Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 16 articles for you...
76

Pwn2Own 2013 Highlights Major Software Failures In Browsers And OS

Over the past few years, the Pwn2Own hacker contest has become an important fixture in the world of testing the security of software applications, operating systems and hardware devices. This year, HP TippingPoint, a sponsor of Pwn2Own, made clear that it was expanding the focus of the competition beyond browsers. . Pwn2own 2013 also includes more than $560,000 in prize money for demonstrations of exploits in the major web browsers, Adobe Reader, Adobe Flash or Oracle Java. And now, with the Pwn2Own contest underway, participants at the Canadian hacking showcase (which is always held in conjunction with the CanSecWest security conference) have found holes in Windows 8, Java and every major browser. Here is more on how the exploits just keep comin'. The link for this article located at OStatic is no longer available. . Pwn2Own 2023 featured a staggering $600,000 in rewards for showcasing vulnerabilities across key systems, encompassing web browsers and operating systems.. Pwn2Own 2013, security exploits, hack contest, browser vulnerabilities. . Anthony Pell

Calendar%202 Mar 08, 2013 User Avatar Anthony Pell Organizations/Events
79

Best Practices For Securing Software Development Lifecycle

Just as software is everywhere, flaws in most of that software are everywhere too. Flaws in software can threaten the security and safety of the very systems on which they operate. The best way to prevent such vulnerabilities in software is to proactively incorporate security and other non-functional requirements into all phases of Software Development Lifecycle (SDLC).. Drawing on the best practices from our book Secure and Resilient Software Development this article summarizes some key activities required for integrating security into your SDLC and offers some recommendations and advice for implementing your own secure software development program. The link for this article located at CSO Online is no longer available. . Strengthen your Software Development Life Cycle (SDLC) by implementing secure software development best practices that proactively address vulnerabilities during development.. Secure Development, Security Integration, SDLC Best Practices. . LinuxSecurity.com Team

Calendar%202 Sep 27, 2010 User Avatar LinuxSecurity.com Team Security Projects
79

Top 25 Programming Errors Impacting IT Security According to SANS

When it comes to programming errors, some are more common than others. A new report from the SANS Institute identifies the top 25 programming errors that have led to nearly every type of IT security threat over the last year. The report draws on the input of 28 different groups including those in government and the private sector and leverages the CWE (Common Weakness Enumeration) numbering system to label vulnerabilities.. The report follows one done by SANS on the same topic for 2009, and provides similar findings this time around. But while the SANS lists attempt to identify the top programming errors, there is some disagreement when it comes to the top programming errors that Linux developers face. "The takeaway from this list isn't so much that there is anything here that is particularly new or surprising at all," Alex Horan, director of product management at Core Security, said in a e-mail to InternetNews.com. "In fact, what it reinforces is that most organizations, and software/Web app developers, continue to struggle with the same types of security issues that they've been dealing with for years." The 2010 SANS list is structured differently than the 2009 list which provided the top 25 in a list broken down by three categories. For 2010, SANS has also provided a general ranking of the top 25 with Cross Site Scripting (XSS) The link for this article located at CodeGuru is no longer available. . Highlighting the top programming errors from SANS Institute's latest report and their impact on IT security.. programming errors, IT security, software vulnerabilities, SANS report. . LinuxSecurity.com Team

Calendar%202 Feb 19, 2010 User Avatar LinuxSecurity.com Team Security Projects
79

Alcotest 7110 MKIII-C Advisory: Significant Software Flaws Uncovered

This is an excellent lesson in the security problems inherent in trusting proprietary software: After two years of attempting to get the computer based source code for the Alcotest 7110 MKIII-C, defense counsel in State v. Chun were successful in obtaining the code, and had it analyzed by Base One Technologies, Inc. Draeger, the manufacturer maintained that the system was perfect, and that revealing the source code would be damaging to its business. They were right about the second part, of course, because it turned out that the code was terrible.. The link for this article located at is no longer available. . The link for this article located at is no longer available.. excellent, lesson, security, problems, inherent, trusting, proprietary, software. . LinuxSecurity.com Team

Calendar%202 May 14, 2009 User Avatar LinuxSecurity.com Team Security Projects
78

Investigating Software Flaws in Forensics: Insights from DefCon

Those of you familiar with CSI (or have surely heard of it) are all too familiar with the process they use to catch the criminals - scientific analysis, forensics, gadgetry, and smarmy head investigators. Reoccurring themes include DNA analysis or other types of human-related evidence. However, in the information world, catching a criminal after the crime is in another league of its own. This article presents an account of a recent DefCon presentation which focused on breaking the actual forensics software used to analyze compromised systems. The most interesting line in the article referred to the weaknesses in one of the most popular forensics tools - "Most of these can and will be fixed in the near future, but at least one is a design flaw, not a bug.". Read on to find out how your forensics tools are only as good as the makers of them, and how it can result in a perfect getaway. . The link for this article located at The Inquirer is no longer available. . Disruption in forensic software can severely affect digital investigations. If data recovery tools fail, it risks the integrity of evidence, leading to errors and misjudgments. Forensics Tools, Security Analysis, Digital Forensics, Cybersecurity Techniques, Software Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Aug 10, 2007 User Avatar LinuxSecurity.com Team Vendors/Products
83

