Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Palamida, an open-source risk management company, believes in open source. But at the same time, its corporate code audits of more than 500 million lines of code has found time and again "specific open-source projects inside mission critical systems that had not been patched" with most recent updates. Read on for an interesting account of what happens when you don't keep up with the times. A great point Palamida gets across is the fact that even though you are using a great open source tool does not substitute not keeping it up to date.. The link for this article located at Linux Watch is no longer available. . The link for this article located at Linux Watch is no longer available.. palamida, open-source, management, company, believes, source. . LinuxSecurity.com Team
Security and vulnerability patching has become one of the top concerns for IT managers, but has also left many IT teams fighting a losing battle as the job of patching competes with day-to-day system maintenance and security tasks. . The patching issue became a more prominent problem for businesses worldwide in 2003 when the Slammer worm was unleashed on the Internet. In the first minute after it started spreading, Slammer doubled the number of web servers it infected every eight seconds. Within 10 minutes, 90% of all vulnerable machines had been infected – leaving businesses with a £500m bill to fix the havoc Slammer created. Yet the patch to fix the vulnerability that Slammer exploited had been available for six months. If the majority of those infected had patched their systems, Slammer would have been a minor blip. So why aren’t businesses catching on to patching? The bottom line is that many IT teams simply do not have the resources or time. Just researching the 4,000+ vulnerabilities published by security monitoring body CERT in the last year would demand hundreds of man-hours. And although an IT staff may be online regularly to see what patches are released, they cannot be 100 percent sure that all systems are properly patched. Then there’s the cost issue. Recent research from analysts at The Yankee Group found that it can cost as much as $1 million to manually deploy a single patch in a 1,000-node network environment. The costs include the manual labour involved in fixing problems and system downtime while patches are being applied. The link for this article located at Security Park is no longer available. . Updating software consistently poses significant challenges for IT departments; financial constraints and limited manpower obstruct prompt remediation of at-risk platforms.. Patch Management,Vulnerability Updates,Resource Allocation. . LinuxSecurity.com Team
Brian Hatch, author of Hacking Linux Exposed, wrote in to point out his step-by-step guide for safely upgrading OpenSSH. "Most folks don't realize that you can kill off the sshd server process (the one that forks off copies to handle incoming connections) without killing off any existing connections.. . .. Brian Hatch, author of Hacking Linux Exposed, wrote in to point out his step-by-step guide for safely upgrading OpenSSH. "Most folks don't realize that you can kill off the sshd server process (the one that forks off copies to handle incoming connections) without killing off any existing connections. That means you can log in, kill off the server process, and still work on the system until you log out. Instead, most folks think you need to upgrade and reboot so the changes take effect. This is not the case. However, if you don't take a few precautions, then you could find yourself in the unfortunate situation where you've killed the old process and accidentally logged out (or, more likely, kill all sshd processes) before starting the new daemon. . Upgrading OpenSSH remotely without downtime or losing connections is possible with thorough planning. Follow this guide for a seamless upgrade process. OpenSSH Upgrade, Remote Administration, Linux Server. . LinuxSecurity.com Team
This Microsoft article does a good job of outlining a list of security issues that no patch can fix. Only dilligence in maintaining your systems can ensure you're systems are as secure as possible. "In other cases, the reported problems simply . . . . This Microsoft article does a good job of outlining a list of security issues that no patch can fix. Only dilligence in maintaining your systems can ensure you're systems are as secure as possible. "In other cases, the reported problems simply result from a mistake someone made in using the product. But many fall in between. They discuss real security problems, but the problems don't result from product flaws. Over the years, we've developed a list of issues like these, that we call the Ten Immutable Laws of Security. Don't hold your breath waiting for a patch that will protect you from the issues we'll discuss below. It isn't possible for Microsoft - or any software vendor - to "fix" them, because they result from the way computers work. But don't abandon all hope yet - sound judgment is the key to protecting yourself against these issues, and if you keep them in mind, you can significantly improve the security of your systems." The link for this article located at Microsoft.com [newsforge] is no longer available. . Implement the principle of least privilege to ensure users have only necessary access, greatly reducing breach damage potential. Immutable Laws, Security Practices, System Maintenance, Risk Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.