Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
79

Revealing The Misleading Nature Of Lottery Systems And Their Randomness

Srivastava realized that the same logic could be applied to the lottery. The apparent randomness of the scratch ticket was just a facade, a mathematical lie. And this meant that the lottery system might actually be solvable, just like those mining samples. . The link for this article located at Wired is no longer available. . The link for this article located at Wired is no longer available.. srivastava, realized, logic, applied, lottery, apparent, randomness. . LinuxSecurity.com Team

Calendar%202 Feb 10, 2011 User Avatar LinuxSecurity.com Team Security Projects
74

Mitigating SSH Risks: Insights From Malicious Login Analysis

Malicious SSH login attempts have been appearing in some administrators' logs for several years. This article revisits the use of honeypots to analyze malicious SSH login attempts and see what can be learned about this activity. The article then offers recommendations on how to secure one's system against these attacks. Have you ever looked at your ssh logs and notice attackers trying to get in? This article analyses those logs and presents some recommendations to show you how to make your ssh server more secure. . The link for this article located at Securityfocus is no longer available. . The link for this article located at Securityfocus is no longer available.. malicious, login, attempts, appearing, administrators', years. . Bill Locke

Calendar%202 Nov 18, 2008 User Avatar Bill Locke Network Security
78

Using SysReport For Effective Diagnostics In Red Hat Systems

Sysreport is a diagnostic utility. It collects information about the running system, which is used for Red Hat Support to analyze current problems with the system. While sysreport is generally considered non-invasive, diagnostic utilities should always be run with caution. As with all tools such as this, it requires caution. And its good to be aware of these issues, considering that this tool can allow you to make better security decisions. . The link for this article located at Red Hat Magazine is no longer available. . Explore the ways SysReport aids in identifying system issues to facilitate thorough analysis for Red Hat Support.. SysReport, Diagnostic Tool, System Analysis, Red Hat Support. . LinuxSecurity.com Team

Calendar%202 Dec 11, 2007 User Avatar LinuxSecurity.com Team Vendors/Products
78

Critique of Microsoft Baseline Security Analyser for System Weaknesses

Microsoft released the Baseline Security Analyser (MBSA), a free tool which analyses Windows systems for common security misconfigurations, earlier this week. But users have already slammed it as just a GUI version of the software giant's HfNetChk.. . .. Microsoft released the Baseline Security Analyser (MBSA), a free tool which analyses Windows systems for common security misconfigurations, earlier this week. But users have already slammed it as just a GUI version of the software giant's HfNetChk. Since the release last year of Microsoft's command line hot fix network security checker, administrators have clamoured for a release with more functionality. The only alternative to date is a paid-for tool called HFNetChkPro, developed by Microsoft and Shavlik Technologies, which costs $5,000 for a 250-desktop licence. The link for this article located at vnunet is no longer available. . Microsoft introduced the Security Assessment Tool (MSAT), a complimentary application that evaluates Windows environments for potential security weaknesses.. Baseline Security Analyser, Windows security tool, system analysis. . LinuxSecurity.com Team

Calendar%202 Apr 16, 2002 User Avatar LinuxSecurity.com Team Vendors/Products
81

FBI Carnivore Analysis: Internet Surveillance Accountability Concerns

In a 121-page report released Tuesday night by the U.S. Department of Justice, a seven-member review team gave mixed marks to the FBI's Internet surveillance system, known as Carnivore. While the Illinois Institute of Technology Research Institute review team confirmed that . . . . In a 121-page report released Tuesday night by the U.S. Department of Justice, a seven-member review team gave mixed marks to the FBI's Internet surveillance system, known as Carnivore. While the Illinois Institute of Technology Research Institute review team confirmed that the software program can snoop on e-mail communications in a manner limited by a court order, it voiced concern over the lack of any method of assuring that FBI agents don't abuse the system. "(In its analysis,) IITRI did not find adequate provisions -- (for example,) audit trails -- for establishing individual accountability for actions taken during the use of Carnivore," stated the report. The link for this article located at ZDNet is no longer available. . The recent analysis conducted by officials triggers alarms regarding the NSA's XKeyscore monitoring apparatus and its insufficient oversight protocols.. FBI Oversight, Carnivore System, Digital Accountability, Internet Privacy, Surveillance Issues. . LinuxSecurity.com Team

Calendar%202 Nov 22, 2000 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200