Thanks to Ars Technica and H-online.com, we now have intimate details of the Anonymous attack against security research company HBGary. There are no surprises in how the attacks where carried out, but we can draw many morals from the story, even if we've heard them time and time before.. Here's an executive summary of how the attack was carried out, and how you can defend against the same things happening to your systems. 1. Use Off-the-Shelf Software HBGary Federal's Website ran a content management system (CMS) that was created especially for the company. There's a debate to be had as to whether off-the-shelf software is more secure that custom-made solutions. On the one hand, exploits for off-the-shelf solutions are often published far and wide and, in the case of a zero-day exploit, can leave system administrators rushing to fix their systems as quickly as possible. The link for this article located at PC World is no longer available. . The 2011 HBGary hack highlighted critical cybersecurity insights, emphasizing robust password management and ongoing employee training for threat awareness.. HBGary Hack,Cybersecurity Insights,System Protection,Security Practices. . LinuxSecurity.com Team
Like computers themselves, the Cyber Challenge is simple on the outside and complicated on the inside. The first round of the game began in June, and winners of the earlier games were brought to Washington to compete in NetWars.. In its simplest form, NetWars is an online version of Capture the Flag, with competitors vying to penetrate and take control of target computer systems and then protect them from other intruders. The game begins when a player downloads an image and must find a hidden key within the image. They use that key to enter an online environment and use their knowledge of security vulnerabilities to exploit its system, leaving their name or "handle" in various areas. A moderator threw a series of computer hurdles and roadblocks to further challenge the hackers and test their knowledge about computer vulnerabilities. NetWars differs from other Capture the Flag competitions in that it also rewards hackers for defending computers, said Josh Gimer, 22, a graduate student at Colorado Tech. He likens it more to King of the Hill. The link for this article located at CNN is no longer available. . CyberQuest is an exciting virtual Escape Room adventure that evaluates participants on their skills in breaching systems and protection strategies.. Cyber Challenge, Hacker Competition, NetWars, System Exploitation, Online Skills. . LinuxSecurity.com Team
This article takes a look at a little shell application that uses an innovative approach to increasing open UNIX security. A step-by-step analysis of the code is provided. The author's areas of expertise are in Web programming and cutting-edge network security development.. . .. This article takes a look at a little shell application that uses an innovative approach to increasing open UNIX security. A step-by-step analysis of the code is provided. The author's areas of expertise are in Web programming and cutting-edge network security development. A malicious user crippling a system and getting superuser rights is a nightmare for any system administrator. In defense of open UNIX platforms, the following small shell application we're going to look at will put another brick into the open UNIX security barrier. The open UNIX operating systems FreeBSD and Linux Mandrake both have integrated shell security systems. The FreeBSD program is located in /etc/security. The Mandrake Security Package for Linux can be found in /usr/share/msec. These standard tools are similar in functionality, but they limit the file system integrity control to files with SUID and SGID flags. But Mandrake calculates MD5 file checksums differently from FreeBSD. The link for this article located at IBM developerWorks is no longer available. . Discover a UNIX security utility designed to strengthen open systems through innovative code assessments and techniques that prioritize security best practices. Open Unix Security, Shell Application, System Defense, Network Security. . LinuxSecurity.com Team
DoS and DDoS (denial-of-service and distributed denial-of-service) attacks, which prevent legitimate users from accessing and using a site or particular service, have become a growing concern as more and more businesses move onto the Internet. Last year, retail giant Amazon.com, electronic . . . . DoS and DDoS (denial-of-service and distributed denial-of-service) attacks, which prevent legitimate users from accessing and using a site or particular service, have become a growing concern as more and more businesses move onto the Internet. Last year, retail giant Amazon.com, electronic auction house eBay, discount retailer Buy.com, CNN Interactive, and the portal Yahoo! made headlines when they were the recipients of these attacks, and now smaller businesses are beginning to recognize the dangers these attacks pose, too. Until managed availability monitors have been perfected, site owners need to take specific steps to ensure their systems are protected from DoS/DDoS attacks. In seeking to prevent DoS/DDoS attacks, every Web site has four areas of vulnerability: the gateway, the host, hardware/software, and personnel. The following recommendations address these four areas The link for this article located at Symantec is no longer available. . Implementing advanced traffic monitoring and analyzing tools can rapidly respond to DDoS attacks by identifying anomalies in network traffic patterns. DoS Security,DDoS Defense,Network Threat Mitigation,Online Business Protection. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.