Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 3 articles for you...
83

Java Under Attack: Insights from the 2014 IBM X-Force Report

Once upon a time, Microsoft was the favorite target of malware developers. As Microsoft improved the defenses in its software, though, cybercrooks moved on to easier pickings. Adobe was a prime target for a while, but Adobe followed Microsoft's lead and made its software more secure as well. . According to data from the 2014 IBM X-Force Threat Intelligence Quarterly Report, the favorite target is now Java. There are two things that put the bulls-eye on an application or platform. The first is distribution. Attackers may be able to develop an exploit for some obscure software that is barely used, but what would be the point? If a malware developer is going to invest the time and effort to create an exploit, he or she wants it to have the greatest possible pool of potential victims. The link for this article located at IT World is no longer available. . According to data from the 2014 IBM X-Force Threat Intelligence Quarterly Report, the favorite targe. microsoft, favorite, target, malware, developers, improved. . LinuxSecurity.com Team

Calendar%202 Mar 06, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Oracle Emergency Update: Java Security Fix Following U.S. Hacker Alert

Oracle Corp. released an emergency update to its Java software for surfing the Web on Sunday, but security experts said the update fails to protect PCs from attack by hackers intent on committing cyber crimes. . The software maker released the update just days after the U.S. Department of Homeland Security urged PC users to disable the program because of bugs in the software that were being exploited to commit identity theft and other crimes. The link for this article located at Globe and Mail is no longer available. . The software maker released the update just days after the U.S. Department of Homeland Security urge. oracle, released, emergency, update, software, surfing, sunday. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2013 User Avatar LinuxSecurity.com Team Vendors/Products
78

How To Disable Java In Firefox And Chrome For Better Security

When the Homeland Security folks get into the mix and urge all computer users to disable Java in their browsers, you know it. To disable Java in Firefox go to Tools> Add-ons. In Chrome or Chromium type The link for this article located at fossforce is no longer available. . Discover the steps to turn off Java in both Firefox and Chrome, following the recommendations set forth by Homeland Security to enhance your online security.. Java Security, Browser Protection, Disable Java. . LinuxSecurity.com Team

Calendar%202 Jan 14, 2013 User Avatar LinuxSecurity.com Team Vendors/Products
83

Oracle Java Critical Patch Remote Code Execution Vuln 2025-0011-1

After informing a researcher just a few days ago that . They fell under heavy criticism after their statement as it was demonstrated by multiple people that the vulnerability was fairly trivial to exploit and could cause some serious damage. I'm glad to see they took the proactive step of understanding the vulnerability and pushing out a patch. I just wish they would fix the way in which Java manages updates (multiple redundant copies of the software with minor differences). Under criticism for not patching a critical vulnerability in its recently acquired Java virtual machine, Oracle on Thursday released an emergency update that eliminates the zero-day threat. Functionality in the Java Web Start component made it trivial for attackers to remotely execute malicious code on end-user machines. Tavis Ormandy, one of the researchers who first discovered the threat, said he alerted Java handlers inside Oracle The link for this article located at Darknet is no longer available. . Oracle addresses critical Java zero-day threat with an emergency patch for remote code execution vulnerability, ensuring user safety.. Java Update, Remote Code Attack, Oracle Java Security. . LinuxSecurity.com Team

Calendar%202 Apr 16, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Sun Microsystems: Java Remains Proprietary Amid Open Source Push

