Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
74

Protecting Your Home Router From Pharming Attacks Effectively Now

If you weren't worried enough about the security of your home computer and network, it may be time to step it up. A new study by Indiana University and Symantec has discovered (and, alas, made more public) a new hacking technique called "drive- by pharming." Of course, we can't use a name actually in the dictionary, but the gist of it is that your home router may be insecure. . First, keep in mind that a good percentage of home computers (and some business PCs) are wide open and already infected with "bot" software that turns them into zombies that spew out those millions of spam e-mails a day. So the first order of business for your computer has to be to clean and secure your PC. That means anti- virus, anti-spyware and anti-adware software needs to be front and center. Simultaneous to that you also need to be concerned about this "pharming" thing. In normal pharming, users are redirected from normal Web sites to bogus sites that contain malicious software code that infects or harms your PC. The link for this article located at RedOrbit news is no longer available. . Enhance your home and network safety by safeguarding your router against emerging cyber threats and pharming schemes.. Router Security,MALWARE PREVENTION,Home Network Safety,Cyber Measures. . Bill Locke

Calendar%202 Feb 28, 2007 User Avatar Bill Locke Network Security
83

Newly Emerging Pharming Threats in Online Banking Security Risks

If the phishers don't get you the pharmers will, police have warned. People are now getting wary of the scam called phishing - where people are sent emails claiming to be from their bank asking them to "confirm" their account details and passwords. . A recent phishing attack on Commonwealth Bank customers fooled very few people into disclosing their internet banking details. But now comes an even more dangerous scam called pharming, where hackers secretly redirect users' computers from financial sites to the scammers' fake sites that look almost exactly the same as the real ones. . A recent phishing attack on Commonwealth Bank customers fooled very few people into disclosing their. phishers, don't, pharmers, police, warned, people, getting. . LinuxSecurity.com Team

Calendar%202 May 29, 2006 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Secure Science Advisory: Pharming Attack Exploiting SSL Vulnerability

Secure Science Corporation released an advisory regarding the fact that the latest Pharming techniques utilized within malware has broken SSL. Chapter 5 of Phishing Exposed, a book by Lance James, who happens to work for Secure Science, demonstrated this technique in his book as an upcoming threat that phishers will take advantage of. The report on how this SSL Pharming attack occurs can be found on the advisories page at Secure Science.. The link for this article located at Mal-aware.org is no longer available. . Cyber Alert unveils new malware danger utilizing SSL via Pharming methods in their recent advisory release.. SSL Disruption, Malware Attack, Phishing Techniques, Secure Science Advisory. . LinuxSecurity.com Team

Calendar%202 Feb 15, 2006 User Avatar LinuxSecurity.com Team Server Security
83

Hushmail: DNS Attack Leads to User Redirections and Service Disruption

Surfers trying to visit the web site of popular secure email service Hushmail were redirected to a false site early Sunday following a hacking attack. Hush Communications said hackers changed Hushmail's DNS records after "compromising the security" of its domain registrar (Network Solutions). These changes were undone after a few hours on Sunday and normal Hushmail services have now been restored. . During the period of the attack users visiting Hushmail.com were confronted by a defaced page (as captured by defacement archive Zone-h id 2309823) containing a jokey reference that The Secret Service is watching. Agent Leth and Clown Jeet 3k Inc. Things might have been far worse if hackers had used the ruse to set up a doppelganger site under their control for the purposes of obtaining the pass phrases needed to access the encrypted email service (a trick known as a pharming attack). As it was the impact of the attack was limited to lost email. In a statement, Hush Communications said: "There was no unauthorized access to any of the Hush servers. Data managed by Hush was not compromised. During this period, email sent to hushmail.com will not have been delivered. Please accept our sincerest apologies for the inconvenience this has caused. We take this incident very seriously, and will continue to update this page as more information becomes available." The link for this article located at The Register is no longer available. . During the period of the attack users visiting Hushmail.com were confronted by a defaced page (as ca. surfers, trying, visit, popular, secure, email, service, hushmail, redirected. . LinuxSecurity.com Team

Calendar%202 Apr 27, 2005 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Comprehending the Dangers of Pharming Attacks and DNS Poisoning

First came phishing scams, in which con artists hooked unwary internet users one by one into compromising their personal data. Now the latest cyberswindle, pharming, threatens to reel in entire schools of victims. Pharmers simply redirect as many users as possible from the legitimate commercial websites they'd intended to visit and lead them to malicious ones. The bogus sites, to which victims are redirected without their knowledge or consent, will likely look the same as a genuine site. But when users enter their login name and password, the information is captured by criminals. . "Phishing is to pharming what a guy with a rod and a reel is to a Russian trawler. Phishers have to approach their targets one by one. Pharmers can scoop up many victims in a single pass," said Chris Risley, president and chief executive officer of Nominum, a provider of IP address infrastructure technology for businesses. E-mailed viruses that rewrite local host files on individual PCs, like the Banker Trojan, have been used to conduct smaller-scale pharming attacks. Host files convert standard URLs into the numeric strings a computer understands. A computer with a compromised host file will go to the wrong website even if a user types in the correct URL. The most alarming pharming threat is DNS poisoning, which can cause a large group of users to be herded to bogus sites. DNS -- the domain name system -- translates web and e-mail addresses into numerical strings, acting as a sort of telephone directory for the internet. If a DNS directory is "poisoned" -- altered to contain false information regarding which web address is associated with what numeric string -- users can be silently shuttled to a bogus website even if they type in the correct URL. The link for this article located at wired.com is no longer available. . 'Phishing is to pharming what a guy with a rod and a reel is to a Russian trawler. Phishers have to . first, phishing, scams, which, artists, hooked, unwary, internet, users, comprom. .LinuxSecurity.com Team

Calendar%202 Mar 14, 2005 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200