Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
SSLyze is a Python tool that can analyze the SSL configuration of a server by connecting to it. It is designed to be fast and comprehensive, and should help organizations and testers identify misconfigurations affecting their SSL servers.. The link for this article located at Darknet is no longer available. . SSLyze is a robust Python utility for assessing the security of SSL/TLS configurations on servers, revealing vulnerabilities and misconfigurations to enhance security. SSLyze, Python Tool, Server Assessment, SSL Security, SSL Analysis. . LinuxSecurity.com Team
Security researchers have discovered a "timing attack" that creates a possible mechanism for a hacker to extract the secret key of a TLS/SSL server that uses elliptic curve cryptography (ECC).. Elliptic curve cryptography is a type of public-key algorithm that uses the maths of elliptic curves rather than integer factorisation, which is used by RSA as a one-way function. By using ECC it is possible to provide equivalent levels of difficulty for a brute-force attack as can be provided by the more familiar integer-factorisation approaches, but using smaller key lengths. The approach has benefits for mobile and low-power systems. The link for this article located at The Register UK is no longer available. . New vulnerabilities in ECC raise concerns about SSL security; highlights the need for robust cryptographic measures.. Timing Attack, SSL Security, ECC Cryptography, Key Exposure. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.