Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 14 articles for you...
209

Why Linux Hosting Outperforms Windows Hosting Options and Alternatives

Linux prevails as the clear choice for web hosting due to its security, compatibility, customization and cost-efficiency. . The 21st century has seen the rapid digitization of life. All things within daily life – be it shopping or eating out or commuting, technology and computers have a role in enabling almost all of these activities. Different countries, organizations and people collaborate on the internet and contribute to a better working world. And the internet works with the use of computers called servers or hosts. Humans interact with computers with the help of operating systems. The importance of Linux reseller hosting stems from the fact a big chunk of the internet (websites) is up and running, thanks to cheap Linux reseller hosting. The link for this article located at NerdsMagazine.com is no longer available. . Explore the reasons that make Linux hosting superior to Windows in terms of security, flexibility, and affordability for online services.. Linux Hosting, Web Hosting Solutions, Cost-Effective Hosting. . Brittany Day

Calendar%202 Mar 30, 2021 User Avatar Brittany Day Security Trends
67

XML Encryption Flaw Exposes Web Services To Security Risks

Watch your Web Services: the official XML Encryption Syntax and Processing standard can be broken. So say two researchers from Ruhr-University Bochum in Germany, who have demonstrated a practical attack against XML's cipher block chaining (CBC) mode. . "We were able to decrypt data by sending modified ciphertexts to the server, by gathering information from the received error messages," according to a statement released by the researchers, Juraj Somorovsky and Tibor Jager. They presented their findings in detail at last week's ACM Conference on Computer and Communications Security in Chicago. The link for this article located at Information Week is no longer available. . Experts uncover a weakness in JSON encryption that puts online services at risk, outlining actionable exploits on networks.. XML Encryption, Web Services Security, Encryption Flaw, Data Breach, Attack Method. . LinuxSecurity.com Team

Calendar%202 Oct 25, 2011 User Avatar LinuxSecurity.com Team Cryptography
74

Exploring Security Risks in Service-Oriented Architecture Integrations

"Extensible Markup Language (XML), Web services, and service-oriented architecture (SOA) are the latest craze in the software development world. These buzzwords burn particularly bright in large enterprises with hundreds or thousands of systems that were developed independently. If these disparate systems can be made to work together using open standards, a tremendous amount of time, money, and frustration can be saved. Whether or not we are on the verge of a new era in software, the goal alone is enough to make security people cringe. It might be easy to glue System A and System B together, but will the combination be secure? Have you ever used or developed a SOA application? If so, you might be interested in this article that talks about some security concerns with it. . The link for this article located at cgisecurity is no longer available. . The link for this article located at cgisecurity is no longer available.. 'extensible, markup, language, (xml), services, service-oriented, architecture, (soa). . Bill Locke

Calendar%202 Nov 03, 2008 User Avatar Bill Locke Network Security
78

Improving Web Services Safety Through OpenLiberty-J Framework

OpenLiberty-J is based on J2SE, and open source XML, SAML, and web services libraries from the Apache Software Foundation and Internet2, including OpenSAML, a product of the Internet2 Shibboleth project. The library implements the Liberty Advanced Client functionality of Liberty Web Services standards This company provides a development architecture explicitly focusing on the deployment of secure practices for Web 2.0 Applications and development. Is this the best way to leverage web service security? . The link for this article located at Net-security.org is no longer available. . OpenLiberty-J is a cutting-edge framework enhancing web service security through open source technologies and features like role-based access control and advanced authentication. OpenLiberty-J, Security Frameworks, Web Services Security. . LinuxSecurity.com Team

