Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
77

Protecting Against Man-In-The-Middle Attacks in SSL VPNs

Your Secure Sockets Layer (SSL) VPN still may not be as secure as you think, especially if your users don't always access the network via corporate-issue laptops. Once they jump on an outside machine to Web browse or check their email, SSL VPN users can leave behind sensitive data or be vulnerable to man-in-the-middle attacks and keystroke loggers, experts say. An infected kiosk can infect your network, too. So even though they may be more convenient than their IPSec counterparts (SSL can be used by browsers anywhere without client software) these VPNs can also backfire if you're not careful in how you deploy them. . SSL VPNs are popular among enterprises that don't have the IT resources to support the administratively-heavy IPSec VPNs, which require client software. Unlike IPSec, which uses digital certifications on both the server and client side, SSL VPNs mostly use certs only on the server side. "With SSL mostly being done in this one-way mode, it opens you up to a man-in-the-middle" attack, says John Pescatore, a vice president with Gartner. SSL VPN products have come a long way in the past year. Many come with features to prevent downloading files or ActiveX or Java applets, for instance, Pescatore observes. The link for this article located at Dark Reading is no longer available. . SSL VPNs provide flexible remote access but come with security risks like man-in-the-middle attacks and data exposure on unsecured devices, necessitating stringent protocols.. SSL VPN, Remote Access Threats, Data Exposure Risks, Network Security Issues. . LinuxSecurity.com Team

Calendar%202 Aug 30, 2006 User Avatar LinuxSecurity.com Team Server Security
74

SSL VPN Technology: Secure Access for Corporate Applications

Secure Sockets Layer (SSL) for remote access is based on a simple concept: use the encryption and authentication capabilities built into every Web browser to provide secure remote access to corporate applications. By combining SSL-enabled Web brow- sers with a secure gateway to terminate connections and provide policy enforcement and access control, so-called SSL VPNs provide access to Web-based, legacy client/server, and terminal applications from anywhere-home PCs, hotel business centers, Internet cafes, or a business partner's LAN-without an IPSec VPN client. It's one of those ideas that make you say "Why didn't I think of that?" . The companies that did think of it are now working very hard to turn that idea into market share. Regardless of which brand wins the biggest piece of the pie graph, here's why the idea is a good one: The link for this article located at IT Architect is no longer available. . SSL VPNs have revolutionized remote access to corporate apps by using strong encryption to keep data secure, enabling employees to connect safely from anywhere.. SSL VPN, Remote Access Security, Corporate Application Security. . Benjamin D. Thomas

Calendar%202 Nov 28, 2005 User Avatar Benjamin D. Thomas Network Security
78

F5 FirePass Controller: New SSL VPN Enhancements For Secure Access

New FirePass(R) product eclipses the competition with extensive new features for enhanced security, reliability, management and FIPS-enabled high performance platform . . .. SEATTLE --(Business Wire)-- Oct. 4, 2004 -- New FirePass(R) product eclipses the competition with extensive new features for enhanced security, reliability, management and FIPS-enabled high performance platform F5 Networks, Inc. (Nasdaq:FFIV), the global leader of Application Traffic Management products, today announced a powerful new version of its best-in-class FirePass(R) Controller -- a Secure Sockets Layer Virtual Private Network (SSL VPN) solution. With this release, F5 sets a new standard for secure remote access solutions and leapfrogs the competition, offering: (1) ubiquitous secure application access; (2) simplified and scalable management; (3) the most advanced application security; and (4) new enterprise class hardware. The FirePass Controller is an essential component of F5's security product roadmap, which is designed to help enable enterprise organizations achieve end-to-end application level security. The link for this article located at TMCNet is no longer available. . F5 announces the launch of FirePass(R), the premier SSL VPN solution, delivering elevated secure remote connectivity through innovative functionalities.. SSL VPN, Remote Access Solutions, F5, FirePass Controller, Enhanced Security. . LinuxSecurity.com Team

