Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 3 articles for you...
72

Fortinet: May 2023 Security Advisory Critical: 0-Day Malware Exploit

A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks targeting a European government entity and a managed service provider (MSP) located in Africa. . Telemetry evidence gathered by Google-owned Mandiant indicates that the exploitation occurred as early as October 2022, at least nearly two months before fixes were released. "This incident continues China's pattern of exploiting internet facing devices, specifically those used for managed security purposes (e.g., firewalls, IPS\IDS appliances etc.)," Mandiant researchers said in a technical report. The attacks entailed the use of a sophisticated backdoor dubbed BOLDMOVE , a Linux variant of which is specifically designed to run on Fortinet's FortiGate firewalls. The link for this article located at The Hacker News is no longer available. . State-sponsored cybercriminals from China took advantage of a flaw in Fortinet security software to install malicious code and create backdoors in compromised networks.. Fortinet Vulnerability, Zero-Day Threat, Network Exploit, Malware Attack, Backdoor Threat. . Brittany Day

Calendar 2 Jan 23, 2023 User Avatar Brittany Day Firewalls
67

Fedora: CVE-2014-3466 Critical: SSLv3 POODLE Threat Explained

Another security vulnerability is hitting the tech (and mainstream!) press, and we want to make Fedora users get straight, simple information. This one is CVE-2014-3466, and the cute nickname of the day is . Here The link for this article located at Fedora Magazine is no longer available. . Uncover insights into the SSLv3 POODLE vulnerability impacting Fedora users and the associated dangers.. SSLv3 Poodle Flaw, Fedora Security, Network Exploit Risk. . LinuxSecurity.com Team

Calendar 2 Oct 15, 2014 User Avatar LinuxSecurity.com Team Cryptography
83

Vodafone Hack: Femto Cell Exploit for Unauthorized Call Access

THC claims it can listen to any call, use other accounts to make calls and access the victim's voice mail. Hackers have claimed that they have successfully re-engineered a standard consumer hardware available from Vodafone store to intercept calls and gain administrator access into other user accounts. . The Hacker's Choice (THC) said in a blogpost https://thcorg.blogspot.com/2011/07/vodafone-hacked-root-password-published.html that their engineers managed to reverse engineer Femto Cell into a full blown 3G/UMTC/WCDMA interception device. A Femto Cell is a tiny home router which boosts the 3G Phone signal. It is available from the Vodafone Store to any customer for 160 GBP, said THC THC said that engineers exploited a design flaw and got full control of the Vodafone UK network. The link for this article located at CBR Online is no longer available. . Cyber intruders penetrated Vodafone's system vulnerabilities, facilitating phone call monitoring and illegal entry into customer profiles.. Vodafone Network, Call Interception, Hacker Exploit, Femto Cell, Network Security. . LinuxSecurity.com Team

Calendar 2 Jul 14, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Red Hat: Kernel Patch Critical for Network Exploit Mitigation

Red Hat has finally managed to release a patch for the previously reported critical Linux kernel vulnerability. Red Hat's initial response was to provide a workaround for the problem that involved blacklisting certain network protocols, preventing the exploit from functioning. Novell has also released updates for openSUSE 10.3 to 11.1, SUSE Linux Enterprise Desktop and SUSE Linux Enterprise Server. . The link for this article located at H Security is no longer available. . Essential notifications from Red Hat and Novell focus on a major vulnerability in the Linux kernel and its associated network security threat.. Kernel Patch, Red Hat Update, SUSE Fix. . LinuxSecurity.com Team

Calendar 2 Aug 25, 2009 User Avatar LinuxSecurity.com Team Vendors/Products
74

Exploring Ethical Concerns Around Michael Lynn's Cisco Exploit Debate

One can only imagine what raced through Michael Lynn's mind the penultimate moment before he saved or sacrificed our nation's critical infrastructure, depending on your take of the researcher's Black Hat Briefings presentation this week. . Lynn's the guy who quit his job at Atlanta-based Internet Security Systems Inc. and defied legal threats from Cisco Systems Inc. to divulge (without much detail) how he reverse-engineered Cisco's Internetwork Operating System [IOS] software to exploit a known flaw in the networking giant's routers. He and Black Hat conference founder Jeff Moss are now off the legal hook, with the two men and two companies having reached an accord late Thursday. But what happened, and why, continues to confound the security community. Initially, ISS consented for Lynn, then with its X-Force research team, to discuss his findings at the annual Las Vegas conference, especially given a patch to prevent the attack had been out for three months. ISS apparently had been working with Cisco on this problem for at least that long. Then Cisco got involved, belatedly, and deployed staff to cut Lynn's PowerPoint pages from 2,300 conference handbooks. Wednesday it issued a restraining order against Black Hat organizers and Lynn. On Thursday, Cisco distributed abridged CDs of proceedings to 2,500 conventioneers. "Considering how important Cisco routers are to the Internet, I can somewhat understand their concerns," Steve Fletcher, a security specialist for a security consulting firm in central Illinois, said in an e-mail exchange. "However, I believe they went to extremes, considering that a patch is supposedly available." The link for this article located at SearchSecurity is no longer available. . The recent verdict by Michael Lynn regarding the vulnerability in Cisco's routing system ignites a debate on moral standards and safety protocols within the technology sector.. Michael Lynn,Cisco Router,Security Ethics,Network Exploit,Black Hat. . Brittany Day

