Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The latest Microsoft bug is a doozy. Why do these things keep cropping up? The federal government and technology industry want you to believe the threats to our networks are external, not internal, where someone must be held accountable when things go wrong. Thus, we hear the rhetoric about cyberterrorists, hackers, and the so-called 'Digital Pearl Harbor' - things you can't easily point fingers at and hold someone accountable for when bad things happen.. . . . The latest Microsoft bug is a doozy. Why do these things keep cropping up? The federal government and technology industry want you to believe the threats to our networks are external, not internal, where someone must be held accountable when things go wrong. Thus, we hear the rhetoric about cyberterrorists, hackers, and the so-called 'Digital Pearl Harbor' - things you can't easily point fingers at and hold someone accountable for when bad things happen. Richard Forno 20 December 2001: Essay #2001-15
A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks targeting a European government entity and a managed service provider (MSP) located in Africa. . Telemetry evidence gathered by Google-owned Mandiant indicates that the exploitation occurred as early as October 2022, at least nearly two months before fixes were released. "This incident continues China's pattern of exploiting internet facing devices, specifically those used for managed security purposes (e.g., firewalls, IPS\IDS appliances etc.)," Mandiant researchers said in a technical report. The attacks entailed the use of a sophisticated backdoor dubbed BOLDMOVE , a Linux variant of which is specifically designed to run on Fortinet's FortiGate firewalls. The link for this article located at The Hacker News is no longer available. . State-sponsored cybercriminals from China took advantage of a flaw in Fortinet security software to install malicious code and create backdoors in compromised networks.. Fortinet Vulnerability, Zero-Day Threat, Network Exploit, Malware Attack, Backdoor Threat. . Brittany Day
Another security vulnerability is hitting the tech (and mainstream!) press, and we want to make Fedora users get straight, simple information. This one is CVE-2014-3466, and the cute nickname of the day is . Here The link for this article located at Fedora Magazine is no longer available. . Uncover insights into the SSLv3 POODLE vulnerability impacting Fedora users and the associated dangers.. SSLv3 Poodle Flaw, Fedora Security, Network Exploit Risk. . LinuxSecurity.com Team
THC claims it can listen to any call, use other accounts to make calls and access the victim's voice mail. Hackers have claimed that they have successfully re-engineered a standard consumer hardware available from Vodafone store to intercept calls and gain administrator access into other user accounts. . The Hacker's Choice (THC) said in a blogpost https://thcorg.blogspot.com/2011/07/vodafone-hacked-root-password-published.html that their engineers managed to reverse engineer Femto Cell into a full blown 3G/UMTC/WCDMA interception device. A Femto Cell is a tiny home router which boosts the 3G Phone signal. It is available from the Vodafone Store to any customer for 160 GBP, said THC THC said that engineers exploited a design flaw and got full control of the Vodafone UK network. The link for this article located at CBR Online is no longer available. . The Hacker's Choice (THC) said in a blogpost https://thcorg.blogspot.com/2011/07/vodafone-hacked-roo. claims, listen, other, accounts, calls, victim's, voice. . LinuxSecurity.com Team
Red Hat has finally managed to release a patch for the previously reported critical Linux kernel vulnerability. Red Hat's initial response was to provide a workaround for the problem that involved blacklisting certain network protocols, preventing the exploit from functioning. Novell has also released updates for openSUSE 10.3 to 11.1, SUSE Linux Enterprise Desktop and SUSE Linux Enterprise Server. . The link for this article located at H Security is no longer available. . Essential notifications from Red Hat and Novell focus on a major vulnerability in the Linux kernel and its associated network security threat.. Kernel Patch, Red Hat Update, SUSE Fix. . LinuxSecurity.com Team
