Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Ahead of the Linux 6.5-rc2 release tomorrow there was a set of x86/x86_64 kernel changes merged overnight to deal with some weaknesses in the kernel's Control Flow Integrity (kCFI) / FineIBT (Indirect Branch Tracking) code. . Going back to the Linux 6.1 days there has been the kernel Control Flow Integrity code in good shape as a replacement to prior CFI code. Since Linux 6.2 has also been FineIBT as an alternative CFI scheme that uses the compiler-provided kCFI paired with hardware Control-Flow Integrity provided by Intel's Indirect Branch Tracking. These efforts are to thwart control-flow hijacking attacks on the kernel but recently some weaknesses were discovered in the kernel's code. Merged overnight is new code to deal with those weaknesses and part of resolving the weaknesses are rewriting some of the Assembly code into C. The link for this article located at Phoronix is no longer available. . Recent updates to the kernel target vulnerabilities in Control Flow Integrity, enhancing protection against potential threats.. Control Flow Integrity, Linux Kernel Security, Assembly Code Rewrite, Cyber Defense Strategies. . LinuxSecurity.com Team
Security weaknesses in the hugely popular file-sharing Web site thepiratebay.org have exposed the user names, e-mail and Internet addresses of more than 4 million Pirate Bay users, according to information obtained by KrebsOnSecurity.com.. An Argentinian hacker named Ch Russo said he and two of his associates discovered multiple SQL injection vulnerabilities that let them into the user database for the site. Armed with this access, the hackers had the ability to create, delete, modify or view all user information, including the number and name of file trackers or torrents uploaded by users. Russo maintains that at no time did he or his associates alter or delete information in The Pirate Bay database. But he acknowledges that they did briefly consider how much this access and information would be worth to anti-piracy companies employed by entertainment industry lobbying groups like the Recording Industry Association of America (RIAA) and the Motion Picture Association of America (MPAA), each of which has assiduously sought to sink The Pirate Bay on grounds that the network facilitates copyright infringement. The link for this article located at Krebs On Security is no longer available. . An exploit at The Pirate Bay exposes user information as a result of SQL injection flaws, affecting more than 4 million accounts.. Pirate Bay Data Breach, SQL Injection Vulnerabilities, User Security Impact. . LinuxSecurity.com Team
In his green Honda CRV, Jason Kaczor looks like any other commuter navigating his way through Calgary's downtown streets in the early hours of the morning. Few realize he is a participant in a bizarre electronic scavenger hunt known as . . . . In his green Honda CRV, Jason Kaczor looks like any other commuter navigating his way through Calgary's downtown streets in the early hours of the morning. Few realize he is a participant in a bizarre electronic scavenger hunt known as "war driving" -- a real life "game" that exposes companies and consumers who are vulnerable to a mobile hacker attack. "War driving is a worldwide phenomenon and it's gathering steam," says the soft-spoken Kaczor as he manoeuvres through traffic. "Most do it as a hobby. Others do it for illegitimate purposes." War driving derives its name from the 1983 movie War Games. In the film, a teenager played by Matthew Broderick hacks into a missile defence system and narrowly avoids blowing the world to kingdom come during the Cold War. The link for this article located at CalgaryHerald is no longer available. . Driving his sleek blue Subaru Outback, Maria Johnson engages in digital forensics, uncovering vulnerabilities in government networks.. Mobile Hacking, War Driving, Corporate Security, Threat Assessment. . Anthony Pell
Mafiaboy, the Canadian teenager accused of launching a series of distributed denial of service attacks against a septet of the Internet's most popular sites last year, pleaded guilty Thursday to 56 of the 66 charges against him--just before his trial was . . . . Mafiaboy, the Canadian teenager accused of launching a series of distributed denial of service attacks against a septet of the Internet's most popular sites last year, pleaded guilty Thursday to 56 of the 66 charges against him--just before his trial was set to start in a Montreal court. While the action brought to a close one chapter in the DDoS saga of 2000, a year in which seven leading sites were hacked, another more disturbing chapter remains open: the fact that many of the same sites are still virtually powerless to stop such attacks. The link for this article located at ZDNet is no longer available. . Mafiaboy, the Canadian teenager accused of launching a series of distributed denial of service attac. mafiaboy, canadian, teenager, accused, launching, series, distributed, denial, service, attac. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.