Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Organisations today invest millions of dollars and thousands of man-hours in building out their IP based infrastructure. However, the question one is often left with is: "Is Denial of Service or Network Disruption something that my enterprise should be concerned with?" Help Net Security has an article that contains a brief self-test that should help you to consider the reality of the threat and how seriously it ought to be pursued. . The link for this article located at Net-Security.org - LogError is no longer available. . In today's digital environment, businesses are vulnerable to network disruptions and DoS attacks, which can cause severe financial losses and trust issues.. Network Disruption, Denial of Service, Threat Analysis, Risk Management. . Benjamin D. Thomas
A Spanish hacker who launched a denial of service attack that hobbled the net connections of an estimated three million users has been jailed for two years and fined €1.4m. Santiago Garrido, 26, (AKA Ronnie and Mike25) launched the attack using a computer worm in retaliation for been banned from the popular "Hispano" IRC chat room for breaking its rules. . The link for this article located at TheRegister.co.uk is no longer available. . The link for this article located at TheRegister.co.uk is no longer available.. spanish, hacker, launched, denial, service, attack, hobbled, connections. . LinuxSecurity.com Team
Even before the CanSecWest security conference started on Wednesday, unknown hackers had given the hotel's high-speed network a case of the hiccups. By Wednesday evening, the system was laid out flat. The pros were peeved, and a call for an electronic posse went out. . . .. Even before the CanSecWest security conference started on Wednesday, unknown hackers had given the hotel's high-speed network a case of the hiccups. By Wednesday evening, the system was laid out flat. The pros were peeved, and a call for an electronic posse went out. "We're forming a hunting party," Dragos Ruiu, independent security consultant and conference organizer, told the room of nearly 150 hackers and security experts late Thursday afternoon. "If anyone wants to help us find out who's...poisoning the hotel network, talk to me." But that evening, the vandal stayed offline and the hotel network was, for a little while, glitch free. Networks don't come much more hostile than those at the CanSecWest security conference. The three-day conference brought together hackers, security consultants, and government officials to talk tech about the latest tools and trends in the online arena. The link for this article located at news.com is no longer available. . Even before the CanSecWest security conference started on Wednesday, unknown hackers had given the h. cansecwest, security, conference, started, wednesday, unknown, hackers, given. . Anthony Pell
Most of the customers of Edinburgh business ISP edNET were left without Internet services yesterday after it experienced a serious distributed denial of service (DDoS) attack. edNET began to experience what it described in an email to users as a "catastrophic network failure" at around 8am yesterday.. . .. Most of the customers of Edinburgh business ISP edNET were left without Internet services yesterday after it experienced a serious distributed denial of service (DDoS) attack. edNET began to experience what it described in an email to users as a "catastrophic network failure" at around 8am yesterday. This resulted in most of edNET's users experiencing difficulties sending email or browsing the Internet throughout yesterday. Engineers confirmed that the problem was a result of a DDoS attack on its network, and were able to restore services after applying filters to its network nodes, and asking upstream service providers to do the same thing. . Most of the customers of Edinburgh business ISP edNET were left without Internet services yesterday . customers, edinburgh, business, ednet, without, internet, services, yesterday. . Anthony Pell
A self-propagating worm known as Ramen is currently exploiting well-known holes in unpatched Red Hat Linux 6.2 systems and in early versions of Red Hat 7.0. In addition to scanning for additional systems and propagating to vulnerable systems, the worm also . . . . A self-propagating worm known as Ramen is currently exploiting well-known holes in unpatched Red Hat Linux 6.2 systems and in early versions of Red Hat 7.0. In addition to scanning for additional systems and propagating to vulnerable systems, the worm also defaces Web servers it encounters by replacing the "index.html" file. It may also interfere with some networks supporting multicasting. Ramen is currently known to attack Red Hat systems running vulnerable versions of wu-ftp, rpc.statd, and LPRng. New exploits can be added to the existing worm to expand its capabilities. Description: Ramen combines several known exploits and tools using a set of scripts. The initial attack starts with a scan for port 21 (FTP) and the retrieval of any FTP banners for any FTP services it encounters. The script uses this information to determine if it has contacted a system that may be vulnerable to one of its packaged exploits. Currently, Ramen uses the date encountered in the FTP banner of the system being scanned. If a vulnerable system is detected, the worm starts a propagation script based on what vulnerability is likely to be present. The propagation scripts and exploits run in parallel with the scanning process. Using one of the exploitable services, Ramen executes a command on the target system that creates a working directory for itself, "/usr/src/.poop". Ramen then requests a copy of itself, ramen.tgz, from the attacking system using Linux web browser and the Web-like service it installs on compromised systems. When installed on the new system, Ramen attempts to set up very limited Web-like service on port 27374 to provide for further distribution of the Ramen package. The service uses port 27374 to provide a copy of the ramen.tgz package to anyconnection with any request on that port. Ramen searches the entire system, including any remotely mounted file systems, and replaces any file named "index.html" with a copy of its own page. This not only defaces any web site that it encounters, but also corrupts html based documentation files and possible working files in personal directories. E-mail messages are sent to two accounts,
Get the latest Linux and open source security news straight to your inbox.