Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 436
Alerts This Week
Warning Icon 1 436

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
76

Intensive BSD Security Tutorial Highlights At BSDCon Monterey CA

This year's BSDCon is being held at the Monterey Hyatt, in Monterey Ca. The first tutorial was a two-day tutorial covering BSD System Security. For the most part the classes are intensive and there was a lot of ground to cover. . . . . This year's BSDCon is being held at the Monterey Hyatt, in Monterey Ca. The first tutorial was a two-day tutorial covering BSD System Security. For the most part the classes are intensive and there was a lot of ground to cover. And attendees should have been fairly comfortable with at least one flavor of UNIX. However there was considerable mention of routers and their important role in overall network security. The topics covered where pretty comprehensive. Alan started with an outline of what is computer crime and then ended up with a quick guide to the latest script kiddie software. This, believe it or not, included running Nessus (a new script kiddie GUI program ) on our local network set up inside the hotel, which discovered a few hosts that where ripe for an attack. The link for this article located at BSD Today is no longer available. . Participants delved into BSD Security during this year's BSDCon held in Monterey, discussing subjects ranging from cybercrime to various security resources.. BSDCon Security, Network Protection, UNIX Security Techniques, Script Kiddie Tools. . Anthony Pell

Calendar%202 Mar 31, 2020 User Avatar Anthony Pell Organizations/Events
74

Maximize Security Efficiency Using Unix/Linux Across Various Roles

It is a rare organization that has the money to deploy best of breed or integrated commercial software for every security role. Whether your job is perimeter protection, incident response or email server administration, there may be an opportunity to use your favorite Unix system with some additional tools to get the job done faster and cheaper than what you do now. . . .. After the reception my last column regarding the security criticism I heaped on Unix and Linux vendors who are pursuing end-user desktops, I thought I would outline some of the areas where I think Linux and Unix already have strong wins. While I am a dedicated Unix and Linux junkie and use it everywhere I can, I may be somewhat biased. However, there are some areas where Unix and Linux systems fit in better than anything else out there. In some cases, these roles can be performed on commercial Unix systems if your organization feels better about paying for commercial-grade software. The upcoming version of Solaris, for example seems to have some new security tricks that are worth a look if you need to run secure enterprise services. CD based OS - security in an insecure world Working in the security industry makes a person slightly paranoid. In my case, my paranoia goes far enough that I don't trust my own mother, or at least I don't trust her computer. The link for this article located at securityfocus is no longer available. . After the reception my last column regarding the security criticism I heaped on Unix and Linux vendo. organization, money, deploy, breed, integrated, commercial, softwa. . Anthony Pell

Calendar%202 Jun 04, 2004 User Avatar Anthony Pell Network Security
77

Linux LIDS CUPS Critical Buffer Overflow Issues Advisory 111294

Welcome to Security Alerts, an overview of recent Unix and open source security advisories. In this column, we look at a security vulnerability in LIDS; buffer overflows in CUPS, jgroff, Sun Solstice Enterprise Master Agent, and Ettercap; and problems in Sawmill, Faq-O-Matic, pforum, GNAT, Taylor UUCP, and IRIX O2 Video.. . .. Welcome to Security Alerts, an overview of recent Unix and open source security advisories. In this column, we look at a security vulnerability in LIDS; buffer overflows in CUPS, jgroff, Sun Solstice Enterprise Master Agent, and Ettercap; and problems in Sawmill, Faq-O-Matic, pforum, GNAT, Taylor UUCP, and IRIX O2 Video. LIDS is a Linux kernel patch and admin tool that enhances Linux kernel security and provides a reference monitor and Mandatory Access Control in the kernel. There are several vulnerabilities in LIDS that can be exploited by a local attacker to execute arbitrary commands with root permissions and bypass or disable LIDS. These vulnerabilities include problems with the LD_PRELOAD environment variable, writing directly to /dev/kmem, and a race condition in applications that are launched prior to LIDS being sealed. You may also be interested in Linux Advisory Watch, distributed weekly by LinuxSecurity.com. . Recent security advisories highlight multiple vulnerabilities in software and systems, including critical concerns with LIDS and CUPS, urging proactive patching and updates.. Linux Kernel, Open Source Security, Unix Vulnerabilities, System Flaws, Security Fixes. . LinuxSecurity.com Team

Calendar%202 Feb 20, 2002 User Avatar LinuxSecurity.com Team Server Security
74

Analyzing Security Through Obscurity For Network Defense

Is security through obscurity ever a useful way to protect your network, or does it just make things easier for corporate spies and hackers? This week in Unix Security, Carole Fennelly investigates who's benefiting from this security tactic. . . .. Is security through obscurity ever a useful way to protect your network, or does it just make things easier for corporate spies and hackers? This week in Unix Security, Carole Fennelly investigates who's benefiting from this security tactic. That accusation was leveled at me. I'd recommended that a client have internal headers stripped out of email at the firewall before that mail was being outside the company. I thought this was just good common sense. I even provided the technical solution to do it with the MTA the client was running (Sendmail). The admins balked and said, "No one does this." OK. So I asked the gods at Sendmail.org for guidance. To my surprise, they also felt it was unnecessary, even inadvisable. In fact, it was said that I was "paranoid" and relying on "security by obscurity." The link for this article located at SunWorld is no longer available. . Security through obscurity is the practice of keeping system details secret, believed to enhance safety by hiding vulnerabilities from attackers. Network Protection, Security Measures, Unix Defense. . Anthony Pell

Calendar%202 Oct 25, 2000 User Avatar Anthony Pell Network Security
77

Cracked Part 3: Tracking Down The Cracker In Unix Systems

Noel continues the story of when some Unix boxes that he helped admin were cracked. This article talks about some of the efforts made to track down the cracker and some surprises. This is the third part of the story . . .. Noel continues the story of when some Unix boxes that he helped admin were cracked. This article talks about some of the efforts made to track down the cracker and some surprises. This is the third part of the story of a community network that was cracked and what was done to recover from it. The first part Cracked! Part1: Denial and truth details the report that leads to the discovery that the community network was indeed cracked and some of the initial reactions. The second article Cracked! Part 2: Watching and Waiting talks about how they learned more about the cracker and what they did next. This article talks about some of the efforts made to track down the cracker and some surprises. The link for this article located at Rootprompt [LinuxToday] is no longer available. . Noel continues the story of when some Unix boxes that he helped admin were cracked. This article tal. continues, story, boxes, helped, admin, cracked, article. . LinuxSecurity.com Team

Calendar%202 May 22, 2000 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200