Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
83

RFID Credit Card Attacks: Insights from Shmoocon Conference

It's been known for some time that there are security issues associated with the increasing use of RFID tags in credit cards, but this past weekend afforded a fresh demonstration of just how easy it is for hackers to take advantage of them. . Onstage at the Shmoocon hacker conference in Washington, D.C., Recursion Ventures security researcher Kristin Paget used about $350 in equipment to wirelessly read a volunteer's RFID-enabled credit card and then encode its key data onto a blank card, as described Monday by Forbes. The link for this article located at Network World is no longer available. . Uncover the alarming simplicity with which cybercriminals can manipulate RFID-enabled payment cards using basic tools, as demonstrated at Shmoocon.. RFID Technology, Credit Card Exploits, Wireless Hacking Techniques. . LinuxSecurity.com Team

Calendar%202 Feb 02, 2012 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

ShmooCon Analysis: Linux USB Exploit Demonstration and Security Insights

At the ShmooCon hacker conference, security expert Jon Larimer from IBM's X-Force team demonstrated that Linux is far from immune from attacks via USB storage devices: during his presentation, the expert obtained access to a locked Linux system using a specially crafted USB flash drive, .... taking advantage of a mechanism that allows many desktop distributions to automatically recognise and mount newly connected USB storage devices and display the contents of the device, in this case, in the Nautilus file explorer. The desktop will do this even if the screensaver is already active. When trying to create thumbnails for the files on the device, Nautilus was tricked by a specially crafted DVI file which then activated the exploit. While the relevant hole in the evince thumbnailer was closed in January, the system used in the presentation was kept vulnerable for demonstration purposes. Larimer also disabled the Address Space Layout Randomisation (ASLR) and AppArmor security mechanisms. However, the expert presented measures that would allow potential attackers to bypass these obstacles. The link for this article located at H Security is no longer available. . taking advantage of a mechanism that allows many desktop distributions to automatically recognise an. shmoocon, hacker, conference, security, expert, larimer, ibm's, x-force, demonstrated. . LinuxSecurity.com Team

Calendar%202 Feb 09, 2011 User Avatar LinuxSecurity.com Team Server Security
67

SHA-1 Exploit By Thomas Roth: Cloud Services And Wireless Security

A hacker claims he's used Amazon's cloud services to bust open SHA-1, a wireless network security standard, and he says he'll be demonstrating his process at an upcoming Black Hat get-together. Malicious hackers could quickly set up brute-force attack systems using the cloud, but critics say real-world password cracks might not come so easily.. German hacker Thomas Roth's announcement that he used Amazon.com's (Nasdaq: AMZN) cloud service to crack a wireless network security standard has left some security researchers scratching their heads. Others are merely shaking them in disbelief. That attack was launched against the SHA-1 hash algorithm. Roth's conclusions are that the SHA-1 algorithm is not fit for password hashing, and the compute power offered by cloud services makes it cheap and easy to launch brute-force attacks on passwords. However, it's been known since 2005 that the SHA-1 algorithm has flaws, and the National Institute of Standards and Technology is seeking to replace it. The link for this article located at Tech News World is no longer available. . German hacker Thomas Roth's announcement that he used Amazon.com's (Nasdaq: AMZN) cloud service to c. hacker, claims, amazon's, cloud, services, sha-1, wireless, network, security. . LinuxSecurity.com Team

Calendar%202 Jan 12, 2011 User Avatar LinuxSecurity.com Team Cryptography
83

Exploring Android Backdoor Exploit: Security and Malware Risks

A security expert working at Alert Logic has published a demonstration back door exploit for smartphones running Android. Criminals could use the principles of this exploit to gain control of a phone and install trojans. A potential victim need only call a malicious web site for infection to occur.. The example exploit will open the back door for demonstration purposes only on the fixed IP address 10.0.2.2 on port 2222. Although as it stands, the demo exploit is harmless, for an experienced cracker it would be relatively easy to customise the shellcode to create a malicious version. In a test conducted by The H's associates at heise Security with an HTC Wildfire (Android 2.1), the exploit only caused a browser crash. Officially, the exploit only is only effective on Motorola's Droid 2.0.1, 2.1, and the test was successful on an emulation of 2.0 - 1.2. The link for this article located at H Security is no longer available. . The example exploit will open the back door for demonstration purposes only on the fixed IP address . security, expert, working, alert, logic, published, demonstration, exploit, smartph. . LinuxSecurity.com Team

Calendar%202 Nov 08, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Def Con 2023: Security Risks of GSM Interception Demonstrated

A researcher at the Def Con security conference in Las Vegas demonstrated that he could impersonate a GSM cell tower and intercept mobile phone calls using only $1500 worth of equipment. The cost-effective solution brings mobile phone snooping to the masses, and raises some concerns for mobile phone security. . How does the GSM snooping work? Chris Paget was able to patch together an IMSI (International Mobile Identity Subscriber) catcher device for about $1500. The IMSI catcher can be configured to impersonate a tower from a specific carrier. To GSM-based cell phones in the immediate area--the spoofed cell tower appears to be the strongest signal, so the devices connect to it, enabling the fake tower to intercept outbound calls from the cell phone. What happens to the calls? The link for this article located at Network World is no longer available. . How does the GSM snooping work?Chris Paget was able to patch together an IMSI (International Mobile . researcher, security, conference, vegas, demonstrated, impersonate. . LinuxSecurity.com Team

Calendar%202 Aug 02, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Understanding Security Demos: Addressing Budget and Manager Requirements

A slick security product demonstration only serves to prove that vendors often don't think enough about what security managers need. How much money do you have in your budget? You have to be aware that this is very expensive software." . . . . A slick security product demonstration only serves to prove that vendors often don't think enough about what security managers need. How much money do you have in your budget? You have to be aware that this is very expensive software." Ah, the not-so-sweet sound of the sales pitch. Much of my work as a security manager is like that of a juggler, always keeping balls in the air. My daily goal is to deal with the next falling ball, be it a virus attack, a new e-commerce project or some suspected abuse. This week, however, I was able to lift my gaze for a few days to think about future needs and meet with vendors. And once again, a slick product demonstration showed all too clearly one vendor's fundamental inability to understand our needs. The link for this article located at ComputerWorld is no longer available. . Protective displays frequently neglect the genuine requirements of safety supervisors; financial planning is vital for efficient resources.. Security Product, Vendor Management, Budget Considerations, IT Security Tools. . LinuxSecurity.com Team

Calendar%202 Mar 11, 2003 User Avatar LinuxSecurity.com Team Vendors/Products
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200