Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 4 articles for you...
77

Windows XP Important UPnP Remote Access Security Risk 2001-0011

The latest Microsoft bug is a doozy. Why do these things keep cropping up? The federal government and technology industry want you to believe the threats to our networks are external, not internal, where someone must be held accountable when things go wrong. Thus, we hear the rhetoric about cyberterrorists, hackers, and the so-called 'Digital Pearl Harbor' - things you can't easily point fingers at and hold someone accountable for when bad things happen.. . . . The latest Microsoft bug is a doozy. Why do these things keep cropping up? The federal government and technology industry want you to believe the threats to our networks are external, not internal, where someone must be held accountable when things go wrong. Thus, we hear the rhetoric about cyberterrorists, hackers, and the so-called 'Digital Pearl Harbor' - things you can't easily point fingers at and hold someone accountable for when bad things happen. Richard Forno 20 December 2001: Essay #2001-15 This email address is being protected from spambots. You need JavaScript enabled to view it. (c) 2001 by Author. Permission is granted to quote, reprint or redistribute provided the text is not altered, and appropriate credit is given. Summary: The latest Microsoft bug is a doozy. Why do these things keep cropping up? Reader feedback is here. This gives "Plug and Pray" a whole new meaning... Plug your XP box to the Internet and pray the hackers don't find it. (Slashdot) "The only secure Microsoft software is what's still shrink-wrapped in their warehouse..." (Forno) By now, people know that I'm not the world's greatest Microsoft fan. Truth be told, I'm not completely biased against the company, and will even acknowledge that it has - at various points - produced some decent products. I also don't 'bash' Microsoft because it's the 'in' thing to do these days, but because there are serious problems with the software company's products and services that they continue to ignore. In fact, some would argue, they just don't get it. Such observations, therefore, must be voiced. The federalgovernment and technology industry want you to believe the threats to our networks are external, not internal, where someone must be held accountable when things go wrong. Thus, we hear the rhetoric about cyberterrorists, hackers, and the so-called 'Digital Pearl Harbor' - things you can't easily point fingers at and hold someone accountable for when bad things happen. The White House would be wise to look at our nation's own self-induced vulnerabilities before rushing to spin up a sinister external threat; absent the rich target of opportunity presented by nearly all Microsoft products, hackers, crackers, and electronic evildoers would have a much harder time causing mainstream mischief every other week. Windows XP was promoted by Microsoft as perhaps the ultimate and most secured Windows operating system the firm had ever created, and one of its key features was increased security from electronic evildoers like hackers, crackers, and so-called cyberterrorists. In fact, in a recent interviewwith E-Week, Microsoft Vice President Jim Allchin said that Windows XP is "...dramatically more secure than Windows 2000 or any of the prior systems." Released on October 25, it was to be the default operating system on all new personal computers sold, and its release was timed to coincide with new PC sales for the 2001 holiday season. Unfortunately, Windows XP doesn't protect you from Microsoft , an entity some argue is more dangerous than any cyberterrorist or hacker gang. It turns out that the Windows XP ships with a new feature called Universal Plug and Play (UPnP) enabled (turned on) by default - thus allowing UPnP devices to locate each other on a local network, so that your home computer can talk to your refrigerator can talk to your toaster can talk to your stereo can send messages to your PDA, and so forth. However, as a result of this oversight, someone could remotely use this feature to exploit, control, or disrupt a system from remote locations around the world. As if computer exploits aren't badenough, you'll soon have to worry about someone turning off your freezer and spoiling your holiday leftovers.... Note this is not to be confused with the Windows Remote Assistance feature - promoted as one of the major benefits of using Windows XP, yet functioning in essentially the same way as the UPnP exploit. (One wonders how quickly the Remote Assistance feature will be exploited in the future as well.) Marc Maiffret, the talented, blue-haired 'Chief Hacking Officer' of Eeye Security, demonstrated the UPnP exploit to a shocked group of reporters yesterday. As a result, media and security experts are calling this "The Mother of All Exploits" for Windows XP, scrambling to inform the public about the importance of downloading and installing the fix for this problem - a security problem not caused by a hacker or cracker, but developed and implemented exclusively by Microsoft for your computing convenience and to enhance your user experience as a 'feature' of the product. According to an AP story by Ted Bridis, Microsoft Security Manager Scott Culp, called this latest vulnerability the "the first network-based, remote compromise that I'm aware of for Windows desktop systems" and a "very serious vulnerability." I guess it's all in how you define "compromise." How very Clintonian. Although repeatedly interviewed by the media reporting on Microsoft-based security events over the years, Culp apparently doesn't consider any of the following Microsoft-centric security exploits as "network-based, remote compromises" for "Windows desktop systems" either - the series of Back Orifice programs from the always-amusing Cult of the Dead Cow (CDC) to e-mail worms, trojans, and viruses (think BadTrans) that can transmit sensitive information from systems they infect. Did Culp miss a few days of class here and there and forget to read up on SECHOLE.EXE (July 1998), the assorted Internet Explorer cross-frame scripting exploits (September 1998) or the mid-2000 ability to remotely exploit a Windows desktop through abuffer overflow found in the Clip Art feature of Microsoft Office? And what about Windows File and Print Sharing vulnerabilities from back in 1995? How