Thousands of servers running etcd are exposing user credentials publicly on the Internet. According to security researcher Giovanni Collazo, a quick query made through the Shodan search engine revealed a total of 2,284 etcd servers which are leaking credentials, including the passwords and keys required for cms_admin, mysql_root, and postgres server infrastructure.. Etcd is a type of database which allows for the storage of data by clustering. The open-source system is able to store the credentials required for different servers and applications, and as apps can read and write data into the management system, reconfiguration across servers and networks becomes a more streamlined process.. Uncover the alarming reality that numerous etcd instances are inadvertently revealing confidential information over the internet, jeopardizing system security.. etcd Security, Server Credentials Leak, Open Source Database, Cybersecurity Risks. . LinuxSecurity.com Team
Google is dropping encryption into MariaDB, the fork of Oracle. The development has been branded a "major enhancement" for MariaDB security by those running the project, particularly for customers building PCI and other types of applications that need encryption at rest. Appearing in a MariaDB community edition means Google's crypto will be picked up by commercial and non-commercial spins of the open-source database. The link for this article located at The Register UK is no longer available. . The development has been branded a 'major enhancement' for MariaDB security by those running the pro. google, dropping, encryption, mariadb, oracle, development, branded. . LinuxSecurity.com Team
A collaborative project intended to give network managers a comprehensive, unbiased source of information on software vulnerabilities has gone live, delivering its entire library of flaws under an open-source licence. . . .. A collaborative project intended to give network managers a comprehensive, unbiased source of information on software vulnerabilities has gone live, delivering its entire library of flaws under an open-source licence. The Open Source Vulnerability Database (OSVDB), made available to the public last week, is intended as a clearing-house for verified vulnerability information, collecting and organizing the thousands of vulnerability reports that surface each year so that IT managers don't have to. The link for this article located at LinuxWorld is no longer available. . Unveil an innovative joint venture offering extensive free-access resources regarding software vulnerabilities aimed at IT administrators.. Open Source Vulnerability Database, Software Flaws, IT Management, Vulnerability Information, Open-Source Project. . LinuxSecurity.com Team
The Internetworked Security Information Service (ISIS) brings together four independent projects--the Open Source Vulnerability Database, the Alldas.de defacement-tracking service, the PacketStorm software database and the vulnerability watchdog VulnWatch--into a loosely organized collaboration. "There are a lot of commercial organizations that . . . . The Internetworked Security Information Service (ISIS) brings together four independent projects--the Open Source Vulnerability Database, the Alldas.de defacement-tracking service, the PacketStorm software database and the vulnerability watchdog VulnWatch--into a loosely organized collaboration. "There are a lot of commercial organizations that put out this type of information for free, but will it always be that way?" said Chris Wysopal, director of research and development for security company @Stake. "We are calling the project 'open source' because the information in it will be open and free." The link for this article located at ZDNet is no longer available. . The Internetworked Security Information Service (ISIS) brings together four independent projects--th. internetworked, security, information, service, (isis), brings, together, independent, projects--th. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.