Network admins take note: A set of vulnerabilities can bypass HTPPS with ease and result in spying, outages and authentication bypass. . Discovered on Wednesday by Cisco's security intelligence and research group Talos, the critical bugs are found within the Network Time Protocol (NTP), designed to synchronize the clocks of computers over a network. Developed before 1985, the protocol is one of the oldest still in use. In a blog post documenting the find, Talos said a logic error within the Network Time Protocol daemon (NTPD), the operating system behind the protocol, could allow attackers to bypass authentication procedures and effectively grant them the keys to a network kingdom. . Significant vulnerabilities in TOTP enable malicious users to circumvent validation, resulting in potential threats and operational turmoil.. NTP Security Flaw, Network Vulnerabilities, Authentication Bypass. . Dave Wreski
The USENIX Security conference has been warned that by tweaking the firmware on certain kinds of phones, a hacker could make it so other phones in the area are unable to receive incoming calls or SMS messages.. The hacker modifies the baseband processor on some Motorola phones and tricking some older 2G GSM networks into not delivering calls and messages. The hack could shut down some small localised mobile networks by spying on the messages sent from phone towers and not delivering them. The link for this article located at Fudzilla is no longer available. . The hacker modifies the baseband processor on some Motorola phones and tricking some older 2G GSM ne. usenix, security, conference, warned, tweaking, firmware, certain, kinds. . LinuxSecurity.com Team
This open-source software for Mac and Linux does for DNS what SSL does for HTTP: It encrypts DNS traffic to prevent spoofing, snooping, and man-in-the-middle attacks.. Like most of the network protocols and systems in widespread use today, the Domain Name System (DNS) harbors significant security vulnerabilities. Though DNS provides a deceptively simple service -- translating human-friendly website addresses such as https://www.cnn.com/ into computer-friendly numerical IP addresses such as -- the system's integrity is a crucial cornerstone of Internet operations and trustworthiness. One common attack on the DNS infrastructure is called "DNS spoofing." In this type of attack, also known as "DNS cache poisoning," an attacker tricks a DNS server into returning an incorrect IP address for a target website. For example, an attacker might perform cache poisoning on the DNS entry for a legitimate bank's website, thereby directing visitors to the hacker's fake look-a-like site in order to capture their login or banking details. This type of attack is difficult for users to detect, because the website address displayed in the user's web browser is not altered in any way. A single compromised DNS server at an Internet Service Provider can in this way affect potentially thousands of users. The link for this article located at eSecurity Planet is no longer available. . Fortify your DNS by implementing DNSCrypt to thwart threats such as impersonation and caching problems often encountered in networking protocols.. Dns Security, DnsCrypt, Network Integrity, Encryption, Dns Spoofing. . Dave Wreski
I remember being excited when I was asked to use a sledgehammer to tear down a covered garage that wasn't approved by the city. It had been standing beside my girlfriend's house for years. You could tell it was built intelligently and with love. The supporting beams were twice as thick as required by code, and every nail and screw was driven straight. The lumber itself was top shelf, not a knot or bend in it.. I have a hard time driving a nail straight -- yet it took me less than an hour to turn the structure into a crumpled pile of lumber. In the security world, something similar happens every day when hackers tear down whole networks and systems. The link for this article located at InfoWorld is no longer available. . Discover practical techniques for thwarting cybercriminals and guaranteeing that your system stays protected and robust in the face of dangers.. Network Defense Strategies, Cybersecurity Techniques, Hacker Mitigation. . LinuxSecurity.com Team
Hardly a day goes by that we don't hear new information about some company getting themselves hacked. Sure they all have firewalls, but HOW are the hackers getting in? I was hired to perform an application security audit for a local university. They wanted to make sure that they didn't become part of the growing statistics. . Exploit Video (9mb Download) Exploit Fixed (1mb Download) What you've just witnessed is an applicaiton vulnerability. I didn't attack the operating system, I simply interacted with and manipulated data given to me by the web server. As you can see, these attacks are staggeringly simple. The link for this article located at Appiant.net is no longer available. . A comprehensive review of application security audit findings is vital for enhancing defenses against cyber threats and vulnerabilities in code and architecture. Application Security, Network Protection, Exploit Control, Audit Insights, Security Strategies. . Brittany Day
For enterprises today, the network is where business takes place. Every department in an organization relies on the network for applications and for a growing share of communications, not only e-mail and instant messaging, but soon telephony as well. . . .. For enterprises today, the network is where business takes place. Every department in an organization relies on the network for applications and for a growing share of communications, not only e-mail and instant messaging, but soon telephony as well. The mission of network security is to ensure that applications can do their jobs and that applications have the network bandwidth and the availability needed to support the operations of the company. There's also a broader perspective on network requirements. It's a holistic view that encompasses security as well as availability, bandwidth and control. We call it network integrity. This is the real goal behind securing a network. When the network is functioning properly, providing applications with the bandwidth and availability they need, then the network has integrity, and security is doing its job, even when the network is under attack. The link for this article located at ComputerWorld is no longer available. . Explore the advantages of an integrated defense strategy in maintaining the protection and reliability of organizational systems and data exchanges.. Network Security, Layered Approach, Application Integrity, Business Communication. . Anthony Pell
DNS is a heavily used protocol on the Internet yet has numerous security considerations. This paper whilst containing nothing new on DNS security brings together in one document many strands of DNS security which has been published and reported in many . . . . DNS is a heavily used protocol on the Internet yet has numerous security considerations. This paper whilst containing nothing new on DNS security brings together in one document many strands of DNS security which has been published and reported in many separate publications before. As such this document intends to act as a single point of reference for DNS security. The link for this article located at Help Net Security is no longer available. . The Domain Name System (DNS) is vital for internet functionality but poses various security risks to networks. This guide details DNS security threats and effective mitigation strategies. DNS Security, Network Threats, Security Protocols. . Anthony Pell
The value of a computer's information determines its desirability as a target for hacking -- but only in part. Even valueless machines can serve as jumping-off sites for additional attacks once compromised, or be used to gather information about an ostensibly . . . . The value of a computer's information determines its desirability as a target for hacking -- but only in part. Even valueless machines can serve as jumping-off sites for additional attacks once compromised, or be used to gather information about an ostensibly "private" network in preparation for a later intrusion. And of course, mischief is an endless source of motivation. Knowledge of what the network should look like is worthless unless regularly compared to the way it is. I'm using "network" here to refer to the sum of all networked computers, not to router and switch security, which is a completely different matter. "Securing the network," in this sense, means preventing remote users from gaining access to your machines. The link for this article located at Certcities is no longer available. . Utilize Nmap proficiently to enhance network security, safeguarding against potential cyber dangers while tracking accessibility.. Network Integrity Assessment, Nmap Monitoring, Cyber Defense Techniques. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.