Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -1 articles for you...
77

Assessing Network Services For Security Risks and Protection Strategies

A network intruder will look for security weaknesses at every point in your network architecture. If you have adequately locked down the Physical, Data Link, Network, and Transport layers of your network, the wily hacker will simply move up to those . . . . A network intruder will look for security weaknesses at every point in your network architecture. If you have adequately locked down the Physical, Data Link, Network, and Transport layers of your network, the wily hacker will simply move up to those protocols and services your network does expose to the Internet. These application-specific protocols are actually much easier to exploit, so many hackers start there and drop down to the Network or Transport level when they need to circumvent a protocol's security mechanisms. In this article, we'll go over each of the most commonly used Internet services, briefly examining each for their weaknesses and abuse potential. First, however, we'll discuss sockets and services ingeneral, identifying typical service vulnerabilities so you can identify potential problems when you need to install services on your own network. In this article, we'll go over each of the most commonly used Internet services, briefly examining each for their weaknesses and abuse potential. First, however, we'll discuss sockets and services ingeneral, identifying typical service vulnerabilities so you can identify potential problems when you need to install services on your own network. Which services are safe to allow through your firewall, which are not safe, and which ones do you do need to keep an eye on? When a new service becomes popular, or when you want to give your network clients a new Internet-based tool, what do you look for when you evaluate the service? Complex services are easier to exploit than simple services. The Echo service, for example, simply transmits back to the client whatever the client sends to it. The Echo service is useful for debugging and for network connectivity testing, but it is difficult to see how the Echoservice could be exploited to gain control of the computer running the service. Since the Echo service accepts data from theclient, however, it must be programmed to correctly handle being fed too much data at once. The link for this article located at LinuxExposed is no longer available. . A cyber attacker will take advantage of vulnerabilities in your system framework. Understand how to safeguard your applications efficiently.. Network Security, Service Assessment, Intrusion Prevention. . LinuxSecurity.com Team

Calendar%202 Aug 01, 2003 User Avatar LinuxSecurity.com Team Server Security
82

Governmentwide Security Report: Addressing Critical Federal Weaknesses

The governmentwide information security report released last month by the Office of Management and Budget is the first serious effort to bring together the executive and legislative branches to solve the monumental job of securing federal systems, which, admittedly, have as many holes as Swiss cheese.. . .. The governmentwide information security report released last month by the Office of Management and Budget is the first serious effort to bring together the executive and legislative branches to solve the monumental job of securing federal systems, which, admittedly, have as many holes as Swiss cheese. The report, required by the Government Information Security Reform Act of 2000, was refreshingly honest. Indeed, many federal systems have serious security weaknesses. But that wasn't the big news laid out in the GISRA report. Rather, the report now organizes secu.rity data into a matrix that the White House and Capitol Hill can use to pinpoint problems and work toward a solution. The report should provide a blueprint for Congress, which, as a whole, has shown that it does not fully understand the shortcomings of federal information security and its consequences. It was just a few years ago, when compiling the Defense Department's fiscal 1999 budget, that the Senate Appropriations Committee nearly zeroed out DOD's $70 million budget to fight information warfare and replaced it with a $500,000 line item for software security research. The budget was later reinstated. Agencies have not been without fault, either. Many are just now putting in place security policies required by the 15-year-old Computer Security Act. The link for this article located at FCW is no longer available. . The governmentwide information security report released last month by the Office of Management and B. governmentwide, information, security, report, released, month, office, management. . Anthony Pell

Calendar%202 Mar 06, 2002 User Avatar Anthony Pell Government
74

Exploring Biometric Access Control Systems: Strengths And Weaknesses

Biometrics have garnered increasing attention and backing in the last few years. We are promised a utopian existence: never again will you forget your password or need to remember your access card to get into the building. Unfortunately, it isn't quite . . . . Biometrics have garnered increasing attention and backing in the last few years. We are promised a utopian existence: never again will you forget your password or need to remember your access card to get into the building. Unfortunately, it isn't quite this simple. While biometrics will be a significant portion of any authentication or identification in the future, they cannot replace many existing security systems without significant disadvantages. Using biometrics in conjunction with other proven security methods can result in a stronger solution; but using biometrics on their own is a very bad idea, for numerous reasons. The link for this article located at Security Portal is no longer available. . Biometric technologies herald a visionary horizon for authentication, yet they cannot completely supplant traditional security measures. Discover further!. Biometric Authentication, Access Control Systems, Secure Identity Management. . Anthony Pell

Calendar%202 Jan 10, 2001 User Avatar Anthony Pell Network Security
74

Exploring Security Scanners' Role in Linux Network Protection

This paper discusses the differnt types of security scanners available for Linux. "A scanner is a program that automatically detects security weaknesses in a remote or localhost.". Scanners are important to Internet security because they reveal weaknesses in the . . .. This paper discusses the differnt types of security scanners available for Linux. "A scanner is a program that automatically detects security weaknesses in a remote or localhost.". Scanners are important to Internet security because they reveal weaknesses in the network. System administrators can strengthen the security of networks by scanning their own networks. The link for this article located at Linux.com --Â Â is no longer available. . This paper discusses the differnt types of security scanners available for Linux. 'A scanner is a pr. paper, discusses, differnt, types, security, scanners, linux, scanner. . Anthony Pell

Calendar%202 May 16, 2000 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200