about the seemingly-endless number of buffer overflow exploits (think CodeRed, Lion, and Nimda) that plague Microsoft Internet Information Server (IIS) - granted, IIS isn't made for "Windows desktops" but it deserves mention given the nearly-identical software code in Microsoft's desktop and server products. So how exactly does Microsoft classify these other types of network-centric exploits? As nuisances but the price of doing business in the wired world? When will it end? And what to do about this latest security problem originating in Redmond? Microsoft, as the world's largest purveyor of PC software, with an established monopoly status, needs to do the responsible thing. Rather than continue to preach security as a marketing tool for its .NET venture, an avenue for business development with new proprietary 'standards' and fee-based, censored security 'partnerships' or review its reactive measures , it should get back to the basics and look within for the solution to its internal problems that usually evolve into the world's problems . Simply put, Microsoft needs to review its software code line-by-line and clean it up. Years of service packing, patching, re-patching, updating, critical updating, and hotfixing Windows products have made them dirty and prone to breaking, as we see every few months. Better yet, Microsoft needs to revisit the basic design of Windows - namely, removing the shared code between applications and the underlying Windows operating system (like the pervasiveness of the Web-enabled Internet Explorer across each Windows application and system.) Like a car, it's time to bring the Windows code into the shop for a major tune-up. Actually, a worldwide recall might in order. In addition, Microsoft must not ensure its products work well together, but also conduct much more aggressive 'abuse testing' of its software (e.g., XP)before it gets released to the Real World. Such testing should be done by independent third parties and conducted in a transparent, public manner to preclude any claims of bias in the results of such testing. In general, Microsoft should conduct what the rest of the computing community considers a real "beta test" - namely, making sure that a supposedly finished application works as intended, using experienced users to test the functionality, durability, and security of the product in a real-world, real-use, take-no-prisoners environment.....not use its much bally-hooed 'beta test' periods as the opportunity to market advance copies of their products, many of which never seem to get out of the beta stage even when they're officially released for sale! In none of the interviews regarding the UPnP situation has Culp admitted that Eeye did the responsible thing by informing Microsoft and waiting for the fix to be available from Microsoft before releasing information on this critical exploit to the internet community, something many folks in the security community (all outside of Microsoft) consider 'responsible disclosure.' According to reports, it took Microsoft nearly two months to release a patch after learning of the exploit. While Eeye's actions were praiseworthy, I wouldn't wait so long before mentioning such a critical security problem to the community. Realisticly, a vendor should be able to examine and verify a reported exploit - particularly one as critical as this one - and release a patch or publish corrective guidance to the public in about two weeks. In this case, Microsoft - had it decided it was in its interest to do so - could have easily assigned fourteen thousand programmer man-days (1000 programmers x 14 days) to address the problem within two weeks. Eeye was very generous in giving Microsoft so long to fix the problem, although why it took nearly two months for Microsoft to address the problem raises some disturbing questions. Perhaps acknowledging this would be contrary to the toneand contents of Culp's October 2001 missive calling for a Microsoft-based Vatican of Vulnerability to quell the public disclosure of security vulnerabilities and implement software security through obscurity and public ignorance. More interestingly, Eeye reported the UPnP exploit to Microsoft back in October (according to sources at EEye, the day after Windows XP was released.) Was Microsoft's two-month silence on this critical exploit a business decision to avoid public embarassment on a new product so close to the holiday (e.g., "new PC purchasing") season? We can only wonder. Microsoft is by far the most notorious in their vulnerability announcements, legaleese, and cover-their-tail security alerts, something CDC member Tweety Fish noted in a 1999 interview discussing the growing number of Microsoft-generated security problems back then. He noted that Microsoft "will not consider any given security risk a problem until it becomes a problem in the press." Or, to put it another way, it's not really a problem until Microsoft says so. Actions speak louder than words. Microsoft pays security plenty of lip service for marketing and public relations spin control, but the firm's history of addressing security problems falls quite short of what security professionals would consider a robust, long-term committment to effectively dealing with the matter. Thus, it's up to third parties like Eeye and other research firms to continue serving as a "check and balance" against a future of vendor-induced security-through-obscurity and public ignorance. Thanks to Eeye's responsible disclosure of this catastrophic vulnerability in Windows XP, not only is the Internet a bit safer, but their actions prove once again that voluntary disclosure of vulnerability information is possible without a fee-based vendor-sponsored club. Resources EEye Security Advisory and Technical Discussion - Easy to Understand (20 Dec 01) Microsoft's Fix to the UPnP Exploit Article: "Microsoft," No. "Mickeysoft", Yes. (28Nov 01) Article: The Freedom to Innovate Includes The Freedom to Obfuscate: Why Microsoft's New "Security Framework" is Just Another .NET Vulnerability (10 Nov 2001) Article: The Microsoft-English Dictionary 1.5 (What Microsoft Really Means To Say) (28 Nov 01) . Microsoft has warned about a critical vulnerability in the UPnP protocol in Windows XP, risking unauthorized access and user safety for outdated systems.. Windows XP Security, UPnP Security Risks, Eeye Security Exploit. . LinuxSecurity.com Team