Calendar%202 Mar 11, 2008 User Avatar LinuxSecurity.com Team Vendors/Products
74

Cisco: Reactivity Acquisition Strengthens Web Services Security

Cisco's acquisition of XML vendor Reactivity today could set the stage for a new approach in handling the Web services security problem, experts say. Cisco announced its intent to acquire privately held Reactivity, a maker of specialized XML processing hardware, for $135 million this morning. On the surface, the deal looks like a simple play for the networking giant to incorporate Web services capabilities into its hardware lines, but security experts inside and outside Cisco say there may be more to it than that. . The Reactivity technology will eventually be built into the Cisco security architecture, so that application-to-application controls can be implemented along with user-to-application controls, says George Kurian, vice president and general manager for Cisco's Application Delivery unit. The link for this article located at darkReading is no longer available. . With the purchase of Reactivity, Cisco seeks to bolster the security of web services through the incorporation of XML capabilities into its infrastructure.. Cisco Networking, Web Services Security, Reactivity Technology, Application Control. . Bill Locke

Calendar%202 Feb 23, 2007 User Avatar Bill Locke Network Security
81

Examining Weaknesses in Password Security Among Major Online Platforms

If you use any number of popular web forums or even some commercial services like classmates.com, amazon.com, netzero.com or your provider's webmail service, you may not be aware that you're sending your credentials over the internet in the clear. . Some sites appear to secure your credentials, but they really don't. Some offer SSL sign-ins, but don't make them the default. Others don't even make an attempt to use proper SSL encryption or any attempt to obscure the credentials. Remember the wall of sheep from DefCon? All of those people that kept logging into net resources assuming that nobody was listening? They were wrong! The link for this article located at ITtoolbox is no longer available. . Numerous platforms pledge to safeguard your information, but many neglect to implement adequate HTTPS encryption, putting your data at risk.. Password Security,SLL Protections,Web Encryption. . LinuxSecurity.com Team

Calendar%202 Aug 22, 2006 User Avatar LinuxSecurity.com Team Privacy
78

Web Services Testing Tools: Kenai Systems eXamine and eXamineST

Kenai Systems Inc., a maker of Web services vulnerability tools, today announced the release of two products: eXamine, and eXamineST. The products enable developers to import WSDL files and test them for Web services security vulnerabilities. . In October, Kenai released a free beta version of eXamine, which is a more general-purpose Web services inspection tool. EXamineST provides enhanced capabilities for inspecting and manipulating WSDL files, including support for OASIS' WS-Security specification and message validation. The tool is available as a standalone application and will eventually be available as an Eclipse plug-in. eXamineST, although containing features that were always on the Kenai product roadmap, was released a quarter earlier than originally anticipated, due to customer feedback resulting from the beta test of eXamine, said Bill Kesselring, CEO of Kenai Systems. "We took what we learned in beta, particularly the things we learned about the adoption of the WS-Security specification," said Kesselring. Said Jack Quinnell, CTO of Kenai Systems, "we accelerated release of many of the more advanced features in eXamineST due to customer demand." The link for this article located at Web Services Pipeline is no longer available. . TechGuardian Solutions has unveiled eShield and eShieldPRO to improve the analysis of application security flaws.. Web Services Testing, Kenai Systems, eXamine Tools. . LinuxSecurity.com Team

Calendar%202 Dec 16, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
78

Novell Identity Manager Update Boosts Network Security with Integration

Novell is integrating its identity management and Web services software in a way that it says will ease customers' ability to secure corporate networks. . . .. Novell is integrating its identity management and Web services software in a way that it says will ease customers' ability to secure corporate networks. The company on Wednesday released Nsure Identity Manager 2, an update to its server software for authenticating access to networks and managing user passwords. Next week, Novell is expected to release exteNd Suite 5, the latest edition of its Java-based server software and Web services development tools. Although the two remain separate products, Novell's plan is to steadily improve the integration between them. The company has created a single organization to develop both products, and sees a growing demand for tools to build Web services applications that depend on corporate-wide security systems, according to Novell executives. "Everybody is trying to make Java tools easier for Java programmers. We want to make Web services and identity management accessible to mainstream business analysts and systems administrators," said Frank Auger, vice president of product management for Novell exteNd and Nsure products. . Novell is integrating its identity management and Web services software in a way that it says will e. novell, integrating, identity, management, services, software. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200