Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Two critical security vulnerabilities were found in pgAdmin, the open-source administration tool for PostgreSQL . The vulnerabilities assigned CVE-2024-4216 and CVE-2024-4215 affect the tool's cross-site scripting and multi-factor authentication features. As Linux admins, InfoSec professionals, and security enthusiasts, it is crucial to understand the implications of these vulnerabilities and discuss their long-term consequences for our security practices. . What Is the Impact of These PostgreSQL Flaws? The first vulnerability, CVE-2024-4216, involves a cross-site scripting vulnerability within the "/settings/store" API response JSON payload. The exploit of this vulnerability could allow malicious actors to execute arbitrary scripts on the client side, potentially leading to the theft of sensitive user data. The second vulnerability, CVE-2024-4215, bypasses multi-factor authentication, enabling attackers to gain unauthorized access to the application and perform various actions, such as managing files and executing SQL queries. Exploiting the first vulnerability could enable a threat actor to execute a malicious script on the client end and steal sensitive cookies. To exploit this bug, an attacker must have a legitimate username and password to authenticate into the application. This raises an important question: How vulnerable are the authentication mechanisms of popular open-source tools like pgAdmin? These security vulnerabilities in pgAdmin have several implications for security practitioners: Trust and Reliability: These issues underline the importance of trust and reliability in open-source software . While pgAdmin is widely used and trusted, discovering these vulnerabilities raises concerns about the tool's overall security posture. This prompts security practitioners to re-evaluate their trust in open-source tools, emphasizing the crucial role of regular security assessments. The Human Factor: The multi-factor authentication bypass vulnerability highlights thehuman factor in security. Even with strong authentication mechanisms, attackers can exploit vulnerabilities to gain unauthorized access. This prompts security professionals to examine the effectiveness of multi-factor authentication implementation and consider additional layers of defense. Patch Management: The swift response of the maintainers in releasing necessary patches is commendable; however, this also raises questions about organizations' patch management practices. To mitigate the risk of exploitation, security practitioners must ensure timely patching and stay updated with the latest security advisories for all infrastructure components. In the long term, these pgAdmin vulnerabilities highlight the need for continuous security assessments, threat modeling, and a proactive approach to security. They remind us that even widely used and trusted tools can have critical security flaws that may go undetected until security researchers discover them. Our Final Thoughts on These pgAdmin Bugs As security practitioners, discovering vulnerabilities in widely used tools like pgAdmin should be a wake-up call to reassess our security practices. This discovery emphasizes the importance of trust, reliability, patch management, and the human factor in security. To stay ahead of the ever-evolving threat landscape, Linux admins, InfoSec professionals, and security enthusiasts must adopt a proactive approach, continuously assess their systems for vulnerabilities , and implement robust security measures. By staying vigilant and addressing these issues head-on, we can enhance the security of our systems and protect sensitive data from potential breaches. . Major vulnerabilities identified in pgAdmin emphasize the critical importance of proactive patch management and a thorough review of security protocols.. PostgreSQL Vulnerabilities, pgAdmin Security, Threat Management, Open Source Security. . Anthony Pell
PHPNuke seems to have a horrible security track record, but continues to be quite popular. No statement from the PHPNuke folks yet, but if you're using a rapid site development tool, don't forget to consider the security implications. "Cross site . . . . PHPNuke seems to have a horrible security track record, but continues to be quite popular. No statement from the PHPNuke folks yet, but if you're using a rapid site development tool, don't forget to consider the security implications. "Cross site scripting is a serious problem, (even if some people doesn't believe it), On this second round i'll show 8 new XSS vulnerabilities in PHP Nuke (most of them are also path disclosure vulns):" Date: 23 Apr 2002 09:50:48 +0200 From: "Replugge [ROD]" To:
Recently discovered flaws impacting Linux and Windows users alike could give attackers the highest system privileges. Remediations have been released for a security shortcoming affecting all Linux kernel versions from 2014 that can be exploited by malicious users and malware already deployed on a system to gain root-level privileges. . Microsoft's Windows 10 and the upcoming Windows 11 versions have been found vulnerable to a new local privilege escalation vulnerability that permits users with low-level permissions access Windows system files, in turn, enabling them to unmask the operating system installation password and even decrypt private keys. "Starting with Windows 10 build 1809, non-administrative users are granted access to SAM, SYSTEM, and SECURITY registry hive files," CERT Coordination Center (CERT/CC) said in a vulnerability note published Monday. "This can allow for local privilege escalation (LPE)." The link for this article located at The Hacker News is no longer available. . New vulnerabilities in both Windows and Linux platforms have been discovered, permitting adversaries to escalate privileges. Swift action is essential to mitigate the risks.. Linux Kernel Flaws, Local Privilege Escalation, Windows Vulnerabilities. . Brittany Day
