Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Once upon a time, Microsoft was the favorite target of malware developers. As Microsoft improved the defenses in its software, though, cybercrooks moved on to easier pickings. Adobe was a prime target for a while, but Adobe followed Microsoft's lead and made its software more secure as well. . According to data from the 2014 IBM X-Force Threat Intelligence Quarterly Report, the favorite target is now Java. There are two things that put the bulls-eye on an application or platform. The first is distribution. Attackers may be able to develop an exploit for some obscure software that is barely used, but what would be the point? If a malware developer is going to invest the time and effort to create an exploit, he or she wants it to have the greatest possible pool of potential victims. The link for this article located at IT World is no longer available. . According to data from the 2014 IBM X-Force Threat Intelligence Quarterly Report, the favorite targe. microsoft, favorite, target, malware, developers, improved. . LinuxSecurity.com Team
Oracle Corp. released an emergency update to its Java software for surfing the Web on Sunday, but security experts said the update fails to protect PCs from attack by hackers intent on committing cyber crimes. . The software maker released the update just days after the U.S. Department of Homeland Security urged PC users to disable the program because of bugs in the software that were being exploited to commit identity theft and other crimes. The link for this article located at Globe and Mail is no longer available. . The software maker released the update just days after the U.S. Department of Homeland Security urge. oracle, released, emergency, update, software, surfing, sunday. . LinuxSecurity.com Team
When the Homeland Security folks get into the mix and urge all computer users to disable Java in their browsers, you know it. To disable Java in Firefox go to Tools> Add-ons. In Chrome or Chromium type The link for this article located at fossforce is no longer available. . Discover the steps to turn off Java in both Firefox and Chrome, following the recommendations set forth by Homeland Security to enhance your online security.. Java Security, Browser Protection, Disable Java. . LinuxSecurity.com Team
After informing a researcher just a few days ago that . They fell under heavy criticism after their statement as it was demonstrated by multiple people that the vulnerability was fairly trivial to exploit and could cause some serious damage. I'm glad to see they took the proactive step of understanding the vulnerability and pushing out a patch. I just wish they would fix the way in which Java manages updates (multiple redundant copies of the software with minor differences). Under criticism for not patching a critical vulnerability in its recently acquired Java virtual machine, Oracle on Thursday released an emergency update that eliminates the zero-day threat. Functionality in the Java Web Start component made it trivial for attackers to remotely execute malicious code on end-user machines. Tavis Ormandy, one of the researchers who first discovered the threat, said he alerted Java handlers inside Oracle The link for this article located at Darknet is no longer available. . Oracle addresses critical Java zero-day threat with an emergency patch for remote code execution vulnerability, ensuring user safety.. Java Update, Remote Code Attack, Oracle Java Security. . LinuxSecurity.com Team
This can be considered closure to an issue that could have affected the entire open-source community. The idea of making Java the basis of a secure, open-source development platform is simply not viable right now. . . .. Despite urging from competitors and open source advocates, Sun Microsystems Inc. of Santa Clara, Calif., will not open the source to its Java programming language anytime soon, said Sun CEO Scott McNealy during a news conference at the 2004 FOSE conference. "We're trying to understand what problem does it solve that is not already solved," McNealy said. Last month Eric Raymond, noted open source programmer and president of the Open Source Initiative advocacy group, posted an open letter to McNealy calling for Sun to make Java open source. "Sun's insistence on continuing tight control of the Java code has damaged Sun's long-term interests by throttling acceptance of the language in the open-source community, ceding the field (and probably the future) to scripting-language competitors like Python and Perl," Raymond wrote. Java is an object-oriented language developed by Sun. Written originally for embedded devices, Java was designed to allow a single program to be written once and be able to run on multiple platforms without modification, through the use of the software-based Java Virtual Machine. Although Sun maintains Java is an open implementation, allowing other software manufacturers to license the code and build competing Java-based products, the company maintains control over what changes can be made to the language. One advantage of keeping Java under its own control is that competing factions break the language into incompatible versions, McNealy said. He noted that Linux already suffers from this problem. The leading Linux vendor, Red Hat Inc. of Raleigh, N.C., has already introduced features in its own version of Linux that make it incompatible with other versions. Since Linux is open source, Red Hat was free to build its own version of the operating system. In contrast, when MicrosoftCorp. of Redmond, Wash., tried to introduce features into its own version of Java that wouldn't work in non-Windows systems, Sun successfully blocked the changes through legal means, McNealy said. The link for this article located at GovernmentComputerNews is no longer available. . Scott McNealy explains the reasoning for Java's proprietary design, emphasizing its impact on the software development landscape amidst the rising calls for open source options. Java Development, Software Control, Open Source Advocacy. . LinuxSecurity.com Team
The Java platform, both its base language features and library extensions, provides an excellent base for writing secure applications. In this tutorial, the first of two parts on Java security, Brad Rubin guides you through the basics of cryptography and how . . . . The Java platform, both its base language features and library extensions, provides an excellent base for writing secure applications. In this tutorial, the first of two parts on Java security, Brad Rubin guides you through the basics of cryptography and how it is implemented in the Java programming language, using plenty of code examples to illustrate the concepts. The link for this article located at IBM is no longer available. . The Java platform, both its base language features and library extensions, provides an excellent bas. platform, language, features, library, extensions, provides, excellent. . LinuxSecurity.com Team
Leading this Security Alerts is a java runtime vulnerability. "In this column, we look at a local root vulnerability in Webmin; a bug in BSD-based TCP/IP stacks; a vulnerability in the Java Runtime Environment; buffer overflows in listar, Imlib, and Open . . . . Leading this Security Alerts is a java runtime vulnerability. "In this column, we look at a local root vulnerability in Webmin; a bug in BSD-based TCP/IP stacks; a vulnerability in the Java Runtime Environment; buffer overflows in listar, Imlib, and Open Unix and UnixWare 7's rpc.cmsd; and problems in Netscape, QPopper, PHP's move_uploaded_file() function, Penguin Traceroute, PHP Net Toolpack, and Mandrake's kdm." . A critical vulnerability within the Java Runtime Environment poses risks for local root access, necessitating urgent action in security protocols.. Java Runtime Environment, Webmin, Local Root Threat, Security Alert, Access Issue. . LinuxSecurity.com Team
In this column, I'll show you how to install JSSE and use it to implement HTTPS (i.e., HTTP over SSL). I'll provide you with an example of a mini-HTTPS server and Java clients that support SSL. I'll then show you how . . . . In this column, I'll show you how to install JSSE and use it to implement HTTPS (i.e., HTTP over SSL). I'll provide you with an example of a mini-HTTPS server and Java clients that support SSL. I'll then show you how to setup a bi-directional SSL scheme where clients authenticate servers and servers authenticate clients. Networked applications, by their very nature, require close attention to security. The Secure Sockets Layer (SSL) protocol was developed by Netscape in 1994 as a common solution to client-server communication security issues. SSL supports a flexible client-server authentication scheme and provides for algorithm-independent encrypted client-server communication. SSL runs as a layer between the Transport Control Protocol (TCP) and application layer protocols, such as HTTP and SMTP. . In this column, I'll show you how to install JSSE and use it to implement HTTPS (i.e., HTTP over SSL. column, install, implement, https. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.