Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 3 articles for you...
79

Metasploit Community Edition: New User-Friendly Pen Testing Tool

Two years after Rapid7 acquired the Metasploit Project, the company has rolled out a free and more user-friendly version of the open-source tool that is aimed at less technical users. . The new Metasploit Community Edition is a combination of the popular open-source Metasploit Framework and a basic version of the user interface of Rapid7's Metasploit Pro commercial product. HD Moore, Rapid7's CSO and chief architect for Metasploit, says the free pen-testing tool features a new user interface and automation of tasks to make penetration testing more approachable for organizations and users not necessarily versed in penetration testing. There's a growing number of organizations that want to get started with pen testing, either for compliance reasons or just to test it out, he says. The link for this article located at Dark Reading is no longer available. . Discover the intuitive Metasploit Community Edition designed for straightforward penetration testing. This platform makes security assessments accessible for beginners and experts alike.. Metasploit Community Edition, Pen Testing, Open Source Tool. . LinuxSecurity.com Team

Calendar%202 Oct 24, 2011 User Avatar LinuxSecurity.com Team Security Projects
78

The Transformation of Metasploit After the Rapid7 Acquisition Journey

When Rapid7 bought the Metasploit Project exactly one year ago this week, there were rumblings of concern that the open-source penetration testing tool would lose its identity and go all commercial. . Metasploit indeed has gone commercial -- there are new commercial versions of the tool available now from Rapid7 in addition to the open-source framework -- but most penetration testers say the tool has maintained its open-source roots and is evolving much more rapidly with the added development resources. Rapid7 rocked the penetration testing marketplace with its announcement it had purchased the Metasploit Project and hired its creator, HD Moore, as chief security officer of the company. Moore and Rapid7 executives were adamant about avoiding a failed open source-commercial marriage such as that of the Nessus scanning tool, which went from an open-source to a proprietary, closed-source license under Tenable Network Security. Their goal was to instead both improve and preserve the open-source framework, while making a commercial version of Metasploit as well. The link for this article located at Dark Reading is no longer available. . Metasploit indeed has gone commercial -- there are new commercial versions of the tool available now. rapid7, bought, metasploit, project, exactly, there, rumblings. . LinuxSecurity.com Team

Calendar%202 Oct 20, 2010 User Avatar LinuxSecurity.com Team Vendors/Products
74

Explore Metasploit's New Java Interface for Improved Usability

If you don't like command mode to interact with metasploit, I have good news for you: there is a new Java GUI. Don't forget to install Java to execute it. . The link for this article located at SANS / Metasploit is no longer available. . Unveil insights into the innovative Java graphical user interface for Metasploit, which elevates user engagement by transcending traditional command-line operations.. Java GUI, Metasploit Interface, Open Source Tools. . Anthony Pell

Calendar%202 Jul 20, 2010 User Avatar Anthony Pell Network Security
79

New Features In Metasploit Framework 3.4.1: Enhanced Meterpreter Tools

The Metasploit Project is proud to announce the release of the Metasploit Framework version 3.4.1. This release sees the first official non-Windows Meterpreter payload, in PHP as discussed last month here.. Rest assured that more is in store for Meterpreter on other platforms. A new extension called Railgun is now integrated into Meterpreter courtesy of Patrick HVE, giving you scriptable access to Windows APIs and an unprecedented amount of control over post-exploitation. For those of you wishing to contribute to the framework, a new file called HACKING has been introduced that lays out a few guidelines to make it easier. The link for this article located at Darknet UK is no longer available. . Investigate the advancements in Metasploit Framework 3.4.1, showcasing upgraded utilities and functionalities designed to facilitate more effective exploitation techniques.. Metasploit Framework, Meterpreter, Exploitation Tools, Open Source Security. . LinuxSecurity.com Team

Calendar%202 Jul 16, 2010 User Avatar LinuxSecurity.com Team Security Projects
74

Exploring New Features in Metasploit Express for Improved Testing

A new version of the open source Metasploit Framework penetration testing tool is set to debut next month with the release of Metasploit Express -- ushering in new enhancements for ease-of-use and management that come courtesy of its new commercial underpinnings.. The Metasploit Framework is an open source vulnerability testing framework and is currently at version 3.3. Rapid7, the lead vendor supporting Metasploit, is now aiming to make Metasploit easier to use and manage -- and that's where Metasploit Express, set for release in May, fits in. Unlike the Metasploit Framework, Metasploit Express is not open source, but rather delivers an open core approach whereby proprietary components are included alongside the core open source framework. "Metasploit is great, and tens of thousands of security professionals use it and the modules within it for a variety of security tasks," HD Moore, Rapid7's chief security officer and Metasploit's chief architect, told InternetNews.com. "We want to make it easier and accessible for people by offering some additional capabilities on top of it, such as automation." The link for this article located at Datamation is no longer available. . The latest version of Metasploit Express simplifies penetration testing, merging the advantages of open source and commercial tools.. Metasploit Framework, Penetration Testing, Security Enhancements. . Anthony Pell

Calendar%202 Apr 23, 2010 User Avatar Anthony Pell Network Security
74

Metasploit 3.3.3 Release: New Features for Security Testing

Metasploit provides useful information to people who perform penetration testing, IDS signature development, and exploit research. This project was created to provide information on exploit techniques and to create a useful resource for exploit developers and security professionals. The tools and information on this site are provided for legal security research and testing purposes only. Metasploit is an open source project managed by Rapid7. . Version 3.3.3 of the Metasploit Framework has been released, featuring exploit safety rankings, a smaller EXE template, the addition of the InitialAutoRunScript option for Meterpreter, and the ability to run a script or command on all open sessions (sessions -c/-s). The complete release notes are online and version 3.3.3 can obtained from the downloads page. . Metasploit Framework 4.1.0 launched, featuring enhanced risk assessments, optimized EXE architecture, and advanced Meterpreter capabilities.. Metasploit Framework, Penetration Testing Tools, Exploit Safety. . Anthony Pell

Calendar%202 Dec 23, 2009 User Avatar Anthony Pell Network Security
74

Enhance Penetration Testing with Metasploit Decloaking Engine

This tool demonstrates a system for identifying the real IP address of a web user, regardless of proxy settings, using a combination of client-side technologies and custom services. No vulnerabilities are exploited by this tool. A properly configured Tor setup should not result in any identifying information being exposed. Have you used Metasploit for your penetration testing? This article looks at the Decloaking Engine. If you want to learn more about this extension to Metasploit read on.... The link for this article located at Metasploit is no longer available. . The link for this article located at Metasploit is no longer available.. demonstrates, system, identifying, address, regardless. . Bill Locke

Calendar%202 Dec 17, 2008 User Avatar Bill Locke Network Security
79

Essential Resources For Mastering Metasploit Exploit Framework

It seems these days you can't get into a discussion about security tools without having Metasploit, the open-source exploit framework, being mentioned. This day is no different. Due to a recent surge of research and development by the creators of Metasploit, the author of this article decided it would be a good idea to have a compilation post of resources including history, docs, and videos of the framework in action. Read on to find out what all the fuss is aboot. Oh yea, did I mention it was written in Ruby? . The link for this article located at Darknet.org is no longer available. . Dive into comprehensive materials that will empower you to command the Metasploit framework and elevate your cybersecurity expertise.. Metasploit Framework, Exploit Development, Open Source Security. . LinuxSecurity.com Team

Calendar%202 Jul 20, 2007 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200