Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 8 articles for you...
76

Analyzing Hardware Hacking and Security Insights From Black Hat USA 2015

Software gets much of the hacking spotlight, perhaps understandably so. But the physical infrastructure that runs all that code is just as susceptible to messing with, though it takes a different set of knowledge and techniques. Today's Training trio touch on the more solid side of that divide.. So, the box sits in front of you, its secrets beckoning. Where to start? One great place would be Hands-On Hardware Hacking and Reverse Engineering, a Training which will teach hardware-hacking and reverse-engineering techniques commonly used against electronic products and embedded systems. Topics will include tool tutorials, circuit board analysis and modification, embedded security, and common attack vectors. Pay attention, because at the end you'll have to apply these skills to defeat the security of a custom circuit board. The link for this article located at Dark Reading is no longer available. . Exploring hardware manipulation and reverse engineering techniques can strengthen embedded system security. Tools like side-channel analysis and fault injection help identify vulnerabilities.. Hardware Hacking, Reverse Engineering, Embedded Protection. . Alex

Calendar%202 Jul 22, 2015 User Avatar Alex Organizations/Events
67

HARES Software Protection: Innovative Anti-Reverse Engineering Method

Software reverse engineering, the art of pulling programs apart to figure out how they work, is what makes it possible for sophisticated hackers to scour code for exploitable bugs. It. At the SyScan conference next month in Singapore, security researcher Jacob Torrey plans to present a new scheme he calls Hardened Anti-Reverse Engineering System, or HARES. Torrey The link for this article located at Wired is no longer available. . Discover an innovative approach that has the potential to transform how software safeguards itself from reverse engineering, as introduced by Jacob Torrey.. Software Protection, Anti-Reverse Engineering, Cybersecurity Research. . LinuxSecurity.com Team

Calendar%202 Feb 12, 2015 User Avatar LinuxSecurity.com Team Cryptography
79

Chinese Malware Reverse Engineering Course at Mississippi State University

Wesley McGrew, a research assistant at Mississippi State University, may be among the few people thrilled with the latest grim report into a years-long hacking campaign against dozens of U.S. companies and organizations.. But McGrew's interest is purely academic: he teaches a reverse engineering class at the university, training 14 computer science and engineering students how to analyze malicious software. The link for this article located at Network World is no longer available. . McGrew instructs learners in malware examination via reverse engineering at the Mississippi State University course.. Malware Analysis, Cybersecurity Education, Reverse Engineering. . LinuxSecurity.com Team

Calendar%202 Feb 21, 2013 User Avatar LinuxSecurity.com Team Security Projects
79

Malicious PDF Attacks: Enhancing Security and System Defense

PDFs are widely used business file format, which makes them a common target for malware attacks. On the surface, PDFs are secure, but because they have so many . By using a number of utilities, we are able to reverse engineer the techniques in malicious PDFs, providing insight that we can ultimately use to better protect our systems. The link for this article located at ThreatPost is no longer available. . By using a number of utilities, we are able to reverse engineer the techniques in malicious PDFs, pr. widely, business, format, which, makes, common, target, malware, attacks. . LinuxSecurity.com Team

Calendar%202 May 24, 2011 User Avatar LinuxSecurity.com Team Security Projects
83

PS3 Hacker Releases Hypervisor Insights After Sony Raid

A Playstation 3 hacker says he has released information about reverse engineering hypervisor technology used in the PS3 after his home in Germany was raided earlier this week, reportedly at Sony's request.. In a comment to a post on his PS3 Linux and Hyper Reverse Engineering Blog, Graf-chokolo writes in the comments section: "Guys, SONY was today at my home with police and got all my stuff and accounts. So be careful from now on." After several readers expressed doubt about the legitimacy of the post, he says in another comment: "Guys, I don't joke, it's serious. And to prove it, I kept my word and uploaded all my HV reversing stuff. Upload it everywhere so SONY couldn't remove it easily. Grab it guys, it contains lots of knowledge about HV and HV procs." The link for this article located at CNET is no longer available. . In a comment to a post on his PS3 Linux and Hyper Reverse Engineering Blog, Graf-chokolo writes in t. playstation, hacker, released, information, about, reverse, engineering, hypervisor, technol. . LinuxSecurity.com Team

Calendar%202 Feb 25, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

In-Depth Analysis of ZeroAccess Rootkit for Cybersecurity Prevention

A malware analyst has deconstructed a highly advanced piece of crimeware believed to be the work of the notorious Russian Business Network. The step-by-step instructions for reverse engineering the stealthy ZeroAccess rootkit is a blow to its developers, who took great care to make sure it couldn't be forensically analyzed.. The tutorial means other malware researchers may also study the malware to close in on the people behind it and to better design products that can safeguard against it. The analysis was written by Giuseppe Bonfa, a malware researcher specializing in reverse engineering at InfoSec Institute, an information security services company. It documents a rootkit that's almost impossible to remove without damaging the host operating system and uses low-level programming calls to create hard disk volumes that are virtually impossible to detect using normal forensic techniques. Sophos's description of the rootkit, which is also known as Smiscer, is here. The link for this article located at The Register UK is no longer available. . Unlock the skills to reverse engineer the ZeroAccess rootkit with this guided tutorial, enhancing your malware analysis and defensive strategies against threats. ZeroAccess Rootkit, Crimeware Analysis, Malware Research, Cybersecurity Insights. . LinuxSecurity.com Team

Calendar%202 Nov 18, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Innovative Botnet Communication Analysis and Reverse Engineering Techniques

Networks of compromised computers controlled by a central server, better known as botnets, are a Swiss Army knife of tools for online criminals. Hackers can use these co-opted systems to churn out spam, host malicious code, hide their tracks on the Internet, or flood a corporate network to cut off its access to the Web.. Whenever a new botnet appears, researchers race to reverse engineer the software it installs on a victim's machine, and to decode the way each bot communicates with the controlling server. Because these communications are often encrypted, such analyses can take weeks or months. Now researchers from the University of California at Berkeley and Carnegie Mellon University have created a way to automatically reverse engineer the communications between compromised computers and their controlling servers. In a paper to be presented this week at the Association for Computing Machinery's Conference on Computer and Communications Security, the researchers show how automatic reverse engineering can decipher the structure and purpose of the communications between a command-and-control server and its bots. The link for this article located at Technology Review is no longer available. . Whenever a new botnet appears, researchers race to reverse engineer the software it installs on a vi. networks, compromised, computers, controlled, central, server, better, known, botnets. . Alex

Calendar%202 Nov 13, 2009 User Avatar Alex Network Security
83

Evolving JavaScript Obfuscation Techniques Making Defense Harder

As JavaScript becomes an increasingly key component of online attacks, attackers are investing more energy in obfuscation and other techniques to make defenders' attempts at reverse engineering more difficult, a security researcher told attendees at the annual CanSecWest conference on Wednesday. . Attackers have adopted the same techniques used to hide the purpose of other types of malicious code, such as splitting up the code into many components and the use of custom encoders, to obfuscate JavaScript, said Jose Nazario, senior security engineer at network-protection firm Arbor Networks. Other advances include the addition of functions aimed at detecting any attempts at debugging or running the program in a virtual machine, he said. The link for this article located at SecurityFocus is no longer available. . Advancements in code encryption methods complicate the decryption of JavaScript scripts for security experts.. JavaScript Obfuscation,Cyberattack Strategies,Security Techniques. . LinuxSecurity.com Team

Calendar%202 Apr 19, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200