The Wireshark developers have announced the release of version 1.2.15 and 1.4.4 of their open source, cross-platform network protocol analyser; maintenance updates address two highly critical security vulnerabilities that could cause the application to crash.. The first issue (CVE-2011-0538), discovered by Huzaifa Sidhpurwala of the Red Hat Security Response Team, could lead to memory corruption when reading a .pcap file in the pcap-ng format The link for this article located at H Security is no longer available. . The first issue (CVE-2011-0538), discovered by Huzaifa Sidhpurwala of the Red Hat Security Response . wireshark, developers, announced, release, version, their, source. . LinuxSecurity.com Team
The three organisations behind the DNSSEC test . Experts expect DNSSEC (DNS security extensions) to deliver better security against attacks on the domain name system (DNS), as it will allow the authenticity of responses to be checked by comparing a key pair. German internet registry DENIC has offered a signed version of the .de zone using its own infrastructure since January. Hardware and software support is also slowly taking shape. At the Frankfurt meeting, Jan Sch The link for this article located at H Security is no longer available. . Experts expect DNSSEC (DNS security extensions) to deliver better security against attacks on the do. dnssec, three, organisations, behind, experts, expect, security, extensions). . Anthony Pell
A group of students at Rome Catholic School are learning how to become the future defenders of cyberspace through a pilot program that officials say is the first of its kind in the country. The program teaches students about data protection, computer network protocols and vulnerabilities, security, firewalls and forensics, data hiding, and infrastructure and wireless security. Most importantly, officials said, teachers discuss ethical and legal considerations in cyber security. . "It's a great course. It's a littler harder than I expected," said Catherine Gudaitis, a junior interested in theater. "But I know in the world I'm going to live in, this will be necessary information, even common knowledge." President Bush made cyber security a focal point in February 2003 in his National Strategy to Secure Cyberspace, citing the importance of safeguarding America from crippling internet-based attacks by terrorists against U.S. power grids, airports and other targets. The link for this article located at Wired is no longer available. . Pupils at St. Michael's Academy acquire vital digital competencies to safeguard online environments, focusing on information safety and system defenses.. CyberSecurity Education, Data Protection, Network Protocols, Ethical Considerations, Student Engagement. . Brittany Day
While the past of Wi-Fi has been plagued with security problems the economics are such that many players in the IT market want to see the insecure WEP replaced with something more robust. While nothing in the future is certain, it seem a given that Wi-Fi will overcome its adolescent growing pains and mature into a reasonably secure and easy to deploy method of networking. . . .. While the growth of 802.11b wireless networking has been explosive, problems with security of data being transmitted have plagued the technology almost since its conception. Still in spite of its drawbacks 802.11b has some compelling reasons for its deployment, both by the consumer and in the enterprise. Those reasons include its low cost, its ease of deployment and the tremendous convenience that wireless networking offers. As anyone knows who remembers the old Party Line telephone system, some times lack of good privacy can be lived with. Risk in general is discussed as well as basic ways to mitigate the risk. While Wireless Fidelity's (Wi-Fi) main security algorithm Wireless Encryption Protocol or WEP as it is commonly referred to remains relatively easy to crack, it is still better than nothing. This and other counter measures are discussed from basic residential wireless setups to more advanced ways the enterprise environment might consider for deploying wireless for transmission of important corporate data. While data security, confidentiality, integrity and user or access point authorization has left much to be desired in Wi-Fi's past, the future of Wi-Fi seems, at least at present to be brighter. Perhaps the main reason for this has been Wi-Fi's tremendous growth, which makes many of IT's main players want to see it succeed. WPA, 802.11X and other technologies have support of such industry giants as Microsoft and Cisco. So while secure wireless computing is still not a reality, it is a technology that merits close watch for the enterprise. The link for this article located at ebcvg.com is no longer available. . Theadvancement of Wi-Fi technology has progressed in response to security threats, investigating protocols such as WPA for enhanced information safeguarding.. Wireless Security, Network Solutions, Wi-Fi Enhancements, Data Safety. . Anthony Pell
Graduate students from Carnegie Mellon University on Monday proposed two methods aimed at greatly reducing the effects of Internet attacks. In two papers presented at the IEEE Symposium on Security and Privacy here, the graduate students suggested simple modifications to . . . . Graduate students from Carnegie Mellon University on Monday proposed two methods aimed at greatly reducing the effects of Internet attacks. In two papers presented at the IEEE Symposium on Security and Privacy here, the graduate students suggested simple modifications to network software that could defeat denial-of-service attacks and that could be implemented in the current protocol used by the Internet. The symposium, sponsored by the Institute of Electrical and Electronics Engineers, began Sunday and lasts through Wednesday. Steven Bellovin, a research fellow in network security at AT&T Labs, said both proposals are credible attempts at solving for network administrators the sticky problems of denial-of-service attacks. The link for this article located at news.com is no longer available. . Graduate students from Carnegie Mellon University on Monday proposed two methods aimed at greatly re. graduate, students, carnegie, mellon, university, monday, proposed, methods, aimed, greatly. . Anthony Pell
Storage security will become an "imperative" this year as the adoption of Internet technologies undermines the comforting notion that storage networks are safe from hacker attacks. In an analysis of storage security, the Yankee Group concludes that security will become an . . . . Storage security will become an "imperative" this year as the adoption of Internet technologies undermines the comforting notion that storage networks are safe from hacker attacks. In an analysis of storage security, the Yankee Group concludes that security will become an essential aspect of deployment strategies as users expand disaster recovery planning or roll out storage networks that mix multiple network protocols. Yankee is seeking to dispel the impression that dedicated, Fibre Channel storage networks are "closed" networks i.e. not subject to security breaches. As mixed IP-Fibre Channel storage networks or IP storage networks become deployed security will be even more important, the research house argues. . As online innovations rise, the safeguards for data holding systems need to advance to counteract the growing threats posed by cybercriminals.. Storage Security, Hacker Risks, Data Protection, Disaster Recovery, Network Protocols. . LinuxSecurity.com Team
Just as 2000 was a rough year for firewalls, with holes blown in both commercial and open-source products, 2001 was a most uncomfortable year for the secure shell, or ssh. Several groups focused their attentions on this cornerstone of the net, and several problems emerged. ssh has emerged from this scrutiny a stronger product. . . .. Just as 2000 was a rough year for firewalls, with holes blown in both commercial and open-source products, 2001 was a most uncomfortable year for the secure shell, or ssh. Several groups focused their attentions on this cornerstone of the net, and several problems emerged. ssh has emerged from this scrutiny a stronger product. Not all of these issues affect all ssh users, so it's important to understand the vulnerabilities, their impact, and how to mitigate these risks. In this piece, several of the vulnerabililities found in 2001 are discussed, and some general recommendations for the ssh user are offered. Briefly, two major vendors of ssh products have emerged, SSH Communications, who originally developed the software, and OpenSSH, who produce an open-source derivative. When referring to the ssh client from SSH Communications, the term Ssh will be used. When referred to the OpenSSH client, the term OpenSSH will be used. This is important as they sometimes do not share security vulnerabilities. SSH1 refers to the version 1 protocol for ssh, and SSH2 refers to the second version of the protocol. The link for this article located at Linux Journal is no longer available. . Just as 2000 was a rough year for firewalls, with holes blown in both commercial and open-source pro. rough, firewalls, holes, blown, commercial, open-source. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.