General Esm W900
xThank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines. This week we have articles on cryptography, the government, host & network security, intrusion detection, and much more.

LinuxSecurity.com Feature Extras:

Measuring Security IT Success - In a time where budgets are constrained and Internet threats are on the rise, it is important for organizations to invest in network security applications that will not only provide them with powerful functionality but also a rapid return on investment.

In most organizations IT success is generally calculated through effectiveness, resource usage and, most importantly, how quickly the investment can be returned. To correctly quantify the ROI of information technology, organizations usually measure cost savings and increased profits since the initial implementation. Additionally, ROI can also be affected based on the overall impact the investment has on employee productivity and overall work environment of the company.

- A buffer overflow occurs when a program or process tries to store more data in a temporary data storage area than it was intended to hold. Since buffers are created to contain a finite amount of data, the extra information can overflow into adjacent buffers, corrupting or overwriting the valid data held in them.


  EnGarde Secure Community 3.0.22 Now Available! (Dec 9)
 

Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.

  Multiple vulnerabilities in VMware products (Feb 1)
 

VMware has advised of a number of vulnerabilities in several of its products, including ESX, Server, VirtualCenter and vCenter. According to the company, a number of the issues relate to problems in the Java Runtime Environment (JRE) and several of the 47 vulnerabilities can be used by an attacker to compromise a system.

news/vendors-products/multiple-vulnerabilities-in-vmware-products
  EFF online tool reveals 'fingerprint' browsers leave on the Web (Feb 1)
 

The Electronic Frontier Foundation has created an on-line tool that details the wealth of information a Web browser reveals, which can pose privacy concerns when used to profile users.

news/privacy/eff-online-tool-reveals-fingerprint-browsers-leave-on-the-web
  Online Credit/Debit Card Security Failure (Feb 1)
 

Ross Anderson reports (via Bruce Schneier blog):

Online transactions with credit cards or debit cards are increasingly verified using the 3D Secure system, which is branded as "Verified by VISA" and "MasterCard SecureCode". This is now the most widely-used single sign-on scheme ever, with over 200 million cardholders registered. It's getting hard to shop online without being forced to use it.

news/cryptography/online-creditdebit-card-security-failure
  Experts fret over iPad security risks (Feb 1)
 

Apple's much hyped iPad tablet may come tightly locked down but the device is still likely to be affected by many of the security issues that affect the iPhone, as well as some of its own.

Security experts polled by El Reg were concerned about a variety of risks, in particular phishing attacks and browser exploits.

  CIA, PayPal under bizarre SSL assault (Jan 31)
 

The Central Intelligence Agency, PayPal, and hundreds of other organizations are under an unexplained assault that's bombarding their websites with millions of compute-intensive requests.

news/cryptography/cia-paypal-under-bizarre-ssl-assault
  Researchers Devise Chip and PIN Crack (Jan 31)
 

Here is a hugely popular article on LinuxSecurity.com from 2007 that is even more true today.Two Cambridge researchers have devised a relay attack with a hacked chip and PIN terminal that could enable attackers to bypass bank card security measures.

Saar Drimer and Steven Murdoch, members of the Cambridge University Computer Laboratory, demonstrated in January how they could modify a supposedly tamper-proof chip and PIN terminal to play Tetris. They have now extended the hack to demonstrate how they can compromise the system by relaying card information between a fake card and a genuine one.

news/hackscracks/researchers-devise-chip-and-pin-crack
  Google Attack Highlights 'Zero-Day' Black Market (Jan 29)
 

The recent hacking attack that prompted Google's threat to leave China is underscoring the heightened dangers of previously undisclosed computer security flaws -- and renewing debate over buying and selling information about them in the black market.

news/hackscracks/google-attack-highlights-zero-day-black-market
  House leaders move swiftly to launch probe of hackers (Jan 29)
 

House Speaker Nancy Pelosi, D-Calif., and Minority Leader John Boehner, R-Ohio, have demanded "an immediate and comprehensive assessment" of how computer hackers were able to attack nearly 50 House Web sites Wednesday night after President Obama's State of the Union speech.

news/government/house-leaders-move-swiftly-to-launch-probe-of-hackers
  FBI Arrests Alleged Cable Modem Hacker (Jan 29)
 

U.S. federal authorities arrested a 26-year-old man on Thursday for allegedly selling modified cable modems that enabled free Internet access, according to the U.S. Department of Justice. Matthew Delorey of New Bedford, Connecticut, is charged with one count of conspiracy and one count of wire fraud. If convicted, he could face up to 20 years in prison for each charge, and a $250,000 fine.

news/government/fbi-arrests-alleged-cable-modem-hacker
  Data breach report reveals need to boost internet security (Jan 29)
 

Research carried out by the University of Bedfordshire in conjunction with 7Safe, the IT forensics specialist, has found that there are a number of areas where organisations are commonly neglecting internet security and being rewarded with a data loss incident.

news/network-security/data-breach-report-reveals-need-to-boost-internet-security
  We Don't Hack (Jan 29)
 

More than 1 million Chinese IP addresses were controlled by foreign sources and hackers attacked 42,000 websites last year. A Ministry of Industry and Information Technology (MIIT) spokesperson told Xinhua News Agency on January 24 that China is the biggest victim of Internet-based hacking attacks. The country, the spokesperson said, has enacted laws that make all cyber attacks illegal and is willing to work with international partners to promote Internet security and fight against hacking.

news/government/we-dont-hack
  Black Hat DC: Researchers To Release Web Development Platform Hacking Tool (Jan 29)
 

A technique used in Web application development platforms that provides a constant look-and-feel across multiple Web pages can potentially expose sensitive user data, such as credit-card numbers, according to researchers, who at next week's Black Hat DC will demonstrate a new class of vulnerabilities in Apache MyFaces, Sun Mojarra, and Microsoft ASP.NET. They will also release a tool that tests for the flaws.

news/organizations-events/black-hat-dc-researchers-to-release-web-development-platform-hacking-tool
  Privacy Bill Nears Introduction in House (Jan 29)
 

The House Democrat heading up the push for legislation that would set new online privacy safeguards that could dramatically reshape Internet marketing said he plans to introduce the bill shortly, with several Republicans likely signed on as co-sponsors.

news/government/privacy-bill-nears-introduction-in-house
  Mitigate the Security Risks of PHP System Command Execution (Jan 29)
 

As the Web continues its march towards becoming the de facto interface for the world's software applications, developers must find effective ways to not only communicate with server processes such as MySQL, but also other operating system tools such as a shell or Ruby script. In this tutorial, I'll show you how to securely execute a variety of system-based commands via a PHP script, demonstrating how to build web applications that can tightly integrate with both the operating system and third-party software.

news/server-security/mitigate-the-security-risks-of-php-system-command-execution
  Moving Forward in Open Source (Jan 28)
 

I started my career with PCQuest as a Linux hacker 10 years ago. Since then, I've seen considerable amount of development happening in the Open Source space, especially in Linux-- high performance clustering, security and forensics, and virtualization. But despite that, I am a little disappointed about how things have actually moved in this domain.

  Set up rsyslog to store syslog messages in MySQL (Jan 28)
 

The de facto system logger on Linux systems is sysklogd, which provides the syslog and klog services that allow system events and application events to be logged and written to standard log files such as /var/log/messages.

news/server-security/set-up-rsyslog-to-store-syslog-messages-in-mysql
  Scan your Linux machine for viruses with ClamTk (Jan 28)
 

What do you mean