Calendar%202 Apr 06, 2024 User Avatar LinuxSecurity.com Team Server Security
72

Fortinet: May 2023 Security Advisory Critical: 0-Day Malware Exploit

A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks targeting a European government entity and a managed service provider (MSP) located in Africa. . Telemetry evidence gathered by Google-owned Mandiant indicates that the exploitation occurred as early as October 2022, at least nearly two months before fixes were released. "This incident continues China's pattern of exploiting internet facing devices, specifically those used for managed security purposes (e.g., firewalls, IPS\IDS appliances etc.)," Mandiant researchers said in a technical report. The attacks entailed the use of a sophisticated backdoor dubbed BOLDMOVE , a Linux variant of which is specifically designed to run on Fortinet's FortiGate firewalls. The link for this article located at The Hacker News is no longer available. . State-sponsored cybercriminals from China took advantage of a flaw in Fortinet security software to install malicious code and create backdoors in compromised networks.. Fortinet Vulnerability, Zero-Day Threat, Network Exploit, Malware Attack, Backdoor Threat. . Brittany Day

Calendar%202 Jan 23, 2023 User Avatar Brittany Day Firewalls
67

Fedora: CVE-2014-3466 Critical: SSLv3 POODLE Threat Explained

Another security vulnerability is hitting the tech (and mainstream!) press, and we want to make Fedora users get straight, simple information. This one is CVE-2014-3466, and the cute nickname of the day is . Here The link for this article located at Fedora Magazine is no longer available. . Uncover insights into the SSLv3 POODLE vulnerability impacting Fedora users and the associated dangers.. SSLv3 Poodle Flaw, Fedora Security, Network Exploit Risk. . LinuxSecurity.com Team

Calendar%202 Oct 15, 2014 User Avatar LinuxSecurity.com Team Cryptography
83

Vodafone Hack: Femto Cell Exploit for Unauthorized Call Access

THC claims it can listen to any call, use other accounts to make calls and access the victim's voice mail. Hackers have claimed that they have successfully re-engineered a standard consumer hardware available from Vodafone store to intercept calls and gain administrator access into other user accounts. . The Hacker's Choice (THC) said in a blogpost https://thcorg.blogspot.com/2011/07/vodafone-hacked-root-password-published.html that their engineers managed to reverse engineer Femto Cell into a full blown 3G/UMTC/WCDMA interception device. A Femto Cell is a tiny home router which boosts the 3G Phone signal. It is available from the Vodafone Store to any customer for 160 GBP, said THC THC said that engineers exploited a design flaw and got full control of the Vodafone UK network. The link for this article located at CBR Online is no longer available. . The Hacker's Choice (THC) said in a blogpost https://thcorg.blogspot.com/2011/07/vodafone-hacked-roo. claims, listen, other, accounts, calls, victim's, voice. . LinuxSecurity.com Team

Calendar%202 Jul 14, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Red Hat: Kernel Patch Critical for Network Exploit Mitigation

Red Hat has finally managed to release a patch for the previously reported critical Linux kernel vulnerability. Red Hat's initial response was to provide a workaround for the problem that involved blacklisting certain network protocols, preventing the exploit from functioning. Novell has also released updates for openSUSE 10.3 to 11.1, SUSE Linux Enterprise Desktop and SUSE Linux Enterprise Server. . The link for this article located at H Security is no longer available. . Essential notifications from Red Hat and Novell focus on a major vulnerability in the Linux kernel and its associated network security threat.. Kernel Patch, Red Hat Update, SUSE Fix. . LinuxSecurity.com Team

