Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
74

New Linux Worm Exploits PHP Injection and Command Execution Threats

Over the weekend reports began to filter in of a new network worm that focused on a variety of vulnerabilities in products typically found in Linux-based Web servers. It's been tagged by many as a Linux problem, and is, in a practical sense, although most of the vulnerabilities aren't strictly Linux issues. So far there's no evidence it's a serious real-world problem, although the Internet Storm Center has been reporting that they are seeing multiple variants of it circulating around the net. . Most anti-virus companies and researchers are focusing on what is probably the most significant vulnerability attacked by the worm, the XML-RPC for PHP Remote Code Injection vulnerability. The others at issue are the AWStats Rawlog Plugin Logfile Parameter Input Validation Vulnerability and the Darryl Burgdorf Webhints Remote Command Execution Vulnerability, both less common than PHP. While the authors are clearly still feeling their way around, there's no reason to believe that this will be a real biggie. But if someone writes a well-designed 'grab bag' worm to exploit the various bugs in PHP and other products common on Linux servers, we could have a problem on our hands. Administrators of these systems don't always feel the pressure to apply updates as frantically as Windows admins. Complicating the problem is the fact that Linux distributors like Red Hat can take months to issue their own versions of updates. The link for this article located at eWeek is no longer available. . Most anti-virus companies and researchers are focusing on what is probably the most significant vuln. weekend, reports, began, filter, network, focused, variety, vulne. . Brittany Day

Calendar%202 Nov 09, 2005 User Avatar Brittany Day Network Security
83

Carnegie Mellon CERT Report Explores Emerging DoS Attack Techniques

Last month, without much fanfare, Carnegie Mellon University's CERT Coordination Center released a white paper on current trends in denial-of-service (DoS) attacks. While much of the report merely chronicles the alerts and warnings the organization has published over the last two . . . . Last month, without much fanfare, Carnegie Mellon University's CERT Coordination Center released a white paper on current trends in denial-of-service (DoS) attacks. While much of the report merely chronicles the alerts and warnings the organization has published over the last two years, a few pages toward the end--where the authors point out new tactics taken by malicious users--are downright troubling. For those of you who don't know, a DoS attack is an event that prevents users from accessing a Web site. It is often the result of hundreds of computers overwhelming that site with bogus traffic. THE WHITE PAPER, written by CERT's Kevin J. Houle and George M. Weaver, as well as Neil Long and Rob Thomas, found that the means necessary to enlist computers (commonly known as "zombies") in this sort of attack has changed. Whereas DoS attacks used to result from the manual insertion of code via a Trojan horse into the targeted computer, now they are the result of autonomous network worms. The link for this article located at ZDNet is no longer available. . Emerging patterns in DDoS assaults showcase innovative tactics by hackers. Critical observations on transforming dangers disclosed.. DoS Attack, Cybersecurity Strategies, Network Security Trends, Automated Attacks. . LinuxSecurity.com Team

Calendar%202 Nov 23, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Analyzing Code Red II: Insights from Security Experts Dinner Discussion

A group of high-powered Internet security experts took their laptops to dinner on Saturday and between courses began analyzing the virulent new worm that now threatens the Web, the researcher who hosted the gathering said Monday. Analysts from Microsoft, Symantec, Computer . . . . A group of high-powered Internet security experts took their laptops to dinner on Saturday and between courses began analyzing the virulent new worm that now threatens the Web, the researcher who hosted the gathering said Monday. Analysts from Microsoft, Symantec, Computer Associates, Deloitte & Touche and the U.S. Naval Fleet Warfare Center among others had been gathered at the third annual NTBugTraq retreat in Canada when the first reports of Code Red II circulated, said Russ Cooper, surgeon general of TruSecure Corp. The group, representing about 20 companies, was finishing up a six-course dinner that included smoked duck, filet mignon and South Australian Shiraz wine on Saturday night at Cooper's home in Lindsay, Ontario, he said. The link for this article located at Silicon Valley is no longer available. . A group of elite cybersecurity analysts convene to delve into the complexities of the recent Blackout virus during a lively evening meal.. Code Red II, Internet Worm, Network Security, Cyber Threats, Security Experts. . LinuxSecurity.com Team

Calendar%202 Aug 07, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200