Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 5 articles for you...
210

Linux 5.6: Driver Issues With Intel WiFi Post Security Fixes

The Linux 5.6 kernel has been released - but you probably want to hold off on this release if you use the Intel "IWLWIFI" WiFi driver. Learn why in an informative Phoronix article. . For those that are normally spinning their own kernels and punctually upgrading to new releases, you will want to hold off on the newLinux 5.6kernel for the moment if you use the Intel "IWLWIFI" WiFi driver. Landing in the kernel right ahead of the Linux 5.6 release were a set of mac80211 security fixes sent in by Intel's Johannes Berg. Those fixes in turn broke the IWLWIFI driver that supports Intel's current wireless chipsets on Linux. The fixes do not note any particular CVE or offer too much detail. They mention though, "drop data packets if there's no key for them anymore, after there had been one, to avoid sending them in clear when hostapd removes the key before it removes the station and the packets are still queued", "check port authorization again after dequeue, to avoid sending packets if the station is no longer authorized", and other fixes in the name of security. The link for this article located at Phoronix is no longer available. . The recent release of Linux kernel 5.6 has presented several problems linked to Intel's IWLWIFI driver following unsuccessful security updates. It's advisable to refrain from upgrading!. Linux kernel, Intel IWLWIFI, Network Security, WiFi Driver Issues. . Brittany Day

Calendar%202 Mar 30, 2020 User Avatar Brittany Day Security Vulnerabilities
67

Exploring Firesheep's Role in WiFi Security Risks and Protection

An open-source Firefox extension called Firesheep has shined a spotlight on just how insecure it is to use unprotected WiFi networks. It's widely known that unprotected WiFi networks make sensitive data readily available for anyone with the technical skill necessary to find it, as demonstrated by Google's four-year Street View WiFi data gathering odyssey. . Google got into trouble for being unaware that software in its Street View cars was vacuuming data, but those broadcasting sensitive information over their networks and those running Web services with inadequate security somehow escaped blame. That may change, thanks to Firesheep, which allows anyone to scan unprotected WiFi networks for users who are logged into Facebook, Twitter, Google, Amazon, and a variety of other Web 2.0 services and to impersonate those users by hijacking their session cookie. The link for this article located at Information Week is no longer available. . WiFi vulnerabilities come to light with Firesheep, highlighting the dangers of unsecured connections that jeopardize user information and facilitate account takeovers.. firesheep, wifi security, open source protection, session hijacking. . LinuxSecurity.com Team

Calendar%202 Nov 02, 2010 User Avatar LinuxSecurity.com Team Cryptography
74

Threats of Cache Poisoning And Data Theft Over Public Wi-Fi

Public Wi-Fi networks such as those in coffee shops and airports present a bigger security threat than ever to computer users because attackers can intercede over wireless to "poison" users' browser caches in order to present fake Web pages or even steal data at a later time.That's according to security researcher Mike Kershaw, developer of the Kismet wireless network detector and intrusion-detection system, who spoke at the Black Hat conference. . He said it's simple for an attacker over an 802.11 wireless network to take control of a Web browser cache by hijacking a common JavaScript file, for example. "Once you've left Starbucks, you're owned. I own your cache-control header," he said. "You're still loading the cache JavaScript when you go back to work. "Open networks have no client protection," said Kershaw, who also uses the handle Dragorn. "Nothing stops us from spoofing the [wireless access point] and talking directly to the client," the user's Wi-Fi-enabled device. The link for this article located at Network World is no longer available. . He said it's simple for an attacker over an 802.11 wireless network to take control of a Web browser. public, wi-fi, networks, those, coffee, shops, airports, present, bigger, security. . Alex

Calendar%202 Feb 04, 2010 User Avatar Alex Network Security
74

Best Practices For Securing Your WLAN In Corporate Environments

The steady growth of Wi-Fi in the enterprise demands that corporate IT teams learn and adopt new security methodologies tailored to the unique requirements and weaknesses of wireless networks. In this paper, we will address each of these areas in detail and identify the real-world best practices needed to deploy and maintain a secure wireless network. . . .. The steady growth of Wi-Fi in the enterprise demands that corporate IT teams learn and adopt new security methodologies tailored to the unique requirements and weaknesses of wireless networks. Network and security staff must first evaluate a potentially confusing set of authentication and encryption mechanisms to be used in the network. Depending on the security selected, IT will then need to establish and document the corporate WLAN security policy, including mechanisms to validate user compliance and monitor for inherent network vulnerabilities. With a defined policy in place, IT staff can turn their attentions to protecting the network from snooping and an ever-expanding list of wireless attacks. In this paper, we will address each of these areas in detail and identify the real-world best practices needed to deploy and maintain a secure wireless network. The link for this article located at net-security.org is no longer available. . The steady growth of Wi-Fi in the enterprise demands that corporate IT teams learn and adopt new sec. steady, growth, wi-fi, enterprise, demands, corporate, teams, learn, adopt. . Anthony Pell

