General Esm W900
Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines. This week, more information on BlackHat, a massive ddos attack, some great book reviews, news that most SSL implementations are configured incorrectly, and details of the AppArmor inclusion in the latest kernel.

LinuxSecurity.com Feature Extras:

Review: Zabbix 1.8 Network Monitoring - If you have anything more than a small home network, you need to be monitoring the status of your systems to ensure they are providing the services they were designed to provide. Rihards Olups has created a comprehensive reference and usability guide for the latest version of Zabbix that anyone being tasked with implementing should have by their side.

Meet the Anti-Nmap: PSAD - How would you know if someone is scanning your defenses? Is there any way to properly respond to such scans? You bet there is...


Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.

Flawed Deployments Undermine Kerberos Security (Aug 9)

Significant weaknesses in the common configuration of Kerberos-based authentication servers could allow attackers to more easily circumvent security measures in networks that rely on the open authentication standard, according to recent research presented by consultants at the recent Black Hat USA 2010 conference.

Why Linux Is More Secure Than Windows (Aug 9)

"Security through obscurity" may be a catchy phrase, but it's not the only thing that's catching among Windows users. The expression is intended to suggest that proprietary software is more secure by virtue of its closed nature. If hackers can't see the code, then it's harder for them to create exploits for it--or so the thinking goes.

Black Hat convention hype hurts the enterprise risk management process (Aug 9)

For a few weeks in 1982, I was convinced that space aliens were outside my house. I had irrefutable evidence: strange lights, odd noises, and the like. Of course, the lights were the neighbor's pool, and the noises were the wind. I was just a child, caught up in the hysteria of having just watched the movie Alien on cable a few nights before. I eventually grew up and accepted the reality that aliens were not going to eat me.

(Aug 9)

Two of our readers (thanks Jason and Mike!) have written in to highlight the ongoing DDOS against DNS Made Easy.You can read the ongoing reports via their twitter page. The DDOS is reported to be circa 50Gb/sec in size. If you have any details on the type of attack we'd love to know.

Vary usernames and passwords on secure websites: study (Aug 9)

Tired of having to memorise several usernames and passwords for every secure website you visit? Don't fret. A recent study confirms what IT security experts have been saying all along--it is wiser to have different usernames and passwords to protect identities and information not meant to be public.

(Aug 6)

Although cyber attacks have been frequently reported across the mainland, China is not home to a vast web of malicious hackers, as many attacks here originate from countries overseas, according to analysts.

Lawmakers question data collection at major sites (Aug 6)

Two senior U.S. lawmakers say they're "troubled" by the collection of personal data at many websites, and they want details on how much data 15 popular sites collect and what the sites do with the data.

More than 1 in 10 Mozilla bug finders turn down cash (Aug 6)

The open-source Mozilla project has been offering cash bounties for security bugs for six years now, but often bug finders simply turn down the cash.

(Aug 6)

The one glimmer of hope during last week's social-engineering contest at Defcon18 was when two different employees at a major retailer separately shut down a contestant trying to smooth-talk his way into gathering sensitive information on their company.

Hacker for Hire Via Text Message (Aug 5)

LIGATT Security International, a cyber security company, today announced that their Hacker for Hire service will now be accessible via text messaging. Customers will now be able to text the word "Hacker" to 90210 to receive instant assistance to any cyber security issue they may have. This method is a faster and more effective approach for Hacker for Hire representatives to connect with cyber crime victims.

(Aug 5)

Many Ohio Valley residents are well aware of our dependence on computerized systems for the basics of life, including electric power. Generating plants throughout the Ohio Valley, along with the power grids they feed, rely on electronic controls.

(Aug 5)

Kevin Mitnick was eager to participate in a social-engineering contest at the Defcon hacker conference in Las Vegas last weekend and was told he would target Microsoft in the event.He figured it would be fun to show off his schmoozing skills, which he so easily used to trick employees at tech companies in the 1990s into handing over passwords and other sensitive information, ultimately landing him in jail.

(Aug 5)

As of Wednesday, software vendors will have a deadline to fix vulnerabilities reported to them by TippingPoint's Zero Day Initiative rather than allowing holes to remain unpatched indefinitely.

Metasploit To Get More Powerful Web Attack Features (Aug 5)

A popular open-source Web application attack and audit framework is now under the umbrella of Rapid7, the vulnerability management company that purchased the Metasploit Project last year. The w3af project ultimately will bring more Web security features and functions to both the Metasploit tool and Rapid7's commercial NeXpose product.

(Aug 4)

If you're thinking about a life of cybercrime, then building a botnet might be the best place to start, a security researcher said here last week.

(Aug 4)

The good news about SSL-based websites: Most are running strong encryption. The bad news: More than 60 percent aren't properly configured.

Repetition breaks Google Audio CAPTCHA (Aug 4)

Google has fixed a flaw in its Audio CAPTCHA software that could have given scammers a way to automatically set up phoney accounts with the company's services.

Botnet that pwned 100,000 UK PCs taken out (Aug 4)

Security researchers have uncovered the command and control network of a Zeus 2 botnet sub-system targeted at UK surfers that controlled an estimated 100,000 computers.

Hacker Wonderland: DefCon 18 in Photos (Aug 4)

Roughly 10,000 computer hacking enthusiasts, poseurs, geeks, nerds and government agents gathered for DefCon last weekend. In its 18th year, the world's largest hacker convention draws people from all walks of life to learn about the latest hacking techniques.

Android rootkit demonstrated (Aug 3)

At the DEFCON hacking conference, which ended yesterday, IT security researchers Nicholas Percoco and Christian Papathanasiou demonstrated what they claim is the first rootkit for Android. Their aim was to show how slight the obstacles to the development of a such a rootkit are and how powerful the result can be. Android is Linux-based and desktop Linux rootkits are nothing out of the ordinary.