Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 9 articles for you...
83

Unlocking Unix: Enthusiasts Crack Historic Passwords with DES

Old passwords never die – they just become easier to decode. That’s the message from a tight-knit community of tech history enthusiasts who have been diligently cracking the passwords used by some of the original Unix engineers four decades ago. Learn more: . On 3 October, an enthusiast on the Unix Heritage Society mailing list asked a question about cracking passwords stored in old Unix systems. The source code for various revisions of Unix from the seventies onward is available online for anyone to download, and these revisions store the passwords for various staff members in the etc/passwd file. Unix hashed these passwords by running them through an algorithm called descrypt (also known as crypt(3)), which used the original DES encryption algorithm and limited the password length to eight characters. This was good enough to stop people recovering the password from the original hashes at the time, but 40 years on, computers are a little bit faster. The link for this article located at Naked Security is no longer available. . Uncover how aficionados are deciphering Unix passcodes, shedding light on legacy frameworks and their relevance to contemporary cybersecurity challenges.. Unix Cracking, Password Security, DES Encryption, Tech History. . LinuxSecurity.com Team

Calendar%202 Oct 14, 2019 User Avatar LinuxSecurity.com Team Hacks/Cracks
77

Apache 2.4.39 Security Advisory: Critical Root Access Exploit Fixed

This week, the Apache Software Foundation has patched a severe vulnerability in the Apache (httpd) web server project that could --under certain circumstances-- allow rogue server scripts to execute code with root privileges and take over the underlying server. . The vulnerability, tracked as CVE-2019-0211, affects Apache web server releases for Unix systems only, from 2.4.17 to 2.4.38, and was fixed this week with the release of version 2.4.39. According to the Apache team, less-privileged Apache child processes (such as CGI scripts) can execute malicious code with the privileges of the parent process. The link for this article located at ZDNet is no longer available. . Critical vulnerability fixed, possibly allowing unauthorized root access through CGI scripts on UNIX-based Apache servers.. Apache Vulnerability, Critical Patch, Web Server Security, UNIX Exploit, Root Access Risk. . LinuxSecurity.com Team

Calendar%202 Apr 03, 2019 User Avatar LinuxSecurity.com Team Server Security
81

OpenVPN Installation Guidelines for Linux and Unix Systems

Installing OpenVPN is easy and platform independent. Modern Linux systems, such as SuSE, Red Hat, Debian, or Ubuntu, provide sophisticated installation and package management systems, and still offer other ways to install the software. In this two-part article by Markus Feilner, we will install it on different Linux versions and FreeBSD.. All Linux/Unix systems must meet the following requirements to install OpenVPN successfully: Your system must provide support for the Universal TUN/TAP driver. The kernels newer than version 2.4 of almost all modern Linux distributions provide support for TUN/TAP devices. Only if you are using an old distribution or if you have built your own kernel, will you have to add this support to your configuration. This project's web site can be found at https://vtun.sourceforge.net/tun/. OpenSSL libraries have to be installed on your system. I have never encountered any modern Linux/Unix system that does not meet this requirement. However, if you want to compile OpenVPN from source code, the SSL development package may be necessary. The web site is https://www.openssl.org:443/. The Lempel-Ziv-Oberhumer (LZO) Compression library has to be installed. Again, most modern Linux/Unix systems provide these packages, so there shouldn't be any problem. LZO is a real-time compression library that is used by OpenVPN to compress data before sending. Packages can be found on https://openvpn.net/community/ and the web site of this project is http://www.oberhumer.com/opensource/lzo/. The link for this article located at PactPub is no longer available. . All Linux/Unix systems must meet the following requirements to install OpenVPN successfully: Your sy. installing, openvpn, platform, independent, modern, linux, systems. . LinuxSecurity.com Team

Calendar%202 Dec 05, 2009 User Avatar LinuxSecurity.com Team Privacy
77

Addressing SSH Security Vulnerabilities in UNIX Operating Systems

This article is a follow-up to my earlier article on SSH security considerations, in which I discussed some very real risks with SSH. Safari has some excellent online books available that cover the VPN aspects in much more depth than I can address in this space, as well as supplemental articles and other resources that can help you to better understand how SSH works and how to create the ultimate SSH technical security plan. This article will help the UNIX administrator The link for this article located at InformIT is no longer available. . Safari has some excellent online books available that cover the VPN aspects in much more depth than . article, follow-up, earlier, security, considerations, which, discuss. . LinuxSecurity.com Team

Calendar%202 Aug 28, 2006 User Avatar LinuxSecurity.com Team Server Security
77

Integrating Linux Authentication With Windows Active Directory

One of the main problems with UNIX/Windows environments is the lack of integration between the two platforms. Userids have to be created separately on each environment, passwords changed separately, etc. This doubles administrative work. This paper will explore using one of several different ways that you can active directory integrate your LINUX boxes to your windows AD forest. This document will give you integration between your linux boxes and your Windows AD forest. Additionally, it will allow you to control who can login to the LINUX boxes by group memberships within Active Directory. It will give you full . The link for this article located at InfoSec Writers is no longer available. . Integrating Linux with Windows Active Directory (AD) allows unified authentication and easier user management, ensuring security across diverse networks. Here's how to do it:. Linux Authentication, Active Directory Integration, User Management. . LinuxSecurity.com Team

