Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
On Tuesday June 26, 2001, a hacker named 'ThePike' managed to deface the European defacement mirror Alldas.de. Visitors to the site saw a modified news banner on the left side saying "ALLDAS GOT CRACKED! READ IT HERE". . . . . On Tuesday June 26, 2001, a hacker named 'ThePike' managed to deface the European defacement mirror Alldas.de. Visitors to the site saw a modified news banner on the left side saying "ALLDAS GOT CRACKED! READ IT HERE". The front page was modified to include a small rant/message from the defacer regarding current defacement activity. His message warned other defacers that "security is not something funny" and cautioned would-be defacers about using their scripts to deface companies that rely on data security. For details on the defacement from Alldas: See Alldas - Die Welt in Ihren Händen. For a mirror and the full text message left: It is interesting to note the amount of commands the attacker attempted to run and the likelihood that he shared the exploit with others. Given the command attempts came from 10 different IP addresses, one might wonder about the intentions of the OTHER people involved. Security web site Security.NL was contacted by someone, possibly from whiskunde.org, believed by some to be involved in the defacement. Security.NL posted an article (in Dutch) about the defacement, as well as mirror and screenshots: screenshots: mirror: Securitywatch article on the incident: It is refreshing to see Alldas.de provide details of the incident as well as make a mirror available on their site. It is that kind of integrity and honesty that is needed in the security community. - The information and commentary is Copyright 2001, by the individual author. Permission is granted to quote, reprint or redistribute provided the text is not altered, and the author and attrition.org is credited. The opinions expressed in this mail are not necessarily the opinion of all Attrition staff members. Commentary Archive: TheAttrition Mirror: Country/TLD Statistics: country.html Attrition Defacement Statistics: stats.html Operating System Graphs: Other Web Defacement Mailing Lists: Contacting Attrition Staff:
HM Revenue and Customs (HMRC) demanded the removal of more than 20,000 malicious sites over the past year, as its efforts to protect taxpayers from scams gained momentum. . The UK tax office claimed it had helped deactivate a record 20,750 sites, a 29% increase from the previous year. According to the National Cyber Security Centre, HMRC is the government’s most abused brand, as scammers look to trick taxpayers into responding to phishing emails and texts offering ‘tax refunds’ and other bogus claims. The link for this article located at InfoSecurity is no longer available. . The UK taxation authority revealed the removal of 21,500 harmful websites, a 31% rise from last year, as part of ongoing cybersecurity efforts. HMRC Malicious Sites, Cybersecurity Increase, Scams Deactivation, Tax Office Security. . Brittany Day
WordPress site administrators just cannot come up for air. With a raft of WordPress vulnerabilities. Researchers at Zscaler on Thursday said that the backdoor code implanted on the sites awakens when a user inputs login credentials - See more at: The link for this article located at ThreatPost is no longer available. . Cybersecurity experts from Zscaler have discovered hidden backdoor scripts within WordPress, compromising user credentials at the point of login. Immediate measures are advised.. WordPress Security Risks, Backdoor Exploitation, Credential Leak, Malware, Website Security. . LinuxSecurity.com Team
According to a new report from Menlo Security, one out of three of the top million websites are either vulnerable to hacking or already hacked. For example, attackers used the Forbes.com website last month for a quick watering hole attack. . According to Dallas-based research firm iSIGHT Partners, Inc., the attack only lasted a couple of days in late 2014, used a zero-day Adobe Flash vulnerability, and was linked to a Chinese cyber espionage group. "We saw the Forbes.com hack, and that there were quite a few other sites being hacked, delivering malware, targeting innocent users," said Menlo Security's CTO Kowsik Guruswamy. "We were curious how that malware got there in the first place." The link for this article located at CSO Online is no longer available. . Menlo Security reveals concerning insights regarding website weaknesses along with cases of cyber intrusions and malicious software distribution.. Website Security Issues,Cybersecurity Threats,Malware Attacks,Cyber Exposure. . LinuxSecurity.com Team
In recent months, the web world was hit with a code exploit that affected many users across various web development platforms, from custom systems to Drupal and WordPress.org. This hack exploited a security vulnerability in the popular TimThumb image resizing PHP script, which allowed the hacker full access to any website running the older version of this script.. An exploit of this nature, of course, didn The link for this article located at memeburn is no longer available. . Boost your WordPress security against exploits like TimThumb by regularly updating your core, themes, plugins, and implementing essential measures to protect your site. WordPress Security, Image Resizing Exploits, Website Malware Prevention, PHP Security Practices. . LinuxSecurity.com Team
A security firm warned Monday that the website for downloading the popular MySQL open source relational database was infecting PCs via drive-by downloads.. Browsers that visited MySQL.com Monday were immediately injected with a JavaScript executable, which generated an iFrame that redirected to a website hosting the Black Hole crimeware exploit kit. "It exploits the visitor's browsing platform (the browser, the browser plugins like Adobe Flash, Adobe PDF, etc, Java, ...), and upon successful exploitation, permanently installs a piece of malware into the visitor's machine, without the visitor's knowledge," according to a blog post written by Wayne Huang, CEO of security firm Armorize, which discovered the attack. "The visitor doesn't need to click or agree to anything; simply visiting mysql.com with a vulnerable browsing platform will result in an infection," he said. The link for this article located at Information Week is no longer available. . Adware infiltrated WordPress.org through deceptive ads, compromising visitor devices without their approval.. MySQL Malware, Drive-By Download Exploit, Security Breach. . LinuxSecurity.com Team
Researchers have discovered a serious weakness in virtually all websites protected by the secure sockets layer protocol that allows attackers to silently decrypt data that's passing between a webserver and an end-user browser.. The vulnerability resides in versions 1.0 and earlier of TLS, or transport layer security, the successor to the secure sockets layer technology that serves as the internet's foundation of trust. Although versions 1.1 and 1.2 of TLS aren't susceptible, they remain almost entirely unsupported in browsers and websites alike, making encrypted transactions on PayPal, GMail, and just about every other website vulnerable to eavesdropping by hackers who are able to control the connection between the end user and the website he's visiting. At the Ekoparty security conference in Buenos Aires later this week, researchers Thai Duong and Juliano Rizzo plan to demonstrate proof-of-concept code called BEAST, which is short for Browser Exploit Against SSL/TLS. The stealthy piece of JavaScript works with a network sniffer to decrypt encrypted cookies a targeted website uses to grant access to restricted user accounts. The exploit works even against sites that use HSTS, or HTTP Strict Transport Security, which prevents certain pages from loading unless they're protected by SSL. The link for this article located at The Register UK is no longer available. . The vulnerability resides in versions 1.0 and earlier of TLS, or transport layer security, the succe. researchers, serious, weakness, virtually, websites, protected, secure. . LinuxSecurity.com Team
Geek.com, one of the Web's most popular technology sites, has been hacked and is serving malware to visitors, security researchers at Zscaler said yesterday.. "It has come to our attention that many different pages [on Geek.com] -- like the main homepage and about us page -- are infected with malicious Iframes pointing to different malicious sites," Zscaler said in a blog. According to the blog, hackers injected a malicious HTML Iframe or script tag into the legitimate pages on the site. The link for this article located at Dark Reading is no longer available. . Cybercriminals infiltrated multiple sections on TechCrunch.com, embedding harmful software and deceptive Iframes, affecting users who browsed the site.. Geek.com Hack, Malware Injection, Exploit Attack, Website Security Breach. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.