Security flaws in open source software have increased and can take a long time to be added to the National Vulnerability Database, says RiskSense. . Open source software offers certain benefits over commercial products. As the source code is publicly available, developers can modify and tweak OSS applications to enhance their capabilities. Plus, the huge number of people who use these programs serve as a crowdsourced way to test their reliability and security. However, that doesn't mean OSS applications are immune from flaws and vulnerabilities. . The advantages of open source applications are notable, yet they cannot eclipse the dangers arising from increasing vulnerabilities. Acknowledge the threats.. Open Source Risks, Software Security Flaws, Risk Management Practices. . LinuxSecurity.com Team
Are you a Google Chrome user? High-rated security vulnerabilities have already been discovered in version 80 of Google Chrome. The Cybersecurity and Infrastructure Security Agency is encouraging Google users to update again just weeks after the Chrome 80 release. Here’s what you need to know. . Earlier this month, version 80 of the Google Chrome browser was released. A release that caused something of an immediate kerfuffle with warnings that cookie changes could break stuff , and even potential new privacy concerns . But updating to a new version ofChrome brings more than just functionality upgrades, or downgrades depending on your viewpoint: it brings security fixes as well. The link for this article located at Forbes is no longer available. . Mozilla advises Firefox users to upgrade to version 90 due to critical vulnerabilities. Update your browser immediately!. Google Chrome, Browser Security, Chrome Update, Security Flaws. . LinuxSecurity.com Team
Cisco Systems has agreed to pay $8.6 million to settle a lawsuit that accused the company of knowingly selling video surveillance system containing severe security vulnerabilities to the U.S. federal and state government agencies. . It's believed to be the first payout on a 'False Claims Act' case over failure to meet cybersecurity standards. The lawsuit began eight years ago, in the year 2011, when Cisco subcontractor turned whistleblower, James Glenn, accused Cisco of continue selling a video surveillance technology to federal agencies even after knowing that the software was vulnerable to multiple security flaws. The link for this article located at The Hacker News is no longer available. . Cisco is negotiating a settlement concerning allegations that it sold defective video surveillance systems to governmental bodies, despite being aware of their shortcomings.. Cisco Systems, Video Surveillance, Cybersecurity Standards, Security Flaws, Lawsuit Settlement. . Brittany Day
The European Union believes it has a simple way to bolster its digital security: offer lots of cold, hard cash. The European Commission is launching bug bounties in January that will offer prizes in return for spotting security flaws in 14 free, open source software tools EU institutions use. . These include well-known tools like VLC Media Player, KeePass, 7-zip and Drupal as well as something as vital as the GNU C Library. The bounties range from €25,000 to €90,000 (about $28,600 to $102,900) and will start expiring August 15th, 2019, although a few will last until 2020. The link for this article located at Engadget is no longer available. . These include well-known tools like VLC Media Player, KeePass, 7-zip and Drupal as well as something. european, union, believes, simple, bolster, digital, security, offer. . LinuxSecurity.com Team
A House Oversight Committee report out Monday has concluded that Equifax’s security practices and policies were sub-par and its systems were old and out-of-date, and bothering with basic security measures — like patching vulnerable systems — could’ve prevented its massive data breach last year.. It comes a little over a year after Equifax, one of the world’s largest credit rating agencies, confirmed its systems had fallen to hackers. Some 143 million consumers around the world were affected — most of which were in the U.S., but also Canada and the U.K. — with that figure later rising to 148 million consumers. Yet, to date, the company has faced almost no repercussions, despite a string of corporate failings that led to one of the largest data breaches in history. The link for this article located at TechCrunch is no longer available. . The cybersecurity lapses at Equifax resulted in a monumental data leak, highlighting the critical importance of fundamental security protocols.. Data Breach Prevention, Equifax Security Measures, Cybersecurity Oversight, Risk Management Solutions. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.