Calendar%202 Oct 04, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
74

Exploring SSL VPN Benefits for Secure Remote Access with AEP Systems VP

In this 6:30 minutes long audio learning session, Rob Lane, AEP Systems VP of Product Management, discusses SSL VPNs in general, shares his point of view on the benefits of using SSL VPNs for secure remote access and talks about the difference between SSL and IPSec VPNs. . . .. Secure Sockets Layer (SSL) Virtual Private Networks are quickly gaining popularity as serious contenders in the remote-access marketplace. Analysts predict that products based on SSL VPN technology will rival - or even replace - IP Security Protocol (IPSec) VPNs as remote-access solutions. In this 6:30 minutes long audio learning session, Rob Lane, AEP Systems VP of Product Management, discusses SSL VPNs in general, shares his point of view on the benefits of using SSL VPNs for secure remote access and talks about the difference between SSL and IPSec VPNs. The link for this article located at net-security.org is no longer available. . Secure Sockets Layer (SSL) Virtual Private Networks are quickly gaining popularity as serious conten. minutes, audio, learning, session, systems, product, management. . Anthony Pell

Calendar%202 Jun 23, 2004 User Avatar Anthony Pell Network Security
74

SSL VPN Implementation at Sydney Adventist Hospital for Secure Data Access

When more and more doctors started asking for access to patients' test results online, Sydney Adventist Hospital explored alternatives to some of the solutions being used elsewhere in healthcare. The hospital's first priority was to keep patients' health information secure and . . . . When more and more doctors started asking for access to patients' test results online, Sydney Adventist Hospital explored alternatives to some of the solutions being used elsewhere in healthcare. The hospital's first priority was to keep patients' health information secure and confidential while still providing the service the doctors were demanding. And, like anywhere else in the healthcare industry, it was important to keep IT costs down. The hospital's tech partner and integrator, Emerging Systems, teamed with Nortel Networks to come up with a slightly left-of-field but secure, low maintenance and lower cost option for the hospital -- a secure sockets layer virtual private network. Already widely used in e-commerce and the financial sector, SSL VPNs have been called the "de facto standard" for securing credit card transactions and online banking. The SSL protocol was developed by Netscape in 1994 as a security mechanism built into the Navigator browser. The link for this article located at iTNews is no longer available. . Sydney Adventist Hospital upgraded patient care with an SSL VPN for secure remote access, protecting sensitive health data while improving healthcare efficiency. SSL VPN, Healthcare Security, Patient Data Protection. . Anthony Pell

Calendar%202 Dec 05, 2003 User Avatar Anthony Pell Network Security
78

Exploring SSL VPN Solutions For Enhanced Corporate Network Security

The market is heating up for products that allow secure access to corporate networks based on a widely used browser security technology known as secure sockets layer encryption. Cisco Systems became the latest company to introduce a virtual private network (VPN) . . . . The market is heating up for products that allow secure access to corporate networks based on a widely used browser security technology known as secure sockets layer encryption. Cisco Systems became the latest company to introduce a virtual private network (VPN) product based on secure sockets layer (SSL) encryption when it announced on Monday that it would add the feature to its 3000 series of network concentrators. The hardware devices act as a single access point into corporate networks and give telecommuters and branch offices a secure connection to internal networks. The link for this article located at News.com is no longer available. . The market is heating up for products that allow secure access to corporate networks based on a wide. market, heating, products, allow, secure, corporate, networks, based. . LinuxSecurity.com Team

Calendar%202 Nov 12, 2003 User Avatar LinuxSecurity.com Team Vendors/Products
74

Secure Application Communication Using SSL-VPN Technology

According to Johna Johnson, president and chief research officer at Nemertes Research, SSL defines a secure, encrypted communications mechanism between applications, most commonly between a web browser and server, and is independent of the underlying protocols, particularly IP (see also page . . . . According to Johna Johnson, president and chief research officer at Nemertes Research, SSL defines a secure, encrypted communications mechanism between applications, most commonly between a web browser and server, and is independent of the underlying protocols, particularly IP (see also page 14: The next-generation VPN). IPSec, on the other hand, provides a secure, encrypted communications mechanism at the IP layer. It is independent of the application, meaning that any application that uses IP can run across it, she explained. SSL-VPNs are a growing market segment. According to Infonetics Research, this new market is expected to exceed US$600 million in sales by 2006. The link for this article located at ComputerWorld is no longer available. . SSL, or Secure Sockets Layer, is essential for securing online communications by creating an encrypted link between clients and servers preventing data breaches. SSL VPN, Encrypted Communication, Network Security, Application Security, VPN Technology. . Anthony Pell

Calendar%202 Oct 22, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200