Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
74

Assessing Network Disruption Risks And DoS Threats For Enterprises

Organisations today invest millions of dollars and thousands of man-hours in building out their IP based infrastructure. However, the question one is often left with is: "Is Denial of Service or Network Disruption something that my enterprise should be concerned with?" Help Net Security has an article that contains a brief self-test that should help you to consider the reality of the threat and how seriously it ought to be pursued. . The link for this article located at Net-Security.org - LogError is no longer available. . In today's digital environment, businesses are vulnerable to network disruptions and DoS attacks, which can cause severe financial losses and trust issues.. Network Disruption, Denial of Service, Threat Analysis, Risk Management. . Benjamin D. Thomas

Calendar%202 Apr 04, 2006 User Avatar Benjamin D. Thomas Network Security
83

Santiago Garrido: Two Years For Major DDoS Attack In Spain

A Spanish hacker who launched a denial of service attack that hobbled the net connections of an estimated three million users has been jailed for two years and fined €1.4m. Santiago Garrido, 26, (AKA Ronnie and Mike25) launched the attack using a computer worm in retaliation for been banned from the popular "Hispano" IRC chat room for breaking its rules. . The link for this article located at TheRegister.co.uk is no longer available. . The link for this article located at TheRegister.co.uk is no longer available.. spanish, hacker, launched, denial, service, attack, hobbled, connections. . LinuxSecurity.com Team

Calendar%202 Feb 08, 2006 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

CanSecWest 2023: Network Attack Leads To Cybersecurity Search Party

Even before the CanSecWest security conference started on Wednesday, unknown hackers had given the hotel's high-speed network a case of the hiccups. By Wednesday evening, the system was laid out flat. The pros were peeved, and a call for an electronic posse went out. . . .. Even before the CanSecWest security conference started on Wednesday, unknown hackers had given the hotel's high-speed network a case of the hiccups. By Wednesday evening, the system was laid out flat. The pros were peeved, and a call for an electronic posse went out. "We're forming a hunting party," Dragos Ruiu, independent security consultant and conference organizer, told the room of nearly 150 hackers and security experts late Thursday afternoon. "If anyone wants to help us find out who's...poisoning the hotel network, talk to me." But that evening, the vandal stayed offline and the hotel network was, for a little while, glitch free. Networks don't come much more hostile than those at the CanSecWest security conference. The three-day conference brought together hackers, security consultants, and government officials to talk tech about the latest tools and trends in the online arena. The link for this article located at news.com is no longer available. . Even before the CanSecWest security conference started on Wednesday, unknown hackers had given the h. cansecwest, security, conference, started, wednesday, unknown, hackers, given. . Anthony Pell

Calendar%202 May 07, 2002 User Avatar Anthony Pell Network Security
74

edNET Internet Outage: DDoS Attack Disrupts Services for Users

Most of the customers of Edinburgh business ISP edNET were left without Internet services yesterday after it experienced a serious distributed denial of service (DDoS) attack. edNET began to experience what it described in an email to users as a "catastrophic network failure" at around 8am yesterday.. . .. Most of the customers of Edinburgh business ISP edNET were left without Internet services yesterday after it experienced a serious distributed denial of service (DDoS) attack. edNET began to experience what it described in an email to users as a "catastrophic network failure" at around 8am yesterday. This resulted in most of edNET's users experiencing difficulties sending email or browsing the Internet throughout yesterday. Engineers confirmed that the problem was a result of a DDoS attack on its network, and were able to restore services after applying filters to its network nodes, and asking upstream service providers to do the same thing. . Most of the customers of Edinburgh business ISP edNET were left without Internet services yesterday . customers, edinburgh, business, ednet, without, internet, services, yesterday. . Anthony Pell

