Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Lots of people “run Linux” without really knowing or caring – many home routers, navigational aids, webcams and other IoT devices are based on it; the majority of the world’s mobile phones run a Linux-derived variant called Android; and many, if not most, of the ready-to-go cloud services out there rely on Linux to host your content. . But plenty of users and sysadmins don’t just “use Linux”, they’re responsible for hundreds, thousands, perhaps even millions of other people’s desktops, laptops and servers on which Linux is running. Those sysadmins are usually responsible not merely for ensuring that the systems under their jurisdiction are running reliably, but also for keeping them as safe and secure as they can. The article located at Naked Security is no longer available. . Tackling significant issues, this patch resolves a disk encryption flaw essential for strong security on Linux systems.. Encryption Fixes, Critical Updates, Linux Data Protection. . LinuxSecurity.com Team
The Financial Times reported last night that Google was going to phase out internal use of Microsoft Windows due to security concerns. The migration away from Windows is reported to have started in January, motivated by the Chinese Aurora attacks on the company that exploited a flaw in Internet Explorer 6. . In the story, the FT said that new Google employees would be given the choice between systems using Mac OS X and Linux. Windows machines will only be available with CIO approval. This would put an end to the existing policy, whereby employees were generally free to pick the platform that they preferred. Google has refused to comment. This seems surprisingly extreme, given that there are practical reasons for Google employees to use Windows. The company produces Windows software, such as the Chrome Web browser and Google Desktop Search. The company also has a great many Web properties, all of which need testing on Windows. As such, Windows is sure to remain a part of the Google ecosystem, at least for anyone involved in end-user facing applications. It's just too important to ignore. In the aftermath of the Google hack, even Microsoft said that people should stop using Internet Explorer 6, as it lacks the defence-in-depth measures found in Internet Explorer 8 when used on Windows Vista and Windows 7. The article located at arsTechnica is no longer available. . Organizations transition away from Microsoft Windows, opting for Linux and Mac OS X as safer options due to rising security issues.. Google Migration, Mac OS X Security, Linux Alternatives, Employee Platform Choice. . LinuxSecurity.com Team
The dangerous Lion worm is stalking Linux systems. Worse than the Ramen worm, Lion installs then hides hacker tools on vulnerable systems Linux system administrators have a new worm to worry about. The SANS Institute is reporting the . . . . The dangerous Lion worm is stalking Linux systems. Worse than the Ramen worm, Lion installs then hides hacker tools on vulnerable systems Linux system administrators have a new worm to worry about. The SANS Institute is reporting the presence of the Lion worm, which is much more dangerous than the Ramen worm earlier this year. What makes Lion more dangerous is that it can steal passwords, install and hide hacker tools, gain root access of an infected system then attack other vulnerable systems. It is unclear whether Lion will surpass Ramen in total number of systems infected. It may infect Unix systems as well as Linux systems. The link for this article located at ZDNet UK is no longer available. . The dangerous Lion worm is stalking Linux systems. Worse than the Ramen worm, Lion installs then hid. dangerous, stalking, linux, systems, worse, ramen, installs. . Anthony Pell
The system had the same account and password as last year. There was a trivial vulnerable program in the home directory, resulting in a root shell. The kernel had been modified to include a form of access control called DTE which . . . . The system had the same account and password as last year. There was a trivial vulnerable program in the home directory, resulting in a root shell. The kernel had been modified to include a form of access control called DTE which is essentially a double labelling system. That root shell would not allow the flag to be planted but gave access to this year's "frustration machine" puzzle: an AF_UNIX socket to sshd, which was running in another compartment which allowed the flag to be planted. Gory details and pictures at . Palante's server now voted best server for three years in CTF. Palante is on the program to speak at toorcon . . An exploit discovered last year's configuration has paved the way for this year's CTF events on Palante's DEFCON 8 platform.. CTF Challenge, Root Shell, Security Issue, Linux System, Exploit. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.