I’m writing this post because I often hear that kernel exploitation is intimidating or difficult to learn. As a result, I’ve decided to start a series of basic bugs and exercises to get you started! Prerequisites Knowledge of the Linux command line Knowing how to read and write basic C may be beneficial Being able to debug with the help of a virtual computer or another system Able to install the kernel module compilation build requirements A basic understanding of the difference between userland and kernelland could be helpful Having a basic understanding of assembly can be beneficial for future episodes For this part, I wrote a simple Linux character device , /dev/shell . This driver will take two arguments, uid and cmd , and it will execute the cmd command as the specified uid . To understand how this driver works, I’ll explain a few things! . . Dive into the fundamentals of kernel exploitation and enhance your skills with straightforward Linux challenges and practical exercises.. Kernel Exploitation, Linux Challenges, C Programming. . LinuxSecurity.com Team
Hackers are consistently breaching enterprise's systems by going after the end user through the use of things like phishing attacks. Even as security technologies are getting smarter hackers are going after the one thing that hasn't improved: The end users' security knowledge.. Even the major attacks on Apple and Facebook last month started because of a human error. High-value users were sought out by hackers and attacked through clever social engineering.. Enhancing awareness of security protocols is crucial because cybercriminals take advantage of user mistakes in corporate networks.. User Awareness,Cybersecurity Training,Phishing Defense,Security Education. . Alex
The Ethical Hacker Network (EH-Net) is more than a free online magazine for security professionals as it also acts almost like an educational portal for newbies interested in security. Every year like a Christmas tradition, EH-Net features a holiday hacking challenge written by security attack and defense guru Ed Skoudis. The 2010 skills challenge is The Nightmare Before Charlie Brown's Christmas.. Donald Donzal, the man behind The Ethical Hacker Network, said one of the great methods to learn and get involved with the security field is EH-Net's "Skillz H@ack1ng Challenges hosted by Ed Skoudis of SANS and InGuardians. Basically, they are written stories from popular culture that we twist into a hacking scenario with questions for which the contestants have to submit their best answers. It's a fun way of learning practical methods and win signed copies of Ed's book, Counter Hack Reloaded." The link for this article located at Computer World is no longer available. . Participate in the festive cyber skills competition hosted by EH-Net and enhance your security knowledge via engaging scenarios and challenging contests.. Ethical Hacking, Hacking Challenge, Cybersecurity Education. . LinuxSecurity.com Team
Sometimes I hear a story that is simply breathtaking in its stupidity and potential for disaster. For your delectation, horror, and amazement, here is one relayed to me by a good friend a few days ago. He's living in a European country that shall remain unnamed; in addition, the names and some details have been changed to protect the guilty (and the very dumb). It was transmitted to me via Skype, so I've also cleaned up the spelling and punctuation common to IM conversations so that it's more readable. . I've touched on this one before, and I know it seems like common sense to the folks reading this column, but my pal's story sure makes one thing painfully clear: many (most?) "ordinary" users don't understand the concepts of wiping a hard drive securely before relinquishing a computer. It's one thing to drag your personal files to the trash and then empty it - lots of people undoubtedly think that will be enough to protect them. A few more knowledgeable ones understand that trashed files can still be recovered, so they want to remove that sensitive data more completely. This usually means asking a friendly computer nerd for advice or help, or Googling for freeware, or paying for some commercial piece of software that will overwrite data the necessary number of times. (Editor's note: Mac users can use the Secure Empty Trash menu to securely delete files.) A tiny number of people - call them "paranoid security experts" - will go the final step and drill, bash, or bend their hard drives so that the data will be totally unrecoverable. The link for this article located at is no longer available. . Many people fail to understand how crucial it is to thoroughly erase data from devices before disposal, risking dangerous data leaks. Learn effective methods.. User Awareness, Data Protection, Secure Wiping. . LinuxSecurity.com Team
The information security officer for a network of healthcare centers in New York found an employee sending confidential payroll information to a recruiter. A California-based semiconductor manufacturing technology provider caught a worker e-mailing PowerPoint slides detailing product plans to a former colleague at a competitor to show off the "cool things" he was working on. A network administrator for a school district in Indiana nabbed a student trying to finagle school lunch account information stored on an off-limits server. . The link for this article located at Network World is no longer available. . The link for this article located at Network World is no longer available.. information, security, officer, network, healthcare, centers, found, employee. . Benjamin D. Thomas
The European Commission today issued a report that calls for greater education on IT security, and the creation of a common framework for collecting incident data. In its report, the EC states that European spending on IT security "represents only around 5 to 13 percent of IT expenditure, which is alarmingly low." The commission calls for a cross-border effort to educate users about security and to unify disjointed national efforts to track exploits. . The report calls for the EC's European Network and Information Security Agency (ENISA) "to study the feasibility of a European information sharing and alert system to facilitate effective responses to existing and emerging threats to electronic networks." Such a system would require the creation of a multilingual EU portal to provide detailed information on threats, risks, and alerts, the commission said. The link for this article located at www.darkreading.com is no longer available. . The report calls for the EC's European Network and Information Security Agency (ENISA) 'to study the. european, commission, today, issued, report, calls, greater, education, security. . LinuxSecurity.com Team
High-schools students have a message for their parents: Trust us with technology. Security and privacy? We have it covered. A panel of teenagers speaking at the Computers, Freedom and Privacy Conference told attendees on Friday that they are far more in tune with technology than their parents and have come to understand the issues of security and privacy on the Internet largely without any guidance from educators or their parents. . "We don't go over Internet security, we don't go after 'Watch out for that, because your identity can be stolen,'" said Elizabeth, a 16-year-old junior at Seattle Prepatory School. "I don't know that a school should be giving courses in computer ethics, but they should talk about computer security. If you are going to have a computer in the classroom, talk to kids about -- hey, you might see an adult site, that there are Internet predators out there, they exist, you kids need to be careful -- you know, give them the basic education." The link for this article located at is no longer available. . Teenagers urge guardians to have faith in their technological skills, highlighting the importance of learning about digital safety and personal data protection.. High School Security, Internet Privacy, Teen Technology Awareness, Digital Safety, Security Education. . LinuxSecurity.com Team
"We've had a focus on education because we felt if we could demonstrate to the marketplace that we could sit in the wildest of environments, it would demonstrate true security functionality," said DeepNines President Dan Jackson. . . .. "We've had a focus on education because we felt if we could demonstrate to the marketplace that we could sit in the wildest of environments, it would demonstrate true security functionality," said DeepNines President Dan Jackson. "At universities you would not believe the spike in traffic and the spike in malicious traffic when school comes back in service." With their bottom lines and corporate reputations at risk, many security professionals, tired of being able only to react to viruses and worms, are looking for ways to prevent degradation and infection. Worms and viruses cost organizations billions of dollars and hundreds of man-hours. Spam has grown to represent between 60 percent and 70 percent of all e-mail, according to published reports. And even the companies charged with helping businesses secure their networks now are coming under attack. In April, for example, Cisco (Nasdaq: CSCO) warned customers about a hole in its Wireless LAN Solution Engine. The link for this article located at Alison Diana is no longer available. . Uncover key perspectives from Alex Turner on enhancing cybersecurity measures and thwarting illicit attacks across varied settings.. Network Security, Threat Prevention, Security Education. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.