This can be considered closure to an issue that could have affected the entire open-source community. The idea of making Java the basis of a secure, open-source development platform is simply not viable right now. . . .. Despite urging from competitors and open source advocates, Sun Microsystems Inc. of Santa Clara, Calif., will not open the source to its Java programming language anytime soon, said Sun CEO Scott McNealy during a news conference at the 2004 FOSE conference. "We're trying to understand what problem does it solve that is not already solved," McNealy said. Last month Eric Raymond, noted open source programmer and president of the Open Source Initiative advocacy group, posted an open letter to McNealy calling for Sun to make Java open source. "Sun's insistence on continuing tight control of the Java code has damaged Sun's long-term interests by throttling acceptance of the language in the open-source community, ceding the field (and probably the future) to scripting-language competitors like Python and Perl," Raymond wrote. Java is an object-oriented language developed by Sun. Written originally for embedded devices, Java was designed to allow a single program to be written once and be able to run on multiple platforms without modification, through the use of the software-based Java Virtual Machine. Although Sun maintains Java is an open implementation, allowing other software manufacturers to license the code and build competing Java-based products, the company maintains control over what changes can be made to the language. One advantage of keeping Java under its own control is that competing factions break the language into incompatible versions, McNealy said. He noted that Linux already suffers from this problem. The leading Linux vendor, Red Hat Inc. of Raleigh, N.C., has already introduced features in its own version of Linux that make it incompatible with other versions. Since Linux is open source, Red Hat was free to build its own version of the operating system. In contrast, when MicrosoftCorp. of Redmond, Wash., tried to introduce features into its own version of Java that wouldn't work in non-Windows systems, Sun successfully blocked the changes through legal means, McNealy said. The link for this article located at GovernmentComputerNews is no longer available. . Scott McNealy explains the reasoning for Java's proprietary design, emphasizing its impact on the software development landscape amidst the rising calls for open source options. Java Development, Software Control, Open Source Advocacy. . LinuxSecurity.com Team

Calendar%202 Mar 25, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
67

Master the Fundamentals of Cryptography for Secure Java Development

The Java platform, both its base language features and library extensions, provides an excellent base for writing secure applications. In this tutorial, the first of two parts on Java security, Brad Rubin guides you through the basics of cryptography and how . . . . The Java platform, both its base language features and library extensions, provides an excellent base for writing secure applications. In this tutorial, the first of two parts on Java security, Brad Rubin guides you through the basics of cryptography and how it is implemented in the Java programming language, using plenty of code examples to illustrate the concepts. The link for this article located at IBM is no longer available. . The Java platform, both its base language features and library extensions, provides an excellent bas. platform, language, features, library, extensions, provides, excellent. . LinuxSecurity.com Team

Calendar%202 Nov 26, 2003 User Avatar LinuxSecurity.com Team Cryptography
83

Webmin: Local Root Threat From Java Runtime Environment Vulnerability

Leading this Security Alerts is a java runtime vulnerability. "In this column, we look at a local root vulnerability in Webmin; a bug in BSD-based TCP/IP stacks; a vulnerability in the Java Runtime Environment; buffer overflows in listar, Imlib, and Open . . . . Leading this Security Alerts is a java runtime vulnerability. "In this column, we look at a local root vulnerability in Webmin; a bug in BSD-based TCP/IP stacks; a vulnerability in the Java Runtime Environment; buffer overflows in listar, Imlib, and Open Unix and UnixWare 7's rpc.cmsd; and problems in Netscape, QPopper, PHP's move_uploaded_file() function, Penguin Traceroute, PHP Net Toolpack, and Mandrake's kdm." . A critical vulnerability within the Java Runtime Environment poses risks for local root access, necessitating urgent action in security protocols.. Java Runtime Environment, Webmin, Local Root Threat, Security Alert, Access Issue. . LinuxSecurity.com Team

Calendar%202 Mar 26, 2002 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

Guide to Installing JSSE for HTTPS Implementation in Java

In this column, I'll show you how to install JSSE and use it to implement HTTPS (i.e., HTTP over SSL). I'll provide you with an example of a mini-HTTPS server and Java clients that support SSL. I'll then show you how . . . . In this column, I'll show you how to install JSSE and use it to implement HTTPS (i.e., HTTP over SSL). I'll provide you with an example of a mini-HTTPS server and Java clients that support SSL. I'll then show you how to setup a bi-directional SSL scheme where clients authenticate servers and servers authenticate clients. Networked applications, by their very nature, require close attention to security. The Secure Sockets Layer (SSL) protocol was developed by Netscape in 1994 as a common solution to client-server communication security issues. SSL supports a flexible client-server authentication scheme and provides for algorithm-independent encrypted client-server communication. SSL runs as a layer between the Transport Control Protocol (TCP) and application layer protocols, such as HTTP and SMTP. . In this column, I'll show you how to install JSSE and use it to implement HTTPS (i.e., HTTP over SSL. column, install, implement, https. . LinuxSecurity.com Team

Calendar%202 May 04, 2001 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200