Calendar%202 Jul 23, 2004 User Avatar Anthony Pell Network Security
74

Managing MAC Protocols for Effective Wi-Fi Bandwidth Protection

By altering the Multiple Access Control (MAC) protocol, one of the series of protocols that govern how bandwidth is distributed between multiple users of the same wi-fi access point by randomly assigning each hotspot user a rate for data transfer, it is possible to siphon off most or all of the bandwidth. . . .. By altering the Multiple Access Control (MAC) protocol, one of the series of protocols that govern how bandwidth is distributed between multiple users of the same wi-fi access point by randomly assigning each hotspot user a rate for data transfer, it is possible to siphon off most or all of the bandwidth. That is what inspired Imad Aad and his colleagues, of the Ecole Polytechnique Federale de Lausanne (EPFL) - the Federal Institute of Technology in Lausanne, Switzerland - to devise a counter-measure. Within a third of a second, Aad told a conference this week, wi-fi operators using a tool called DOMINO could detect if someone is doing this by monitoring the rate of data flow in the MAC layer. The tool can be set to raise an alarm when one user is receiving data at an abnormally high speed compared to other users. The link for this article located at Sys-Con is no longer available. . Enhancing the Media Access Control (MAC) protocol can effectively combat Wi-Fi bandwidth theft by employing encryption, dynamic MAC addresses, and real-time monitoring. Wi-Fi Security, MAC Protection, Bandwidth Management. . Anthony Pell

Calendar%202 Jun 10, 2004 User Avatar Anthony Pell Network Security
74

Understanding Rogue Access Points and Their Threat to Network Security

A rogue access point is not authorized by an organization's IT department for operation.) Setting up an access point is child's play. In addition to plugging the access point into a power source, all one has to do is connect one end of an Ethernet cable to an available Ethernet port, connect the other end to an access point and voila! A new Wi-Fi WLAN is born. . . .. Although most wireless security solutions target organizations that have deployed wireless networks, there is a class of solutions that target all companies--even those that haven't deployed wireless networks. These solutions detect the existence of rogue access points. (An access point is a transceiver that connects devices on a wireless LAN to the wired infrastructure. A rogue access point is not authorized by an organization's IT department for operation.) Setting up an access point is child's play. In addition to plugging the access point into a power source, all one has to do is connect one end of an Ethernet cable to an available Ethernet port, connect the other end to an access point and voila! A new Wi-Fi WLAN is born. Not all rogue access points are malicious. Until my IT department found out about it and asked me to shut it down, I ran a rogue access point for almost two years (long before Wi-Fi was popular). So early was it in the history of Wi-Fi, that the software for setting up, managing, and securing my Lucent-based 802.11b WLAN was both proprietary and not very user friendly. Knowing that hardly anyone was using Wi-Fi at the time, I didn't bother securing it. Eventually, the company standardized on a single vendor's technology for deploying and securing WLANs and, knowing about my access point through the grapevine, the IT department saw my rogue WLAN for what it was: a back door that bypassed all of the hard work and planning that went into building a secure Wi-Fi network. Nick Miller, CEO of wireless management solution provider Cirond, put the problem in simple terms. "Companies spend thousands upon thousands of dollars andman-hours on network security," said Miller, "and all it takes is a $30 access point to render that investment useless." The link for this article located at ZDNet is no longer available. . Although the emphasis of wireless security measures is primarily on enterprises, threats from unauthorized access points can still arise independently of wireless local area networks.. Rogue Access Point, Wireless Threats, Network Risk. . Anthony Pell

Calendar%202 May 17, 2004 User Avatar Anthony Pell Network Security
74

WPA Security Advisory: Password Flaw And Network Attack Risks

A research paper posted online warns of holes in the latest WiFi (or 802.11) wireless cryptography protocol and outlines how WiFi Protected Access (WPA) can be compromised using a traditional network assault known as a dictionary attack. The paper, written . . . . A research paper posted online warns of holes in the latest WiFi (or 802.11) wireless cryptography protocol and outlines how WiFi Protected Access (WPA) can be compromised using a traditional network assault known as a dictionary attack. The paper, written by TruSecure's ICSA Labs senior technical director Bob Moskowitz, who indicates WPA can be compromised by intruders using network sniffers, cautions against use of weak passwords that could allow attackers to gain unauthorized access. Moskowitz, who has worked extensively with standards-setting bodies on WiFi technology, told TechNewsWorld that the passphrase issue is an old one that had been discussed during development of the WPA standard. The link for this article located at TechNewsWorld is no longer available. . A research paper posted online warns of holes in the latest WiFi (or 802.11) wireless cryptography p. research, paper, posted, online, warns, holes, latest, wireless, cryptography. . Anthony Pell

Calendar%202 Nov 12, 2003 User Avatar Anthony Pell Network Security
74

Protect Your WLAN: Strategies Against Network Threats and Attacks

Wireless LANs have experienced tremendous growth since the introduction of the 802.11b wireless networking standard spurred the development of a wide range of "Wi-Fi" solutions developed by network equipment vendors. Flexibility, ease of deployment and low component costs constitute three major . . . . Wireless LANs have experienced tremendous growth since the introduction of the 802.11b wireless networking standard spurred the development of a wide range of "Wi-Fi" solutions developed by network equipment vendors. Flexibility, ease of deployment and low component costs constitute three major drivers for the popularity of WLANs. However, the same flexibility and mobility provided by wireless networking also introduces new security vulnerabilities in addition to those that threaten conventional LANs. For real-time communications like Wi-Fi, a comprehensive real-time network protection strategy is required to enable pervasive, widespread deployment. WLANs are extremely vulnerable to denial-of-service attack and interruption. Any malicious hacker with a laptop and a wireless Network Interface Card can transmit wireless signal interrupters in close proximity to company sites where WLANs are deployed and effectively jam a Wi-Fi signal. Internal employees can set up their WLAN interface cards to operate in peer-to-peer (P2P) mode to communicate directly with people outside of the company. The link for this article located at ComputerWorld is no longer available. . Wireless LANs have experienced tremendous growth since the introduction of the 802.11b wireless netw. wireless, experienced, tremendous, growth, since, introduction. . Anthony Pell

Calendar%202 Feb 09, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200