The recently discovered DreamBus botnet uses exploits and brute-force attacks to target PostgreSQL, Redis, SaltStack, Hadoop, Spark, and others enterprise-level apps that run on Linux systems. "The idea is to give the DreamBus gang a foothold on a Linux server where they could later download and install an open-source app that mines the Monero (XMR) cryptocurrency to generate profits for the attackers." . Chances are that if you deploy a Linux server online these days and you leave even the tiniest weakness exposed, a cybercrime group will ensnare it as part of its botnet. The latest of these threats is named DreamBus. Analyzed in a report published last week by security firm Zscaler, the company said this new threat is a variant of an older botnet named SystemdMiner, first seen in early 2019 . . Should you launch a Linux server in the cloud today and overlook any minor weakness, hackers will take advantage of it.. DreamBus Botnet, Linux Applications, Security Threat, Cryptocurrency Mining, Open Source Security. . LinuxSecurity.com Team
Would you like to have a Linux-based router capable of doing tasks such as stateful firewall inspection, virtual private networking, and traffic shaping, in addition to packet routing? Tired of having to do administration from the command line but want to be able to administer your box from a Windows-based client PC? MikroTik's RouterOS may what you need. You can boot RouterOS via diskette, CD, or over the network via PXE or Etherboot-enabled network interface card. You can find a full list of RouterOS technical specifications at the homepage. . I installed the 13MB ISO CD image RouterOS v2.9.23 on a old Compaq Proliant 400 (450MHz, 128MB RAM, 20GB hard disk). The software's minimum configuration is a 100MHz Pentium, 64MB RAM, and 64MB storage. When I booted the PC, I found a list of available packages for RouterOS, including the packages to use DHCP and PPTP servers, Web proxy, and much more. You can select individual packages, all available packages, or the minimum required packages. To see the full range of what RouterOS was capable of, I selected all. After a last warning about the data on the disk being erased, the software is installed. The link for this article located at Linux.com is no longer available. . I revived an old Compaq Proliant 400 by installing RouterOS v2.9.23, a rewarding journey of setup that deepened my networking knowledge and skills. RouterOS Installation, MikroTik Router Features, Linux Firewall Applications. . Brittany Day
Sun Microsystems has previewed a new feature of the Solaris 10 operating system, code-named Project Janus. This new technology will allow users to run Linux binary applications unchanged on the Solaris OS, reducing the development and administration costs of operating in a heterogeneous environment without sacrificing performance, scalability or manageability. . . .. Sun Microsystems has previewed a new feature of the Solaris 10 operating system, code-named Project Janus. This new technology will allow users to run Linux binary applications unchanged on the Solaris OS, reducing the development and administration costs of operating in a heterogeneous environment without sacrificing performance, scalability or manageability. According to Dumisani Mtoba, senior systems engineer at Sun Microsystems SA, Project Janus will provide businesses that are using mixed Solaris OS and Linux environments with broader access to applications written for both operating systems. The link for this article located at CITIGATE PR is no longer available. . Sun Microsystems has previewed a new feature of the Solaris 10 operating system, code-named Project . microsystems, previewed, feature, solaris, operating, system, code-named, project. . LinuxSecurity.com Team
It is a rare organization that has the money to deploy best of breed or integrated commercial software for every security role. Whether your job is perimeter protection, incident response or email server administration, there may be an opportunity to use your favorite Unix system with some additional tools to get the job done faster and cheaper than what you do now. . . .. After the reception my last column regarding the security criticism I heaped on Unix and Linux vendors who are pursuing end-user desktops, I thought I would outline some of the areas where I think Linux and Unix already have strong wins. While I am a dedicated Unix and Linux junkie and use it everywhere I can, I may be somewhat biased. However, there are some areas where Unix and Linux systems fit in better than anything else out there. In some cases, these roles can be performed on commercial Unix systems if your organization feels better about paying for commercial-grade software. The upcoming version of Solaris, for example seems to have some new security tricks that are worth a look if you need to run secure enterprise services. CD based OS - security in an insecure world Working in the security industry makes a person slightly paranoid. In my case, my paranoia goes far enough that I don't trust my own mother, or at least I don't trust her computer. The link for this article located at securityfocus is no longer available. . Unix/Linux systems are versatile and economical, excelling in security with advanced features, fine-grained user management, and a wide range of customizable tools. Unix Security Roles, Linux Applications, Security Management. . Anthony Pell
In the past three months, the open-source community has been given a wake-up call. While Microsoft has concentrated on reviewing its flagship Windows source code as part of a new focus on security, Internet watchdogs have released the details of . . . . In the past three months, the open-source community has been given a wake-up call. While Microsoft has concentrated on reviewing its flagship Windows source code as part of a new focus on security, Internet watchdogs have released the details of three widespread flaws in open-source applications usually shipped with the Linux operating system. The flaws could compromise the security of computers on which the applications are installed, prompting some developers to urge the open-source community to take another look at popular code. But most fear the majority of members won't bother. No one is doing auditing," said Crispin Cowan, chief scientist at Linux maker WireX Communications, one of several companies selling a version of the OS with additional security options. Cowan is the founder of Sardonix, a Web site aimed at organizing groups of people who want to review major open-source software. The link for this article located at cnet is no longer available. . The collaborative software ecosystem grapples with vulnerabilities as significant defects lead to demands for scrutiny and fostering of confidence.. Open Source Trust, Security Auditing, Code Review, Community Engagement, Linux Applications. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.