Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This is a scary, but true, story about how heavy handed the FBI is willing to be to a data center. Did you know that they can confiscate all of your servers on the suspicion that, while you did nothing wrong, you are inadvertently hosting a hacker? The FBI was simply impatient with the pace of the investigation on-site, so they took all of the servers to their own labs. People who fear the coming of Big Brother should, perhaps, ask themselves if he's here now. . . .. If FBI agents showed up at your data center bearing a warrant, would you be able to provide them prompt access to customer data? How long would it take? That's an important question in the wake of an FBI raid of Columbus, Ohio hosting company CIT Hosting last Saturday. Federal agents wound up shutting down the entire operation, seizing all the company's web servers and all customer data as part of its investigation of a hacking incident. CIT Hosting, also known as FooNet, markets itself as "the leader in the IRC and DDoS protection business for the last 5 years." The company posted a web page informing customers that its data center was shut down, and instructing customers to contact the FBI if they needed access to their files. "The FBI executed a search warrant issued by the United States District Court for the Southern District of Ohio regarding the IRC network that we host," the company said in its statement. IRC (Internet Relay Chat) is a live chat system that allows users to create private discussion rooms. While IRC has a lengthy history of legitimate use, it is also a medium for discreet communication between hackers. CIT said the FBI was "investigating whether someone hosted on our network hacked and attacked someone else." The link for this article located at carrierhotels.com is no longer available. . If FBI agents showed up at your data center bearing a warrant, would you be able to provide them pro. scary, story, about, heavy, handed, willing, center. . LinuxSecurity.com Team
A member of the Debian GNU/Linux system administration team believes there is an unknown local root exploit for the Linux kernel circulating in the wild and says it may have been used to compromise four servers belonging to the free software . . . . A member of the Debian GNU/Linux system administration team believes there is an unknown local root exploit for the Linux kernel circulating in the wild and says it may have been used to compromise four servers belonging to the free software project, after initial unprivileged access was gained by using a sniffed password. Debian is a free operating system which uses the Linux kernel; most of the basic OS tools come from the GNU project hence the name GNU/Linux. The break-in was reported on November 21. An ongoing investigation had shown that a sniffed password was used to initially access the server named klecker, one of four which was compromised, a post to one of the Debian mailing lists, by James Troup, said. Troup said that on November 20, it had been noticed that the kernel on a server called master, which hosts the project's bug tracking system, was doing an oops - something which occurs when the kernel code gets into an unrecoverable state. . The Debian GNU/Linux development group warns of a potential local root vulnerability following a breach of credentials that may have impacted their server infrastructure.. Debian Server Security, Root Exploit Incident, Password Sniffing Attack. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.