During an IP scan of all possible IPv4 addresses, Rapid7, the security firm that is known for the Metasploit attack framework, has discovered 40 to 50 million network devices that can potentially be compromised remotely with a single data packet. . The company says that remote attackers can potentially inject code into these devices, and that this may, for example, enable them to gain unauthorised access to a user's local network. All kinds of network-enabled devices including routers, IP cameras, NAS devices, printers, TV sets and media servers are affected. The link for this article located at H Security is no longer available. . Countless connected gadgets display security flaws, enabling the potential for malicious code execution and unapproved entry threats.. UPnP Vulnerabilities, Remote Device Security, Network Device Threats. . LinuxSecurity.com Team
Nice article from a press release at Interop. What kind of virtualization security does Linux have, and how does it compare? What steps do people take to secure their virtual servers? Ultrasecure operating system maker Green Hills Software is quietly providing some major network equipment manufacturers with an extra layer of security for its devices. Green Hills, which last fall released a commercial version of its hardened Integrity-178B operating system used in military fighter planes, is now leveraging that technology for the network, as well. Company officials here revealed they have built a secure virtualization platform for networking equipment based on a combination of the company's secure OS virtualization and networking technologies. . "Connecting our secure operating system environment to networking equipment, which is not secure" didn't make sense, says Dan Mender, vice president of business development for Green Hills. So the company has built a secure, virtualized networking platform based on its hardened Integrity OS plus its own switching and routing software -- a combination that Green Hills say protects network devices from denial-of-service, buffer overflow, and other attacks. Susan Hares, director of networking solutions for Green Hills, says this secure virtualization approach for networking equipment is crucial to protecting switches, routers, firewalls, and other network devices from attack. "Network attacks are coming -- it has just been considered bad form to make a lot of noise about it," she says. "The domino effect of [an attack on a network device] can be quite serious." . 'Connecting our secure operating system environment to networking equipment, which is not secure' di. article, press, release, interop, virtualization, security, linux. . Anthony Pell
Cisco Systems on Friday warned that a denial of service (DoS) vulnerability exists for its products. The threat affects all Cisco products running the vendor's Internetwork Operating System (IOS). A DoS attack can be triggered if a hacker crafts a malicious TCP connection to a Telnet or reverse Telnet port of a Cisco device running IOS, according to a security advisory issued by Cisco, San Jose, Calif. . . .. Cisco Systems on Friday warned that a denial of service (DoS) vulnerability exists for its products. The threat affects all Cisco products running the vendor's Internetwork Operating System (IOS). A DoS attack can be triggered if a hacker crafts a malicious TCP connection to a Telnet or reverse Telnet port of a Cisco device running IOS, according to a security advisory issued by Cisco, San Jose, Calif. Telnet is a common way to control Web servers remotely. If the vulnerability is exploited, network-based management connections to IOS-based Cisco routers could be blocked. However, data traffic through the routers would continue to flow. The link for this article located at Dan Neel is no longer available. . Cisco Systems has raised alarms over a potential denial of service vulnerability impacting its offerings, especially affecting devices utilizing IOS.. Cisco Vulnerability, Denial Of Service, IOS Security Advisory. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.