Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
You might think that working on a secured floor in a 30-story office tower puts you out of reach of Wi-Fi hackers out to steal your confidential documents. . But researchers in Singapore have demonstrated how attackers using a drone plus a mobile phone could easily intercept documents sent to a seemingly inaccessible Wi-Fi printer. The method they devised is actually intended to help organizations determine cheaply and easily if they have vulnerable open Wi-Fi devices that can be accessed from the sky. But the same technique could also be used by corporate spies intent on economic espionage. . But researchers in Singapore have demonstrated how attackers using a drone plus a mobile phone could. might, think, working, secured, floor, 30-story, office, tower, reach. . LinuxSecurity.com Team
An electronic dongle used to connect to the onboard diagnostic systems of more than two million cars and trucks contains few defenses against hacking, an omission that makes them vulnerable to wireless attacks that take control of a vehicle, according to published reports.. US-based Progressive Insurance said it has used the SnapShot device in more than two million vehicles since 2008. The dongle tracks users' driving to help determine if they qualify for lower rates. According to security researcher Corey Thuen, it performs no validation or signing of firmware updates, has no secure boot mechanism, no cellular communications authentication, and uses no secure communications protocols. SnapShot connects to the OBDII port of Thuen's 2013 Toyota Tundra pickup truck, according to Forbes. From there, it runs on the CANbus networks that control braking, park assist and steering, and other sensitive functions.. A system installed in more than two million cars is vulnerable to remote assaults, putting critical operations at risk from cybercriminals.. Wireless Security, Automotive Threats, Firmware Security. . LinuxSecurity.com Team
Nearly three-quarters of malicious connections to wireless networks are used for sending spam, according to new research. Security consultant Z/Yen set up two wireless local area networks (Lans) on behalf of RSA Security to monitor unauthorised connections - a so-called . . . . Nearly three-quarters of malicious connections to wireless networks are used for sending spam, according to new research. Security consultant Z/Yen set up two wireless local area networks (Lans) on behalf of RSA Security to monitor unauthorised connections - a so-called 'honeypot' trap. The survey found that almost a quarter of unauthorised connections to the wireless Lans were intentional, and 71 per cent of those were used to send emails." The biggest problem for someone wanting to deliver spam is having anonymity," said Z/Yen consultant Phil Cracknell. The link for this article located at vnunet.com is no longer available. . Studies indicate that almost 75% of unauthorized attempts to access Wi-Fi networks are aimed at distributing unsolicited emails.. malicious connections, wireless security, spam attacks. . Anthony Pell
Bob Fleck, a security consultant at Cigital, working with Jordan Dimov, has discovered new class of wireless attacks that can be used to gain unauthorized access to normally-protected machines on a standard wire-based internal network. Wireless networks involve installation of . . . . Bob Fleck, a security consultant at Cigital, working with Jordan Dimov, has discovered new class of wireless attacks that can be used to gain unauthorized access to normally-protected machines on a standard wire-based internal network. Wireless networks involve installation of a wireless Access Point on a normal internal network. This Access Point is usually connected to the wired network through a switch or a hub. The attacks discovered by Cigital are based on an adaptation of a well understood network attack from the non-wireless world known as ARP cache poisoning. This emphasizes the importance of re-considering old risks in light of new technologies, something that is especially important in software-based systems! The new class of attacks encompasses: 1) the ability to monitor and manipulate traffic between two wired hosts behind a firewall 2) the ability to monitor and manipulate traffic between a wired host and a wireless host 3) the ability to compromise roaming wireless clients attached to different Access Points 4) the ability to monitor and manipulate traffic between two wireless clients Previous wireless attacks have demonstrated that wireless traffic on an 802.11b network is vulnerable to monitoring and manipulation, even when it is "protected" with WEP encryption. This new class of attacks discovered by Cigital is based on abusing the Address Resolution Protocol (ARP) which binds internal IP addresses to ethernet addresses. Mitigating the risks of these attacks is possible. The best fix involves placing a technical barrier between the wireless network and the normal wired network. This provides only a partial solution that leaves the wireless network in a compromised state, though it protectsagainst the worst of the attack class Cigital discovered. Further risks can be mitigated through advanced design of any and all software applications that make use of the wireless network. Bob Fleck (
Get the latest Linux and open source security news straight to your inbox.