Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A new Linux malware , GTPDOOR, specifically designed to target telecom networks connected to GPRS roaming exchanges (GRX), has emerged. This malware stands out because it utilizes the GPRS Tunnelling Protocol (GTP) for command-and-control (C2) communications. . The implications of this discovery are significant for Linux admins, infosec professionals, internet security enthusiasts, and sysadmins who work with telecom networks. How Does GTPDOOR Malware Work? What Are the Security Implications for Linux Users? GTPDOOR is believed to be linked to the threat actor LightBasin. The malware disguises itself as syslog and opens a raw socket, enabling it to receive UDP messages and execute commands on infected machines. Furthermore, the malware can be probed covertly from an external network, eliciting a response that reveals if the destination port on the host is open or responding. The presence of GTPDOOR raises intriguing questions and concerns. As Linux admins and information security professionals, we must consider the potential long-term consequences of such malware targeting telecom networks. How can we effectively detect and mitigate this threat? Are current security measures in telecom networks sufficient to protect against advanced malware like GTPDOOR? Additionally, we need to explore the possibility of similar malware emerging that could exploit other protocols within the telecom infrastructure. The impact on security practitioners is significant. Their role in safeguarding telecom networks becomes even more crucial as sophisticated malware like GTPDOOR evolves. They must keep up with the latest security practices , including regularly patching and updating software , conducting network vulnerability assessments, and implementing robust intrusion detection and prevention systems. Additionally, security practitioners should collaborate with telecom providers to share threat intelligence and develop effective mitigation strategies. Our Final Thoughts on GTPDOOR Linux Malware Theemergence of GTPDOOR Linux malware targeting telecom networks through GPRS roaming networks raises serious concerns for security practitioners. Using GTP for command-and-control communications presents a new challenge for Linux admins, infosec professionals, internet security enthusiasts, and sysadmins. It is imperative to critically analyze the implications of such malware and take appropriate measures to protect telecom networks from long-term consequences. By staying proactive, collaborating, and continuously updating security practices, security practitioners can effectively combat the threat posed by GTPDOOR and other evolving malware in the future. . The rise of JXPKEY Windows trojans signifies a major risk to financial institutions, demanding immediate action from security teams.. Linux Malware,GTPDOOR,Telecom Security,Vulnerability Management. . Anthony Pell
Huawei can covertly access mobile networks through back doors meant for law enforcement, the U.S. has told allies in a bid to show that the firm poses a security threat. . U.S. officials say Huawei Technologies Co. can covertly access mobile-phone networks around the world through “back doors” designed for use by law enforcement, as Washington tries to persuade allies to exclude the Chinese company from their networks. The link for this article located at The Wall Street Journal is no longer available. . U.S. officials warn Huawei can secretly access global mobile networks through back doors intended for law enforcement.. huawei, covertly, mobile, networks, through, doors, meant, enforcement. . LinuxSecurity.com Team
T-Mobile today confirmed that the telecom giant suffered a security breach on its US servers on August 20 that may have resulted in the leak of "some" personal information of up to 2 million T-Mobile customers.. The leaked information includes customers' name, billing zip code, phone number, email address, account number, and account type (prepaid or postpaid). The link for this article located at The Hacker News is no longer available. . T-Mobile confirmed a security breach exposing personal information of 2 million customers including names and accounts.. T-Mobile Hack, Customer Data Theft, Data Breach, Telecom Security. . LinuxSecurity.com Team
How easy is it for the average internet user to make a phone call secure enough to frustrate the NSA's extrajudicial surveillance program? Wired News took Phil Zimmermann's newest encryption software, Zfone, for a test drive and found it's actually quite easy, even if the program is still in beta. Zimmermann, the man who released the PGP e-mail encryption program to the world in 1991 -- only to face an abortive criminal prosecution from the government -- has been trying for 10 years to give the world easy-to-use software to cloak internet phone calls. . The link for this article located at Wired.com is no longer available. . The link for this article located at Wired.com is no longer available.. average, internet, phone, secure, enough, frustrate. . LinuxSecurity.com Team