Calendar 2 Jul 29, 2005 User Avatar Brittany Day Network Security
79

Arkeia Backup Agent Remote Access: Buffer Overflow Exploit Analysis

On February 18th, 2005 "John Doe" posted a remote buffer overflow exploit for the Arkeia Network Backup Client. This vulnerability affected all known versions of the software, going back as far as the 4.2 series (when the company was called Knox). The buffer overflow occurs when a large data section is sent with a packet marked as type 77. The Arkeia Network Backup Client is your typical backup agent; it runs with the highest privileges available (root or LocalSystem) and waits for a connection from the backup server. The Arkeia client and server both use TCP port 617 for communication. According to the SANS ISC, the kids are wasting no time. . A few hours after the exploit was posted, I started to investigate the flaw and port the code to the Metasploit Framework. On the Windows platform, it was possible switch from a plain return address smash to a SEH frame overwrite. This provides room for about 1000 bytes of payload and avoids the heap tricks used in the original exploit. When overwriting the SEH frame, a pop/pop/ret opcode is used to redirect execution to [esp+8], which happens to always point 4 bytes before the smashed SEH function pointer. Since Windows 2003 and Windows XP SP2 block SEH returns to system libraries, the best return address to use is one found inside the executable itself The link for this article located at MetaSploit is no longer available. . The Arkeia Network Backup Agent is under scrutiny due to a buffer overflow vulnerability, allowing malicious actors to execute arbitrary code on systems affected. Arkeia Network, Buffer Overflow, Remote Access Exploit, Backup Software. . LinuxSecurity.com Team

Calendar 2 Feb 21, 2005 User Avatar LinuxSecurity.com Team Security Projects
83

WorldCom Network Security Flaws Exposed By Hacker Adrian Lamo

A 20-year-old computer hacker who last weekend alerted telecommunications giant WorldCom Inc. about security holes he uncovered inside the company's network (see story) said he enters corporate Web sites without permission to satisfy his curiosity. Adrian Lamo, who has a publicized . . . . A 20-year-old computer hacker who last weekend alerted telecommunications giant WorldCom Inc. about security holes he uncovered inside the company's network (see story) said he enters corporate Web sites without permission to satisfy his curiosity. Adrian Lamo, who has a publicized history of exploring the inner workings of corporate computer networks in search of system weaknesses, said in an interview with Computerworld that he sees himself as helping companies improve their system security by reporting flaws. "I try to engage in harm reduction when I'm inside a computer network," said Lamo. "I've never intentionally done damage in a network." The link for this article located at ComputerWorld is no longer available. . A 21-year-old coder unveiled critical weaknesses in Microsoft’s system, highlighting the necessity of responsible disclosure practices.. WorldCom Security,Hacker Lamo,Exploit Discovery,Network Vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Dec 10, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Windows XP Raw Socket Threat: Security Risks Analyzed by Steve Gibson

Security specialist Steve Gibson has created quite a fracas with his increasingly vocal opposition to the raw-socket connectivity planned for Windows-XP, and upon which he bases predictions of impending chaos for the entire Internet, so he's decided to exploit the very threat he claims will make the Internet permanently unstable.. . .. Security specialist Steve Gibson has created quite a fracas with his increasingly vocal opposition to the raw-socket connectivity planned for Windows-XP, and upon which he bases predictions of impending chaos for the entire Internet, so he's decided to exploit the very threat he claims will make the Internet permanently unstable. The raw sockets which have Gibson so steamed enable a machine to send or capture data independent of the operating system -- quite handy if you're a software developer or an advanced hobbyist. And while it's true that this also enhances the packet-flooding capabilities of a Windows machine by making it easy to spoof packets, it's also true that this function is already included in most other operating systems, and can be added to an existing Win-9x, 'ME, or '2K machine quite easily with a library called WinPcap. All right, we'll allow that there'll be a few s'kiddies who might prefer to use their Win-XP boxes for such purposes. But they can already do so simply by installing Linux and doing a bit of reading. The link for this article located at The Register is no longer available. . Steve Gibson cautions that the raw socket capability in Windows XP might unleash havoc across the web.. Windows XP Exploit, Raw Socket Security, Internet Chaos, Security Threats. . LinuxSecurity.com Team

Calendar 2 Jun 12, 2001 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here