Two security researchers are calling for an industry-wide response to fix a serious vulnerability they discovered in the SSL protocol, used widely on the Internet for secure data transfers. But a noted network security researcher says the vulnerability has very little impact on most users and will not result in data loss.. Moxie Marlinspike, a security researcher who has discovered high- profile security flaws, said the vulnerability has extremely limited value in practice. The attack is not designed to intercept traffic. Instead code is injected revealing nothing to the attacker, Marlinspike said. "It has virtually no impact on the majority of users in the common case of how SSL/TLS is deployed," Marlinspike wrote in an email message. "It doesn't affect your webmail, online banking or online shopping experience." The link for this article located at SearchSecurity is no longer available. . Moxie Marlinspike, a security researcher who has discovered high- profile security flaws, said the v. security, researchers, calling, industry-wide, response, serious, vulnerability. . LinuxSecurity.com Team
This is a short run down of the two popular security protocols of the Internet. Some familiarity with the basics is assumed. In short, SSL requires applications to be modified as it operates above the TCP layer and this happens in user space in linux and other OSes. Whereas IPsec works seamlessly no matter what application and what protocol the application uses. ICMP traffic, UDP traffic and TCP all are protected by IPsec without the user or application developer worrying about it. . Whereas SSL involves a certain degree of user interaction. One has to verify certificates, their validity, expiry date and so on. There is another key difference between the two security protocols.SSL protects traffic end to end whereas IPsec is usually deployed in tunnel mode in which only the edge of your network and beyond is protected by IPsec. It is interesting to see how technical differences especially which layer a particular protocol operates influence ease of deployment.IPsec is a popular method to run corporate VPNs and gives a somewhat complete security solution. The link for this article located at linuxforums.org is no longer available. . SSL and IPsec are key protocols for securing data transmissions. SSL operates at the transport layer for applications, while IPsec secures IP packets at the network layer.. IPsec, SSL, Traffic Protection, VPN Security, Network Encryption. . Bill Locke
This time we will install a network protocol analyzer to watch the traffic on our LAN from initiating and connecting a SIP call. The Wireshark open source project was formerly known as Ethereal. I used to work for a great company called Cybera as a programmer, and I was always fascinated by networking. I. The link for this article located at AsteriskBlog is no longer available. . Delve into setting up Wireshark for observing SIP call data across your local network, augmenting your analysis of network performance.. Wireshark Installation,SIP Traffic Monitoring,Network Protocol Analysis. . Benjamin D. Thomas
The protocol that has defined e-mail for more than two decades may have a fatal flaw: It trusts you. Developed when the Internet was used almost exclusively by academics, the Simple Mail Transfer Protocol, or SMTP, assumes that you are . . . . The protocol that has defined e-mail for more than two decades may have a fatal flaw: It trusts you. Developed when the Internet was used almost exclusively by academics, the Simple Mail Transfer Protocol, or SMTP, assumes that you are who you say you are. SMTP makes that assumption because it doesn't suspect that you're sending a Trojan horse virus or fraudulent pleas for money from the relations of deposed African dictators, or that you've hijacked somebody else's computer to send tens of millions of advertisements for herbal Viagra. In other words, SMTP trusts too much--and that has spam foes, security mavens and even an original architect of today's e-mail system agitating for an overhaul, if not an outright replacement, of the omnipresent protocol. "I would suggest they just write a new protocol from the beginning," said Suzanne Sluizer, a co-author of SMTP's immediate predecessor and a visiting lecturer at the University of New Mexico, in an interview. . The foundation that has governed online messaging for over twenty years could possess a critical vulnerability: It relies on trust.. Email Protocol, SMTP Security, Protocol Risks. . LinuxSecurity.com Team
While this knowledge could easily have led a younger Chappell down the path to what she refers to as the "dark side", or malicious computer hacking (known as cracking), she chose to pursue a different career. Decades later, she has moved on from Novell and established a career as an expert and consultant in protocol analysis, a segment of network security.. . .. While this knowledge could easily have led a younger Chappell down the path to what she refers to as the "dark side", or malicious computer hacking (known as cracking), she chose to pursue a different career. Decades later, she has moved on from Novell and established a career as an expert and consultant in protocol analysis, a segment of network security. Courted by organisations such as Cisco, Novell, IBM, as well as the FBI, Chappell has made a name for herself in an arena she enjoys. And while, as she says, "there is no such thing as a secure network, or a secure operating system", Chappell is doing her best to make sure the organisations she works with are able to protect themselves from vulnerabilities and attacks. ZDNet Australia spoke with Laura Chappell about cyber threats for 2002, how script kiddies and junior hackers can bring down your network, why there is safety in grey hair, and how to train hackers without losing them to the "dark side". The link for this article located at ZDNet AU is no longer available. . Professionals examine combating digital dangers, the hazards associated with breaches, and safeguarding systems for businesses.. Network Security, Threat Management, Hacking Prevention, Attack Strategies, Protocol Analysis. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.