The TeamTNT threat group has updated Black-T - its crypto-mining worm - with Linux password-stealing capabilities and with an additional network scanner to help facilitate its spread to other vulnerable devices. . While known mostly for actively targeting Docker instances to use compromised systems for unauthorized Monero (XMR) mining, the group now shifted their tactics by upgrading their cryptojacking malware to also collect user credentials. As Unit 42 researchers found TeamTNT is hard at work boosting their malware's capabilities, this time adding memory password scraping capabilities via mimipy (with support for Windows/Linux/macOS) and mimipenguin (Linux support), two open-source Mimikatz equivalents targeting *NIX desktops. . TeamTNT's recent malware advancements include enhanced Linux password harvesting and network reconnaissance, targeting cloud and application servers more effectively. Crypto Mining, Linux Malware, TeamTNT, Password Theft, Cryptojacking. . LinuxSecurity.com Team
After more than a year of development, the Insecure.org developers have released version 5.50 of Nmap, their popular open source network scanner and mapper. According to the developers, the primary focus of this second stable update since Nmap 5.00 is the Nmap Scripting Engine (NSE); this "has allowed Nmap to expand up the protocol stack and take network discovery to the next level".. Nmap 5.50 more than doubles the number of included NSE scripts, bringing the total to 177, and includes 54 NSE libraries The link for this article located at H Security is no longer available. . Nmap 5.50 introduces enriched features through 177 new NSE scripts, representing a major enhancement for network exploration.. Nmap Network Scanner, NSE Scripts, Open Source Tool, Network Mapping, Software Release. . LinuxSecurity.com Team
It happens every day -- a sensitive document lies in the copier room, forgotten by the person who left it on the scanner. No big deal, right? Nobody else was able to read it.. Wrong, says Michael Sutton, a lab researcher at security vendor Zscaler. In fact, that document could easily be captured by an insider or an external hacker, without ever moving the paper from the scanner. In a blog posted yesterday, Sutton offered some hard evidence to suggest that networked scanners equipped with remote operations capabilities can easily be tapped to collect data from the sensitive documents that are run through them each day. The link for this article located at Dark Reading is no longer available. . Wrong, says Michael Sutton, a lab researcher at security vendor Zscaler. In fact, that document coul. happens, every, sensitive, document, copier, forgotten, person. . LinuxSecurity.com Team
The Insecure.org developers have announced the release of version 5.20 of Nmap, their popular network scanner and mapper. According to the developers, this first stable update since Nmap 5.00, released last July, includes more than 150 "significant improvements".. In addition to reduced memory consumption and performance improvements, Nmap 5.20 features protocol-specific payloads for more effective UDP scanning and the addition of 31 new Nmap Scripting Engine (NSE) scripts, bringing the total to 80. NSE allows users to create scripts to automate several common network tasks. For better performance, the traceroute engine has been completely rewritten and now sends probes in parallel to individual hosts The link for this article located at H Security is no longer available. . Nmap 5.20 launched featuring enhanced speed, additional scripts, and superior UDP scanning functionalities for comprehensive network assessment.. Nmap 5.20, Network Scanner, Performance Enhancements. . LinuxSecurity.com Team
As you all probably known since version 3 Nessus turned to a proprietary model and started charging for the latest plugins locking most of us out. Now we finally have a new, properly organized forked development with the name of OpenVAS - at last a decent and free Vulnerability Scanner! OpenVAS is a network security scanner which contains a graphical user front-end to help find problems in remote systems and applications. Have you tested it out? . The link for this article located at DarkNet is no longer available. . OpenVAS is a powerful network vulnerability scanner that identifies security risks in remote systems, featuring comprehensive scanning, customizable options, and more. OpenVAS, Network Security Scanner, Vulnerability Assessment Tool, Open Source Tool. . Bill Locke
Nmap (Network MAPper) is a network scanner written by Gordon Lyon. It is a free and open source tool and is available at insecure.org with versions for Windows and Linux and is ubiquitous in its use. Nmap can be (and is) used to for instance, scan for open ports on a remote server, to detect the OS run on the server, what all services are running on the remote server and so on. In the hands of a ethical hacker Nmap can be used for helping to audit a network but it's also used by attackers. So this brings up the question is software like Nmap ethical? . The link for this article located at Linuxhelp is no longer available. . Nmap, or Network Mapper, is essential for ethical hackers and auditors, enabling detailed scans to identify network security vulnerabilities and weaknesses. Nmap Tool, Ethical Hacking, Network Security, Open Source Scanner. . Bill Locke
With news settling in that the makers of the network vulnerability scanner Nessus will not open source the next version of the software, the team behind the soon-to-be-renamed GNessUs project is growing fast and attracting attention. . Word broke on October 5 that Tenable Network Security, the company founded in 1998 to hold the copyright for Nessus, would not release Nessus 3.0 under the GNU General Public License (GPL). The company said it would continue to maintain the GPLed 2.2.x series, but would not open the source of the impending Nessus 3. By October 10, the GNessUs project launched a fork based on Nessus 2.2.5 and a community quickly began forming around it. Tim Brown, a penetration tester for Portcullis Computer Security Limited in the UK and founder of GNessUs, said the idea to fork the project came out of conversations with colleagues in the security industry in England. Brown said that the company's move to drop the GPL for Nessus 3 was no great surprise after Tenable split the plugin streams for the software and ignored concerns by Brown and others that vulnerabilities would be missed because people refused to check the streams for either fiscal or ethical reasons. "My fork is dedicated to that community," Brown said. The split last December created a three-part stream structure that offered a fee-based "Direct Feed" with the latest vulnerability checks available from Tenable, a delayed feed available to those who registered with Tenable and agreed to Tenable's license agreement for plugins, and a "GPL Feed" with plugins from the user community. The link for this article located at Newsforge is no longer available. . Explore how GNessUs emerges as a new open source fork of the Nessus network scanner, addressing community concerns.. settling, makers, network, vulnerability, scanner, nessus. . LinuxSecurity.com Team
The Auditor security collection is a GPL-licensed live CD based on Knoppix, with more than 300 security software tools. Auditor gives you easy access to a broad range of tools in almost no time. . How can Auditor help you with IT security? Many security engineers arrive on a client's site and find that the network documentation required for solving the task properly is incorrect or even obsolete. In Auditor's Scanning submenu you'll find the Nmap network scanner. You can choose the traditional shell version or Nmap FE, which provides a graphical front-end for Nmap. After you have gained a basic overview of the network you can use NBTScan, a NetBIOS name scanner, and Nessus, a vulnerability scanner. If the audit includes Web applications, try the Nikto and Amap application scanners. Let's say you've been called in to examine a possible compromised server, and until the integrity of the server has been established you are not allowed to install any forensic software or even take the server offline. You can take your Auditor CD and start running the chkrootkit utility to see if any known rootkits are installed on the server. If you find any suspicious activity, you can take a disk image with the dd command and examine it for any possible rootkits or strange processes. You can also use the Autopsy Forensic Browser, a graphical interface that can analyze Windows, Linux, and BSD file systems (NTFS, FAT, Ext2/3) to search for files. If you are analysing a Linux or Unix system, you can use Nibbler to extracts known offsets from binaries to find hidden trojan horses. The link for this article located at linux.com is no longer available. . How can Auditor help you with IT security? Many security engineers arrive on a client's site and fin. auditor, security, collection, gpl-licensed, based, knoppix, secur. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.