Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Text messages containing VPN passwords and authentication codes for Google and Facebook are found on a command-and-control server for Android malware. Research on Android malware called KorBanker has uncovered a treasure trove of text messages that include authentication codes for Google and Facebook and VPN passwords. How the thieves made use of the data is not known. However, FireEye researcher Hitesh Dharmdasani assumes cybercriminals have figured out a way to exploit it for financial gain. The link for this article located at CSO Online is no longer available. . The malicious software known as KorBanker for Android compromises personal data by revealing confidential messages that involve authentication tokens for services like Google and Facebook.. KorBanker Malware, Android Malware Attack, Data Exposure. . LinuxSecurity.com Team
Security researchers Tuesday said reports of the arrest of the hacker behind Blackhole, one of the most widely used exploit kits on the Internet, is good news for IT operations and users. But it shouldn't be long before another hacker takes his place.. "[It's] is a big deal," said Mikko Hypponen, chief research officer at security firm F-Secure. "According to our statistics, Paunch has been the biggest provider of exploit packs for the past two years." The link for this article located at Network World is no longer available. . '[It's] is a big deal,' said Mikko Hypponen, chief research officer at security firm F-Secure. 'Acco. security, researchers, tuesday, reports, arrest, hacker, behind, blackhole. . LinuxSecurity.com Team
Security analysts have been predicting that kernel rootkits, which cloak their activity by replacing a portion of a program's software kernel with modified code, are expected to continue to grow in frequency in 2007. While rootkit-fighting technologies such as the PatchGuard kernel protection system built into 64-bit versions of Microsoft's new Windows Vista operating system are arriving, most PC users will still be left open to the attacks over the next twelve months, CA has said, and even experienced PC users are vulnerable to their sophisticated techniques. . F-Secure Security Labs has been tracking and dissecting kernel malware for years; this form of attack was first spotted as far back as 1999, in the form of the WinNT/Infis attack. F-Secure researcher Kimmo Kasslin has made the findings available in a paper titled "Kernel Malware: The Attack from Within" (a PDF) as well as in a slide show (also a PDF). The link for this article located at eweek is no longer available. . F-Secure Security Labs has been tracking and dissecting kernel malware for years; this form of attac. security, analysts, predicting, kernel, rootkits, which, cloak, their, activity, replacing. . LinuxSecurity.com Team
The National Science Foundation announced Tuesday that it has granted more than $12 million to academic researchers for the creation of two centers to investigate infectious code and study the Internet's ecology. . . .. The funds set aside for the centers are part of the NSF's Cyber Trust program, through which the foundation has granted a total of $30 million to 33 projects focused on researching ways to provide better information security. The Center for Internet Epidemiology and Defenses, or the CIED, will work to understand how digital diseases such as worms and viruses spread across the Internet, and how epidemics can be defeated. The Security Through Interaction Modeling, STIM, Center will draw parallels with nature's ecology to understand the complex interaction between machines, humans and cyberattacks. "These centers, as well as our other funded activities, are looking not only for new ways to cope with imperfections in today's systems but also for the knowledge and techniques to build better systems in the future," Carl Landwehr, the NSF's program director for Cyber Trust, said in a statement. The link for this article located at Robert Lemos CNET News.com is no longer available. . The funds set aside for the centers are part of the NSF's Cyber Trust program, through which the fou. national, science, foundation, announced, tuesday, granted, million, acade. . Anthony Pell
Fueled by the old myth that "you can't get a virus in Unix" and by the increasing popularity of Linux and FreeBSD, Unix viruses passed an important milestone in 2001 and continued by receiving even more attention during 2002. . .. Fueled by the old myth that "you can't get a virus in Unix" and by the increasing popularity of Linux and FreeBSD, Unix viruses passed an important milestone in 2001 and continued by receiving even more attention during 2002 . It all begun with the Ramen worm, then continued with Adore, Lion, Cheese, RST.B and many, many more. Some of them even became widespread, culminating with the inclusion of OSF.8759 in the May 2002 Wildlist Unfortunately, while there are lots of charts and distribution statistics available for Win32 viruses, the same cannot be said about Unix viruses. Actually, at the time of writing, there is no reliable (and constantly updated) source of information regarding the distribution of Linux/FreeBSD malware, not to mention other Unix flavors which are less appealing to virus writers. The link for this article located at SecurityFocus is no longer available. . The belief in Unix’s strong immunity fostered a false security among users, encouraging worm exploits that highlighted vulnerabilities and spurred security dialogues in Linux.. Unix Worms, Linux Malware, Virus Myths, Security Threats, Worm Tracking. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.