Calendar%202 Apr 10, 2002 User Avatar Anthony Pell Network Security
74

Red Hat 6.2 Security Advisory: Ramen Worm Moderate Threat Report

A self-propagating worm known as Ramen is currently exploiting well-known holes in unpatched Red Hat Linux 6.2 systems and in early versions of Red Hat 7.0. In addition to scanning for additional systems and propagating to vulnerable systems, the worm also . . . . A self-propagating worm known as Ramen is currently exploiting well-known holes in unpatched Red Hat Linux 6.2 systems and in early versions of Red Hat 7.0. In addition to scanning for additional systems and propagating to vulnerable systems, the worm also defaces Web servers it encounters by replacing the "index.html" file. It may also interfere with some networks supporting multicasting. Ramen is currently known to attack Red Hat systems running vulnerable versions of wu-ftp, rpc.statd, and LPRng. New exploits can be added to the existing worm to expand its capabilities. Description: Ramen combines several known exploits and tools using a set of scripts. The initial attack starts with a scan for port 21 (FTP) and the retrieval of any FTP banners for any FTP services it encounters. The script uses this information to determine if it has contacted a system that may be vulnerable to one of its packaged exploits. Currently, Ramen uses the date encountered in the FTP banner of the system being scanned. If a vulnerable system is detected, the worm starts a propagation script based on what vulnerability is likely to be present. The propagation scripts and exploits run in parallel with the scanning process. Using one of the exploitable services, Ramen executes a command on the target system that creates a working directory for itself, "/usr/src/.poop". Ramen then requests a copy of itself, ramen.tgz, from the attacking system using Linux web browser and the Web-like service it installs on compromised systems. When installed on the new system, Ramen attempts to set up very limited Web-like service on port 27374 to provide for further distribution of the Ramen package. The service uses port 27374 to provide a copy of the ramen.tgz package to anyconnection with any request on that port. Ramen searches the entire system, including any remotely mounted file systems, and replaces any file named "index.html" with a copy of its own page. This not only defaces any web site that it encounters, but also corrupts html based documentation files and possible working files in personal directories. E-mail messages are sent to two accounts, This email address is being protected from spambots. You need JavaScript enabled to view it. and This email address is being protected from spambots. You need JavaScript enabled to view it., from compromised systems. Owners of the systems where the two addresses were hosted have been notified. Ramen disables existing FTP services (in inetd on Red Hat 6.2 or in xinetd on Red Hat 7.0) and disables rpc.statd. This action may be to prevent any attempts to re-infect the systems with additional copies of the worm. Ramen continues to propagate by using the newly compromised system to scan Class B (/16) wide address spaces, searching for port 21 (FTP) and looking for new vulnerable hosts. On networks and ISPs supporting multicasting, the SYN scanning performed by Ramen can disrupt network traffic when scanning the multicast network range. Ramen is driven by scripts that can be easily modified to attack other versions of Linux or other Unix systems. The exploits included with Ramen are known to work against other versions of these systems, even though Ramen itself is not keyed to trigger on them. Affected Systems: Red Hat 6.2 for Intel not patched for wu-ftp or nfs. Red Hat 7.0 First Edition for Intel not patched for LPRng. Systems not known to be vulnerable: Red Hat 7.0 for Intel Second Edition (Respin). Previous versions of Red Hat Linux. Non-Intel versions of Linux. Non-Red Hat versions of Linux. Any other versions of Unix. Additional Information: Ramen does not attempt to hide its presence or clean up after itself. It can be detected on a system by the presence of the directory /usr/src/.poop or by the presence of the file /sbin/asp. To remove the Ramen Worm from your system, follow these steps: 1. Delete: /usr/src/.poop and /sbin/asp. 2. If itexists, remove: /etc/xinetd.d/asp 3. Remove all lines in /etc/rc.d/rc.sysinit which refer to any file in /etc/src/.poop. 4. Remove any lines in /etc/inetd.conf referring to /sbin/asp 5. Reboot the system or manually kill any processes such as synscan, start.sh, scan.sh, hackl.sh, or hackw.sh. 6. ISS recommends that ftp, rpc.statd, or lpr are not enabled until updates have been installed. Due to the general-purpose exploits at the core of this worm, it is advisable to implement the following safeguards to prevent successful attacks from potential variations of this exploit. Disable FTP if it is not a required service. FTP provides information that can be exploited to identify vulnerable systems, even when FTP is not vulnerable. Do not permit outside network access to RPC services, including NFS. Do not permit outside network access to LPR services. Install and maintain all security fixes in a timely manner. Support to detect both the rpc.statd and the wu-ftp vulnerabilities is available to ISS Internet Scanner customers in X-Press Update 4.4. ISS RealSecure support to detect both the rpc.statd vulnerability and the wu-ftp vulnerability is available in X-Press Update SR 1.1. ISS X-Force plans to make support available for the LPrng vulnerability for both Internet Scanner and RealSecure in an upcoming X-Press Update release. ISS RealSecure customers can configure a Connection Event on port 27374 to detect activity associated with the propagation of this worm and may use the following User Defined signature to detect outbound emails originating from machines infected with the Ramen Worm: - From the Sensor window: 1. Right-click on the sensor and select 'Properties'. 2. Choose a policy you want to use, and click 'Customize'. 3. Select the 'User Defined Events' tab. 4. Click 'Add' on the right hand side of the dialog box. 5. Create 2 User Defined Events, one for Hotmail the other Yahoo. 6. Type in a name of each event, such as 'Ramen Hotmail' and 'Ramen Yahoo'. 7. In the 'Context' field for eachevent, select 'Email_Receiver'. In the 'String' field, type the following for each event: This email address is being protected from spambots. You need JavaScript enabled to view it. This email address is being protected from spambots. You need JavaScript enabled to view it. 8. Click 'Save', and then 'Close'. 9. Click 'Apply to Sensor' or 'Apply to Engine', depending on the version of RealSecure you are using. Credits: The material contained in this advisory was researched by Michael Warfield of ISS X-Force. For additional information refer to the INCIDENTS and VULN-DEV mailing lists hosted at as well as mailing lists hosted on Red Hat.com. ____ About Internet Security Systems (ISS) Internet Security Systems, Inc. (ISS) (NASDAQ: ISSX) is the leading global provider of security management solutions for the Internet. By combining best of breed products, security management services, aggressive research and development, and comprehensive educational and consulting services, ISS is the trusted security advisor for thousands of organizations around the world looking to protect their mission critical information and networks. Copyright (c) 2001 by Internet Security Systems, Inc. Permission is hereby granted for the redistribution of this Alert electronically. It is not to be edited in any way without express consent of the X-Force. If you wish to reprint the whole or any part of this Alert in any other medium excluding electronic medium, please e-mail This email address is being protected from spambots. You need JavaScript enabled to view it. for permission. Disclaimer The information within this paper may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties with regard to this information. In no event shall the author be liable for any damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk. X-Force PGP Key available at: as well as on MIT's PGP key server and PGP.com's key server. Please send suggestions, updates, and comments to: X-Force This email address is being protected from spambots. You need JavaScript enabled to view it. of Internet Security Systems, Inc. . An autonomous malwarevariant targets vulnerable Debian servers, altering web pages and causing interruptions in online services. Discover the details.. Ramen Exploit, Red Hat 6.2 Worm, Network Defense, System Intrusion. . Anthony Pell

Calendar%202 Jan 18, 2001 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200