Telecommunications companies spend as much as $8 billion a year fixing phones with programming errors, faulty mechanics and other problems. Now some are scrambling to prevent virus attacks that could cost carriers millions of dollars more in repairs and lost business.. . .. Telecommunications companies spend as much as $8 billion a year fixing phones with programming errors, faulty mechanics and other problems. Now some are scrambling to prevent virus attacks that could cost carriers millions of dollars more in repairs and lost business. As more consumers begin surfing the Web and sending e-mail messages on cellphones and handheld devices, along comes a new worry: worms and viruses spread via Internet-enabled equipment. The problem is still small, with only a few cases reported globally so far. But as operating systems in cellphones become standardized, hackers are likely to begin focusing on vulnerabilities in those systems as they have with personal computers. And as cellphones and personal digital assistants connect to the Internet at ever faster speeds, more users will be able to download files with attachments, some of which may be infected. Asia, where high-speed networks and text messaging on mobile phones are common, is the most vulnerable to these threats. As carriers in Europe and North America adopt similar technology , they will confront similar hazards. The link for this article located at TechNewsWorld is no longer available. . Mobile network providers invest up to $8 billion annually to rectify devices affected by software bugs and emerging security vulnerabilities.. Telecommunications Security, Mobile Malware, Network Safety. . Anthony Pell
Voicemail passwords are being transformed into all-access backstage passes that allow malicious hackers to exploit voicemail systems, racking up huge charges on their unlucky victims' phone bills.. . .. Voicemail passwords are being transformed into all-access backstage passes that allow malicious hackers to exploit voicemail systems, racking up huge charges on their unlucky victims' phone bills. Hackers are exploiting a combination of automated operator services from AT&T, voicemail services from SBC Communications and consumers who haven't changed their default voicemail passwords. Victims say that AT&T and SBC know about the scam and are taking no concrete action to protect consumers from it. But AT&T spokesman Gordon Diamond said that AT&T has been instrumental in stopping the scam. The link for this article located at Wired is no longer available. . Voicemail passwords are being transformed into all-access backstage passes that allow malicious hack. voicemail, passwords, being, transformed, all-access, backstage, passes, allow, malicious. . LinuxSecurity.com Team
Although most companies today have improved security on their data networks, thus cutting down on white-collar crime and hack attacks, too few have paid enough attention to their PBX system. The PBX remains a potentially huge back door problem for data . . . . Although most companies today have improved security on their data networks, thus cutting down on white-collar crime and hack attacks, too few have paid enough attention to their PBX system. The PBX remains a potentially huge back door problem for data network security. "Many corporates have implemented firewalls as well as stringent anti-virus and content filtering applications to reduce attack and fraud," says John van den Munckhof, managing director of Dimension Data Interactive Communications. "The PBX, however, remains a significant loophole. All the perimeter security in the world can be bypassed by a poorly configured authorised or unauthorised modem." Indeed, as a leading communications publication puts it: "If you want to do real damage to a business or institution, telecom infrastructure is probably a better target than the corporate LAN or Web site. PBX hacking may not sound glamorous by comparison with elite Internet penetrations, but it can be just as damaging. Attacks on PBXs, ACDS, voicemail, voice-response units, and other infrastructure can bring down a company: make it unable to function, expose its secrets, damage its reputation, burden it with telephone charges and the cost of re-provisioning and repair after damage is done." (Source: Communications Convergence, April 2002. Securing your Switch by John Jainschigg.) By not securing the PBX, companies risk a number of costly problems. The link for this article located at ITWeb is no longer available. . Enhance the security of your organization’s telecommunications; PBX systems may be neglected and pose a considerable threat to data integrity.. PBX Security, Telecom Risks, Data Breach Prevention. . Anthony Pell
Security, when dealing with large linux clusters has no single solution, only the commonly used approach of packaging together several existing solutions. DSI (Distributed Security Infrastructure) is Ericsson's attempt to centralize security. The interest in clustering from the telecommunications industry . . . . Security, when dealing with large linux clusters has no single solution, only the commonly used approach of packaging together several existing solutions. DSI (Distributed Security Infrastructure) is Ericsson's attempt to centralize security. The interest in clustering from the telecommunications industry originates with the fact that clusters address carrier-class characteristics, such as guaranteed service availability, reliability and scaled performance, using cost-effective hardware and software. These carrier-class requirements now include advanced levels of security. There are few efforts, however, to build a coherent distributed framework to provide advanced security levels in clustered systems. Ericsson Reasearch is currently working on designing a Secure Carrier Class Linux that meets the constraints of a large Linux-based Cluster. The link for this article located at Ericsson DSI Team is no longer available. . Explore how Ericsson's DSI fortifies large-scale Linux ecosystems with a cohesive system designed to meet telecommunications necessities.. Distributed Security Infrastructure, Secure Linux Clusters, Telecom Security Solutions, Cluster Security Framework. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.