Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Once upon a time, not so long ago, the IT admin chose exactly what hardware and software would be used by employees. Recent trends like the consumerization of IT and BYOD (bring your own device) have shifted the balance of power, but IT still has to maintain some degree of control over the applications used and where sensitive data is stored.. Many users just download apps or start using unsanctioned services, though, and introduce unnceccesary security risks through "shadow IT." The link for this article located at CSO Online is no longer available. . Many users just download apps or start using unsanctioned services, though, and introduce unnceccesa. admin, chose, exactly, hardware, software, would. . LinuxSecurity.com Team
From 2005 through today, SQL injection has been responsible for 83% of successful hacking-related data breaches. It is estimated that there are a total of 115,048,024 SQL injection vulnerabilities in active circulation today. . Imperva The link for this article located at SecurityPark is no longer available. . Cross-site scripting (XSS) vulnerabilities persist as a significant danger, with 79% of security breaches linked to them over the past decade. Be vigilant!. SQL Injection, Cyber Threats, Security Controls, Hacking Techniques. . LinuxSecurity.com Team
Embedded virtualisation company Open Kernel Labs has introduced a mobile security product based on the company's phone-specific hypervisor, the OKL4 'microvisor'.. The SecureIT Mobile Enterprise package allows the creation of independent secured domains on a mobile device, the company announced at Mobile World Congress 2011 on Monday. The product, which combines an embedded hypervisor with tailored security software, is part of a future vision where "employees bring personal devices to work and happily let employers install enterprise mobility solutions [on them]", Open Kernel Labs said. The link for this article located at ZDNet UK is no longer available. . The SecureIT Mobile Enterprise package allows the creation of independent secured domains on a mobil. embedded, virtualisation, company, kernel, introduced, mobile, security, product, based. . LinuxSecurity.com Team
The cloud -- and outsourcing in general -- breaks off pieces of the stack beneath any given application. That removes the stack from an enterprise CISO's control, and that's not good.. That, according to Wendy Nather, a senior analyst in The 451 Group's enterprise security practice. She spoke out about the problem at the firm's client security event Dec. 1. Even consolidated security offerings that try to unify the stack are no longer as useful, said Nather, in a presentation entitled, "How the Cloud Breaks Application Security (and a lot of other things)." There's less to manage, she noted, and unifying management technologies like identity and access management and governance risk and compliance have less to work with, too. The link for this article located at CSO Online is no longer available. . Markus Vance emphasizes the complexities that remote work and hybrid environments present for data protection and organizational governance.. Application Security Management, Cloud Security, Outsourcing Risks. . Alex
The National Institute of Standards and Technology has released the final standard for securing agency computer systems under the Federal Information Security Management Act. Federal Information Processing Standard 200 [1] sets minimum security requirements for federal systems in 17 security areas. It is the third of three publications required from NIST under FISMA, which requires executive branch agencies to establish consistent, manageable IT security programs for non-national security systems. The intent of FISMA is to implement risk-based processes for selecting and implementing security controls. . FIPS 199 [2], released two years ago, establishes standards for categorizing IT systems as low, moderate or high-impact, depending on the effect of a breach of confidentiality, integrity or availability of the system. Special Publication 800-53 [3] - "Recommended Security Controls for Federal Information Systems", lays out the tools to be used under FIPS 200 to secure IT systems. Agencies must be in compliance with FIPS 200 by March 2007. The link for this article located at Government Computer News is no longer available. . FIPS 199 [2], released two years ago, establishes standards for categorizing IT systems as low, mode. national, institute, standards, technology, released, final, standard, securing. . Brittany Day
Security Enhanced Linux has move into the mainstream of operating system architecture in recent years. For those who don't understand the technology, many articles exist. SELinux provides mandatory access control to a wider audience. It helps eliminate O-day attacks. The agenda for the 2006 SELinux Symposium has just been announced and some project leaders of Linux distributions may way want to attended. . Existing distributions such as Fedora are including SELinux in the default build, and ports are underway to bring SELinux functionality to BSD and Darwin. Management has already stressed the importance of SELinux in many organizations. So, security minded systems administrators will find SELinux an important area to gain proficiency. The link for this article located at LXer.com is no longer available. . Explore the pivotal role of SELinux in modern operating systems, elevating security measures and governance for various distributions.. SELinux, Access Control, Operating System Security. . LinuxSecurity.com Team
The National Institute for Standards and Technology today released the first draft of a publication describing mandated security controls for federal information systems. NIST officials want agencies to experiment with the initial public draft, "Special Publication 800-53: Recommended Security Controls for Federal Information Systems.". . .. The National Institute for Standards and Technology today released the first draft of a publication describing mandated security controls for federal information systems. NIST officials want agencies to experiment with the initial public draft, "Special Publication 800-53: Recommended Security Controls for Federal Information Systems." It outlines electronic and physical controls for systems categorized under three levels of potential impacts, such as what would happen if someone steals information from a federal system and modifies the data or disrupts a government service. Low-, medium- and high-impact levels are defined in draft "Federal Information Processing Standard (FIPS) 199: Standards for Security Categorization of Federal Information and Information Systems." NIST officials released the final draft of that standard in September. Controls outlined in the Publication 800-53 draft fall into three classes -- management, operational and technical -- and are then broken down further into families. For example, under the management class, families include security planning and acquisition of information systems and services. Operational class families focus on issues such as incident response and contingency planning and operations. NIST's Computer Security Division plans to use agencies' comments from the initial draft and an open workshop in March to develop final security controls that would become the new "FIPS 200: Minimum Security Controls for Federal Information Systems." FIPS 199 and 200 are required under the Federal Information Security Management Act of 2002. NIST expects to publish FIPS 200 in the fall of 2005, when its controls will become mandatoryfor all federal agencies. Comments are due by Jan. 31, 2004, and may be submitted to
If you're still running inetd, it's time to move on. Either xinetd or tcpserver offer superior security and control. We're going to look at tcpserver. Note that there is one limitation: it manages only tcp. If you're using UDP or rpc services, tcpserver alone will not do the job. In that case, xinetd is the way to go.. . .. If you're still running inetd, it's time to move on. Either xinetd or tcpserver offer superior security and control. We're going to look at tcpserver. Note that there is one limitation: it manages only tcp. If you're using UDP or rpc services, tcpserver alone will not do the job. In that case, xinetd is the way to go. The (in)Famous DJB tcpserver is part of the ucspi-tcp suite of tools by none other than the famous, and infamous, Daniel J. Bernstein. Professor Bernstein seems to inspire strong passions in the tech community; some refuse to use his software because they do not like the author. Other objections are that his programs install themselves in non-standard file locations, and that he keeps too tight a grip on the code. Personality issues aside, I find that his programs are lean, fast, secure, and worthy on their own merits. A special item of note is Professor Bernstein led the suit against the United States Government against export controls on encryption software, and won. DJB's security model is based on a zero-trust premise. His programs don't even trust themselves- each function is isolated from other parts of the program. They run in user accounts with restricted rights; services that require root access are as restricted and limited as possible. Any successful intrusion will be severely limited, if an intruder can get in at all. The link for this article located at CrossNodes is no longer available. . Tcpserver provides significant advantages over inetd for managing TCP services, focusing on security, isolation, resource controls, and improved logging capabilities. Tcp Server Management, Xinetd Alternative, Daemon Security, Network Control. . LinuxSecurity.comTeam
Get the latest Linux and open source security news straight to your inbox.