Exploring the Rise of Bug Bounties and Vulnerability Sales in Security

The co-founder of security group Secure Network Operations Software (SNOSoft), Desautels has claimed to have brokered a number of deals between researchers and private firms--as well as the odd government agency--for information on critical flaws in software. Last week, he bluntly told members of SecurityFocus's BugTraq mailing list and the Full-Disclosure mailing list that he could sell significant flaw research, in many cases, for more than $75,000. "I've seen these exploits sell for as much as $120,000," Desautels told SecurityFocus in an online interview. It's a statement that underscores the increasing acceptance of the sale of vulnerability information. Once a frowned-upon practice, the sale of such information is taking off. Flaw bounty programs such as TippingPoint's Zero-Day Initiative (ZDI) and iDefense's Vulnerability Contributor Program (VCP) have added legitimacy to the practice, even if they remain controversial. Software vendors have had to increasingly get used to dealing with third parties reporting security flaws that were bought from anonymous researchers. Microsoft, for example, patched at least 17 flaws reported by the two programs in 2006, up from 11 reported in 2005. . Desautels, now the chief technology officer for boutique security firm Netragard, highlighted the trend by announcing a program on Wednesday whereby the security company would act as a broker to any researcher with a critical flaw to sell. The program could be a more lucrative option for freelance researchers aiming to sell information on software vulnerabilities. In many ways, the push by researchers for greater returns on their research efforts is part of the ebb and flow of the debate over the proper way to disclose information about software vulnerabilities. In 2000, a researcher known as Rain Forest Puppy released a basic framework, dubbed the RFPolicy, for disclosing vulnerabilities in a way that seemed fair to responsible software makers. In 2002, two security researchers further refined the guidelinesand submitted them to the Internet Engineering Task Force (IETF), but the technical standards body decided that setting disclosure policy was outside of its jurisdiction. Over the past few years, software makers, and Microsoft in particular, have focused on holding researchers to the guidelines, calling such disclosure "responsible." It's been an uneasy truce, and one that has fractured in many places. In 2005, a researcher attempted to auction off information about a flaw in Microsoft Office. Other flaw finders have decided to just release details of vulnerabilities they have found as a punishment for, what they believe to be, irresponsible behavior on the part of the software vendor. In the last six months, for example, a number of researchers have collected advisories on potential security issues into month-long releases of daily bugs. The trend started with the Month of Browser Bugs in July and continues with the latest Month of Apple Bugs this month. Now, flaw finders fed up with software vendors are increasingly turning to third parties to buy their research. "One of the reasons why the hacking community is so frustrated with large corporations is because these corporations are making a killing off their research and they are not seeing fair value for their work," Desautels said in an online interview with SecurityFocus. Software makers typically do not pay for vulnerability information, with the notable exception of the Mozilla Foundation. The well-known public bounty programs typically pay thousands of dollars for original vulnerabilities, while lesser-known private deals can net a researcher tens of thousands of dollars, according to security experts. The amounts quoted by Desautels are not excessive, according to experts interviewed by SecurityFocus. In September, for example, a private buyer approached noted security researcher HD Moore and offered between $60,000 and $120,000 for each client side vulnerability found in Internet Explorer, the founder of the Metasploit Projectsaid. Moore declined to pursue the offer, but said that such prices are typical of high-level private purchases, while information on serious flaws in generic enterprise-level applications can be sold to safe buyers--such as 3Com's ZDI program and VeriSign's VCP program--for between $5,000 and $10,000. "The ZDI and (VCP) programs are definitely the easier way to sell a vulnerability, but at the 5x or 10x multipliers you see from a private buyer, it's usually worth the effort," Moore told SecurityFocus in an e-mail interview The link for this article located at Security Focus is no longer available. . Emerging patterns indicate increased rewards for tech flaws, mirroring shifts in the ways experts exchange data.. Bug Bounty Programs, Exploit Trading, Vulnerability Economics. . LinuxSecurity.com Team

Calendar%202 Jan 24, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Sendmail Security Flaws: A Historical Overview and Context

As far as software goes, Sendmail is ancient, dating all the way back to 1981. Sendmail 8 itself is well over 10 years-old. To put it nicely, its security track record is less than stellar. However, the last big show stoppers in Sendmail were found about three years ago – Zalewski's prescan() bugs reported in September and March of 2003, and crackaddr(), also in March of 2003. The crackaddr() bug was also discovered by Mark Dowd. . The link for this article located at TheRegister.co.uk is no longer available. . Sendmail, once a leader in email transfer, now faces significant vulnerabilities and inefficiencies due to its outdated architecture and antiquated design practices. Sendmail Software, Email Security, Protocol Flaws, Security Issues. . LinuxSecurity.com Team

Calendar%202 May 11, 2006 User Avatar LinuxSecurity.com Team Server Security
77

Linux Advisory: Critical Gaim Client And LibTiff Flaws Exploited

Linux vendors have been hit by two fresh security bugs, affecting a widely used graphics decoder and the Gaim instant-messaging client. . . .. Linux vendors have been hit by two fresh security bugs, affecting a widely used graphics decoder and the Gaim instant-messaging client. Separately, Red Hat, the biggest Linux developer, said attackers have begun targeting Red Hat users with an email-based scam similar to methods commonly used to target Windows. The flaws in Gaim and libtiff, used by many Linux graphics programs to decode tiff images, follow a series of serious bugs patched last week. The earlier flaws affected Linux's libpng, Xpdf and Cups components. The link for this article located at Matthew Broersma is no longer available. . Multiple Linux distributions encounter new vulnerabilities in a popular video compression library and the Gaim instant messaging client, worsened by phishing schemes targeting email users.. Gaim Client Bugs, Red Hat Vulnerabilities, Graphics Decoder Issues. . LinuxSecurity.com Team

Calendar%202 Oct 25, 2004 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200