden threat of insider risks exposes critical vulnerabilities from trusted individuals within an organization, necessitating increased vigilance to protect sensitive data. Insider Threats, Employee Risks, Security Measures, Access Control. . Benjamin D. Thomas
In an effort to boost sales and generate revenue, one U.S. multinational energy company recently embraced the Internet to bolster external communication and internal collaboration. In addition to creating a corporate web site, the firm deployed hundreds of intranet applications for . . . . In an effort to boost sales and generate revenue, one U.S. multinational energy company recently embraced the Internet to bolster external communication and internal collaboration. In addition to creating a corporate web site, the firm deployed hundreds of intranet applications for procurement, expense reporting and other processes. Numerous departments and branch offices worldwide also set up specialized web sites for partners, customers and even project management. Though the company has achieved its strategic goals for the web, by leveraging valuable communication and management tools that lower costs and streamline processes, it has, unwittingly, set itself up for malicious intrusion. The decentralized and ad hoc intranet application deployment has created a fragmented, multi-platform mosaic that raises important security questions (see boxout below). Clearly for internal or external web applications, security is the biggest concern today. The dramatic number of attacks is expected by CERT to double again this year to almost 100,000. It is estimated by Gartner Group that as many as 70 to 80 percent of these attacks are coming in through ports 80 and 443, commonly used by web applications. Such attacks can be costly and detrimental to corporate credibility. Privileged customer, financial and operational information or valuable intellectual property can be damaged or stolen during the average hacker intrusion of 15 minutes or less. The average loss is more than $2 million among those willing to quantify losses, according to an FBI/CSI survey. Downtime alone can potentially cost tens of thousands of dollars per minute. "There is much more illegal and unauthorized activity going on in cyberspace than corporations admit totheir clients, stockholders and business partners or report to law enforcement. Incidents are widespread, costly and commonplace," the survey concluded. The link for this article located at SCMagazine is no longer available. . Explores how firewalls and intrusion detection systems (IDS) can foster a false sense of security in organizations, despite the growing cyber threat landscape. Network Security,Cyber Threats,Intrusion Detection,Internal Security. . Anthony Pell
Is your company data an asset or a threat? The issue will be discussed with particular reference to the U.K. Information is a commodity. Indeed, for many companies it's the most valuable asset they possess, especially when it comes to customer relationships. . .. Is your company data an asset or a threat? The issue will be discussed with particular reference to the U.K. Information is a commodity. Indeed, for many companies it's the most valuable asset they possess, especially when it comes to customer relationships . The more a company knows about its customers, the easier it is to reach out and touch them. Now though, governments across Europe are under pressure to develop legislation in response to the growing consensus that businesses should be made accountable for how personal information is stored, used and distributed. Consequently, a raft of new laws have emerged which codify privacy rights for the digital age. The Data Protection Act (DPA) and the Regulation of Investigatory Powers Act (RIPA) are, in the United Kingdom, the first in this new wave of 'cyberlaws' - legislation designed to reinforce privacy rights threatened by the unregulated dissemination of information, in a world where everything from birth records to shopping habits are stored electronically. Much of the thinking behind cyberlaw is so new however, that the majority of companies are unaware it even exists, let alone realize they must now comply. And yet, unless business leaders take formal action to protect the integrity of their data, it could become a major threat rather than an important asset. The link for this article located at SCM is no longer available. . Evaluate your organization's information to determine if it is a valuable asset or a potential risk, especially in light of recent UK cyber laws and privacy regulations. Cybersecurity Legislation, Data Protection Act, Compliance, IT Security. . LinuxSecurity.com Team
Searching for relief from the pressures of abundant capacity and intense competition for their core services, carriers such as WorldCom Inc. and Sprint Corp. are rushing headlong into the managed security services business. But the plans are drawing fire from security experts and customers, who say the carriers should look internally and secure their networks before offering external services. . . .. Searching for relief from the pressures of abundant capacity and intense competition for their core services, carriers such as WorldCom Inc. and Sprint Corp. are rushing headlong into the managed security services business. But the plans are drawing fire from security experts and customers, who say the carriers should look internally and secure their networks before offering external services. Although for years many carriers have employed large staffs of security professionals, most providers still lack basic security safeguards such as DDoS (distributed-denial-of-service) protection on their data networks. Indeed, Telus Corp., a Canadian company, last week became the first North American carrier to install an anti-DDoS system. Preventing and mitigating DDoS attacks is a challenge in that it requires cooperation among the victim, its ISP and, often, the attacker's ISP. But such cooperation is nearly impossible if providers aren't prepared for an attack. The link for this article located at eWeek is no longer available. . Providers face intense rivalry, prompting them to seek outside security solutions while neglecting to fortify their own infrastructures initially.. Telco Security, Network Protection, DDoS Mitigation, Internal Safeguards. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.