Calendar%202 Aug 22, 2006 User Avatar LinuxSecurity.com Team Server Security
74

2004 Cyberattack Risks: RPC Vulnerabilities for Unix and Linux

The New Year will offer weary network administrators little respite from a new generation of Internet worms, viruses and targeted hacks that appeared in 2003, according to security experts. While many of those attacks will target Microsoft operating systems, malicious hackers may also look for ways to exploit RPC security holes in Unix and Linux. . . .. The New Year will offer weary network administrators little respite from a new generation of Internet worms, viruses and targeted hacks that appeared in 2003, according to security experts. In 2004, malicious hackers will continue to take advantage of security weaknesses in popular communications protocols such as Remote Procedure Call (RPC), while improvements in hacker tools will shorten the time that technology vendors and their customers have to respond to new vulnerabilities, according to comments by leading security researchers and corporate security experts at the InfoSecurity 2003 Conference and Exhibition in New York City Wednesday. The experts, including chief security officers from eBay Inc. and Siebel Systems Inc., took part in a panel discussion of security vulnerabilities and so-called "zero-day" exploits -- vulnerabilities that are exploited by attackers before software patches have been issued. Attacks that take advantage of holes in RPC will continue next year, according to Gerhard Eschelbeck of security company Qualys Inc. RPC vulnerabilities in Microsoft Corp.'s products were behind recent worms such as Blaster and Welchia, which spread worldwide in August. While many of those attacks will target Microsoft operating systems, malicious hackers may also look for ways to exploit RPC security holes in Unix and Linux, he said. . Cybersecurity analysts predict a rise in digital threats in 2024, focusing on Windows and Mac systems exploiting SMB weaknesses.. Cyberattack Forecasting, RPC Vulnerabilities, Internet Security Threats. . Anthony Pell

Calendar%202 Dec 31, 2003 User Avatar Anthony Pell Network Security
76

OpenBSD Anticipates Major Changes to Combat Buffer Overflows

The OpenBSD project hopes new changes to its latest release will eliminate "buffer overflows," a software issue that has been plaguing security experts for more than three decades.. . .. The OpenBSD project hopes new changes to its latest release will eliminate "buffer overflows," a software issue that has been plaguing security experts for more than three decades. Theo de Raadt, the project leader for the group, believes that the group's latest improvements to the Unix variant, due to be released on May 1, will make causing a buffer overflow extremely difficult, if not impossible. A buffer overflow is a memory error in software that allows an attacker to run a malicious program. "I could say that I am killing buffer overflows, but I am in the security community, so I have to put it in quotes," he told attendees at the CanSecWest security show on Thursday. Theo de Raadt, the project leader for the group, believes that the group's latest improvements to the Unix variant, due to be released on May 1, will make causing a buffer overflow extremely difficult, if not impossible. A buffer overflow is a memory error in software that allows an attacker to run a malicious program. "I could say that I am killing buffer overflows, but I am in the security community, so I have to put it in quotes," he told attendees at the CanSecWest security show on Thursday. The link for this article located at CNET is no longer available. . The FreeBSD developers are committed to removing memory leaks through innovative coding practices in their forthcoming version.. OpenBSD Security, Buffer Overflows, Unix Memory Error. . Anthony Pell

Calendar%202 Apr 11, 2003 User Avatar Anthony Pell Organizations/Events
83

Gobbles Security: Trojan Horse Threat Revealed Amid Antipiracy Hoax

A wisecracking group of hackers confirmed its claim this week that it spread an antipiracy virus was nothing but a hoax aimed at garnering fame. But members of the group, known as Gobbles Security, conceded that a program it released . . . . A wisecracking group of hackers confirmed its claim this week that it spread an antipiracy virus was nothing but a hoax aimed at garnering fame. But members of the group, known as Gobbles Security, conceded that a program it released to demonstrate the problem was a Trojan horse capable of destroying files on the computers of unwary Unix users. Experts said the bizarre incident, which caused a brief frenzy among some security firms and fans of music file sharing, follows a grand tradition of pranks by the playful hacking group. "I think that the latest Gobbles advisory is genius," said Dave Aitel, head of Immunity Security, a security software and services provider. "Gobbles takes the piss out of all of us, and we need to respect and appreciate that." The link for this article located at WiredNews is no longer available. . A wisecracking group of hackers confirmed its claim this week that it spread an antipiracy virus was. wisecracking, group, hackers, confirmed, claim, spread, antipiracy, virus. . LinuxSecurity.com Team

Calendar%202 Jan 16, 2003 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200