One can only imagine what raced through Michael Lynn's mind the penultimate moment before he saved or sacrificed our nation's critical infrastructure, depending on your take of the researcher's Black Hat Briefings presentation this week. . Lynn's the guy who quit his job at Atlanta-based Internet Security Systems Inc. and defied legal threats from Cisco Systems Inc. to divulge (without much detail) how he reverse-engineered Cisco's Internetwork Operating System [IOS] software to exploit a known flaw in the networking giant's routers. He and Black Hat conference founder Jeff Moss are now off the legal hook, with the two men and two companies having reached an accord late Thursday. But what happened, and why, continues to confound the security community. Initially, ISS consented for Lynn, then with its X-Force research team, to discuss his findings at the annual Las Vegas conference, especially given a patch to prevent the attack had been out for three months. ISS apparently had been working with Cisco on this problem for at least that long. Then Cisco got involved, belatedly, and deployed staff to cut Lynn's PowerPoint pages from 2,300 conference handbooks. Wednesday it issued a restraining order against Black Hat organizers and Lynn. On Thursday, Cisco distributed abridged CDs of proceedings to 2,500 conventioneers. "Considering how important Cisco routers are to the Internet, I can somewhat understand their concerns," Steve Fletcher, a security specialist for a security consulting firm in central Illinois, said in an e-mail exchange. "However, I believe they went to extremes, considering that a patch is supposedly available." The link for this article located at SearchSecurity is no longer available. . The recent verdict by Michael Lynn regarding the vulnerability in Cisco's routing system ignites a debate on moral standards and safety protocols within the technology sector.. Michael Lynn,Cisco Router,Security Ethics,Network Exploit,Black Hat. . Brittany Day
On February 18th, 2005 "John Doe" posted a remote buffer overflow exploit for the Arkeia Network Backup Client. This vulnerability affected all known versions of the software, going back as far as the 4.2 series (when the company was called Knox). The buffer overflow occurs when a large data section is sent with a packet marked as type 77. The Arkeia Network Backup Client is your typical backup agent; it runs with the highest privileges available (root or LocalSystem) and waits for a connection from the backup server. The Arkeia client and server both use TCP port 617 for communication. According to the SANS ISC, the kids are wasting no time. . A few hours after the exploit was posted, I started to investigate the flaw and port the code to the Metasploit Framework. On the Windows platform, it was possible switch from a plain return address smash to a SEH frame overwrite. This provides room for about 1000 bytes of payload and avoids the heap tricks used in the original exploit. When overwriting the SEH frame, a pop/pop/ret opcode is used to redirect execution to [esp+8], which happens to always point 4 bytes before the smashed SEH function pointer. Since Windows 2003 and Windows XP SP2 block SEH returns to system libraries, the best return address to use is one found inside the executable itself The link for this article located at MetaSploit is no longer available. . The Arkeia Network Backup Agent is under scrutiny due to a buffer overflow vulnerability, allowing malicious actors to execute arbitrary code on systems affected. Arkeia Network, Buffer Overflow, Remote Access Exploit, Backup Software. . LinuxSecurity.com Team
A 20-year-old computer hacker who last weekend alerted telecommunications giant WorldCom Inc. about security holes he uncovered inside the company's network (see story) said he enters corporate Web sites without permission to satisfy his curiosity. Adrian Lamo, who has a publicized . . . . A 20-year-old computer hacker who last weekend alerted telecommunications giant WorldCom Inc. about security holes he uncovered inside the company's network (see story) said he enters corporate Web sites without permission to satisfy his curiosity. Adrian Lamo, who has a publicized history of exploring the inner workings of corporate computer networks in search of system weaknesses, said in an interview with Computerworld that he sees himself as helping companies improve their system security by reporting flaws. "I try to engage in harm reduction when I'm inside a computer network," said Lamo. "I've never intentionally done damage in a network." The link for this article located at ComputerWorld is no longer available. . A 21-year-old coder unveiled critical weaknesses in Microsoft’s system, highlighting the necessity of responsible disclosure practices.. WorldCom Security,Hacker Lamo,Exploit Discovery,Network Vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.