Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 14 articles for you...
83

Bitdefender: MIT Web Attacks From Compromised Servers Overview

SECURITY FIRM Bitdefender has traced a number of brute force web site attacks on a server at the Massachusetts Institute of Technology (MIT),. A report on the firm's security blog, called Malware City, claims that a hacking attack against the MIT.edu infrastructure started with a malicious script on one MIT server. The link for this article located at The Inquirer is no longer available. . A report on the firm's security blog, called Malware City, claims that a hacking attack against the . security, bitdefender, traced, number, brute, force, attacks, server. . LinuxSecurity.com Team

Calendar 2 Nov 04, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Mass SQL Injection Attack Hits Over 1 Million ASP.NET Pages

A mass-injection attack similar to the highly publicized LizaMoon attacks this past spring has infected more than 1 million ASP.NET Web pages, Armorize researchers said today. According to database security experts, the SQL injection technique used in this attack depends on the same sloppy misconfiguration of website servers and back-end databases that led to LizaMoon's infiltration.. "This is very similar to LizaMoon," says Wayne Huang, CEO of Armorize, who, with his team, first reported of an injected script dropped on ASP.NET websites that load an iFrame to initiate browser-based drive-by download exploits on visitor browsers to the site. The link for this article located at Dark Reading is no longer available. . A widespread XSS infiltration has breached more than 1 million PHP websites, reminiscent of past SQL injection outbreaks like Jellyfish.. SQL Injection Attack, ASP.NET Sites, Cybersecurity Vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Oct 21, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

Reviewing Chrome Extensions: 27 Out Of 100 Expose User Data

We reviewed 100 Chrome extensions and found that 27 of the 100 extensions leak all of their privileges to a web or WiFi attacker. Bugs in extensions put users at risk by leaking private information (like passwords and history) to web and WiFi attackers. . Web sites may be evil or contain malicious content from users or advertisers. Attackers on public WiFi networks (like in coffee shops and airports) can change all HTTP content. We The link for this article located at Adrienne Porterfelt is no longer available. . Vulnerabilities in browser add-ons may leak personal information to cybercriminals on shared WiFi connections. Discover ways to fortify your browsing experience.. Chrome Extensions, Data Leak, Security Best Practices, Privilege Management. . LinuxSecurity.com Team

Calendar 2 Sep 29, 2011 User Avatar LinuxSecurity.com Team Security Projects
79

Android Browser Exploit Code Release By M.J. Keith At HouSecCon

A computer security researcher says he plans to release code Thursday that could be used to attack some versions of Google's Android phones over the Internet. The attack targets the browser in older, Android 2.1-and-earlier versions of the phones.. It is being disclosed Thursday at the HouSecCon conference in Houston by M.J. Keith, a security researcher with Alert Logic. Keith says he has written code that allows him to run a simple command line shell in Android when the victim visits a website that contains his attack code. The link for this article located at Network World is no longer available. . The recent findings disclosed during ByteSecure Conference exploit vulnerabilities in legacy iOS systems, enabling direct exploitations through compromised web pages.. Android Exploit, Web Attack, Browser Vulnerability, Security Research. . LinuxSecurity.com Team

Calendar 2 Nov 05, 2010 User Avatar LinuxSecurity.com Team Security Projects
81

Browser Auto-Complete Advisory: Critical Data Leak Threats Unveiled

In the run-up to his presentation at the Black Hat conference, Jeremiah Grossman of White Hat Security told The Register that users who allow their browsers to auto-complete frequently used form fields, such as names or email addresses, may become an easy target for data thieves. For instance, auto-complete data can reportedly be retrieved automatically via JavaScript in Safari 4 and 5.. To exploit the flaw a crafted web page is created with various input fields with such typical labels as name, email address or credit card number. A script is created which tries out all possible first letters in these fields. This triggers the auto-complete feature which kicks in once the first character has been entered. If the browser auto-completes the letter to make a word, the script processes the entered value. This can even be done invisibly via hidden form fields. Grossman informed Apple about the data leak on the 17th of June but says that so far he has not received any reply, other than an automated confirmation of receipt. A similar form of this attack scenario is already familiar from versions 6 and 7 of Microsoft Internet Explorer. In combination with cross-site scripting, Chrome and Firefox are also said to be vulnerable. There, attackers can even obtain data which the browsers' auto-complete feature only enters into the relevant web page The link for this article located at H Security is no longer available. . Unintended information exposure from web browser suggestion tools places individuals at risk for privacy breaches and cybersecurity challenges.. auto-complete security, browser exposure, data protection, web vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Jul 22, 2010 User Avatar LinuxSecurity.com Team Privacy
83

WordPress 2.9.2 Security Alert: Risk of Malware Injection from Design Flaw

Hundreds of WordPress blogs were hacked during the past few days by attackers who pilfered blogger credentials stored in plain text in the database. The researchers who discovered the attacks say a design flaw in the WordPress blogging platform was the underlying problem because by default it allows users to set up permissions that let anyone read their blog's wp-config.php file configuration files, and because WordPress stores the bloggers' credentials in plain text.. The attackers injected malicious iFrames into the blogs so that any visitors would automatically be infected with malware, including code that spreads fake antivirus software. "A few people got hacked last week and asked us to help," says David Dede, founder of Sucuri Security, which also uses WordPress for its own blog. "We fixed them and in one site, just after we fixed it, it got hacked again. Looking at the logs, we didn't see any access in there at all, so the attack didn't come from the Web." Dede says after further analysis and more complaints of hacked blogs, he and his team found that the blogs were getting hit with a malicious iFrame, and that the blogs were all hosted on Network Solutions' servers. Most were running the newest version of WordPress, 2.9.2, he says The link for this article located at Dark Reading is no longer available. . The attackers injected malicious iFrames into the blogs so that any visitors would automatically be . hundreds, wordpress, blogs, hacked, during, attackers, pilfered, blogger. . LinuxSecurity.com Team

Calendar 2 Apr 13, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Mozilla: Important Update Addresses Critical Flaws in Firefox 9

The Firefox web browser has been patched for security flaws, four of which were identified as "critical" by Mozilla. A total of nine security flaws were fixed in the new release. The patches include a fix for flaws such as one that allows scripts from page content to run with elevated privileges. With this, an attacker could cause an object such as a browser sidebar to interact with web content so that an attacker's code had elevated privileges.. The link for this article located at SC Magazine is no longer available. . Google has issued important security updates for Chrome, fixing ten vulnerabilities, improving safety for users against potential threats.. Firefox Security Patches, Mozilla Vulnerability Fixes, Browser Security Updates. . LinuxSecurity.com Team

Calendar 2 Jun 13, 2009 User Avatar LinuxSecurity.com Team Vendors/Products
83

Metasploit.com Hijacked By ARP Spoofing Attack Incident

Monday morning, Metasploit.com was temporarily hijacked using an attack on the local area network of Metasploit's hosting provider. Using what is technically known as ARP spoofing, the attacker was able to intercept visitors to Metasploit.com, and instead serve them up a page saying the site had been "hacked by sunwear ! just for fun. Users were then redirected to a Chinese forum with an image of the hack. . The link for this article located at Wired is no longer available. . The Metasploit.com incident reveals serious network security flaws, particularly with ARP spoofing that exploits ARP's lack of authentication to mislead devices.. Metasploit Incident, ARP Spoofing, Web Security Attack. . LinuxSecurity.com Team

Calendar 2 Jun 04, 2008 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here