Calendar%202 Aug 25, 2009 User Avatar LinuxSecurity.com Team Vendors/Products
74

Exploring Ethical Concerns Around Michael Lynn's Cisco Exploit Debate

One can only imagine what raced through Michael Lynn's mind the penultimate moment before he saved or sacrificed our nation's critical infrastructure, depending on your take of the researcher's Black Hat Briefings presentation this week. . Lynn's the guy who quit his job at Atlanta-based Internet Security Systems Inc. and defied legal threats from Cisco Systems Inc. to divulge (without much detail) how he reverse-engineered Cisco's Internetwork Operating System [IOS] software to exploit a known flaw in the networking giant's routers. He and Black Hat conference founder Jeff Moss are now off the legal hook, with the two men and two companies having reached an accord late Thursday. But what happened, and why, continues to confound the security community. Initially, ISS consented for Lynn, then with its X-Force research team, to discuss his findings at the annual Las Vegas conference, especially given a patch to prevent the attack had been out for three months. ISS apparently had been working with Cisco on this problem for at least that long. Then Cisco got involved, belatedly, and deployed staff to cut Lynn's PowerPoint pages from 2,300 conference handbooks. Wednesday it issued a restraining order against Black Hat organizers and Lynn. On Thursday, Cisco distributed abridged CDs of proceedings to 2,500 conventioneers. "Considering how important Cisco routers are to the Internet, I can somewhat understand their concerns," Steve Fletcher, a security specialist for a security consulting firm in central Illinois, said in an e-mail exchange. "However, I believe they went to extremes, considering that a patch is supposedly available." The link for this article located at SearchSecurity is no longer available. . The recent verdict by Michael Lynn regarding the vulnerability in Cisco's routing system ignites a debate on moral standards and safety protocols within the technology sector.. Michael Lynn,Cisco Router,Security Ethics,Network Exploit,Black Hat. . Brittany Day

Calendar%202 Jul 29, 2005 User Avatar Brittany Day Network Security
79

Arkeia Backup Agent Remote Access: Buffer Overflow Exploit Analysis

On February 18th, 2005 "John Doe" posted a remote buffer overflow exploit for the Arkeia Network Backup Client. This vulnerability affected all known versions of the software, going back as far as the 4.2 series (when the company was called Knox). The buffer overflow occurs when a large data section is sent with a packet marked as type 77. The Arkeia Network Backup Client is your typical backup agent; it runs with the highest privileges available (root or LocalSystem) and waits for a connection from the backup server. The Arkeia client and server both use TCP port 617 for communication. According to the SANS ISC, the kids are wasting no time. . A few hours after the exploit was posted, I started to investigate the flaw and port the code to the Metasploit Framework. On the Windows platform, it was possible switch from a plain return address smash to a SEH frame overwrite. This provides room for about 1000 bytes of payload and avoids the heap tricks used in the original exploit. When overwriting the SEH frame, a pop/pop/ret opcode is used to redirect execution to [esp+8], which happens to always point 4 bytes before the smashed SEH function pointer. Since Windows 2003 and Windows XP SP2 block SEH returns to system libraries, the best return address to use is one found inside the executable itself The link for this article located at MetaSploit is no longer available. . The Arkeia Network Backup Agent is under scrutiny due to a buffer overflow vulnerability, allowing malicious actors to execute arbitrary code on systems affected. Arkeia Network, Buffer Overflow, Remote Access Exploit, Backup Software. . LinuxSecurity.com Team

Calendar%202 Feb 21, 2005 User Avatar LinuxSecurity.com Team Security Projects
83

WorldCom Network Security Flaws Exposed By Hacker Adrian Lamo

A 20-year-old computer hacker who last weekend alerted telecommunications giant WorldCom Inc. about security holes he uncovered inside the company's network (see story) said he enters corporate Web sites without permission to satisfy his curiosity. Adrian Lamo, who has a publicized . . . . A 20-year-old computer hacker who last weekend alerted telecommunications giant WorldCom Inc. about security holes he uncovered inside the company's network (see story) said he enters corporate Web sites without permission to satisfy his curiosity. Adrian Lamo, who has a publicized history of exploring the inner workings of corporate computer networks in search of system weaknesses, said in an interview with Computerworld that he sees himself as helping companies improve their system security by reporting flaws. "I try to engage in harm reduction when I'm inside a computer network," said Lamo. "I've never intentionally done damage in a network." The link for this article located at ComputerWorld is no longer available. . A 21-year-old coder unveiled critical weaknesses in Microsoft’s system, highlighting the necessity of responsible disclosure practices.. WorldCom Security,Hacker Lamo,Exploit Discovery,Network Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Dec 10, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200