General Esm W900
Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines.

LinuxSecurity.com Feature Extras:

Review: The Official Ubuntu Book - If you haven't used Linux before, are new to Ubuntu, or would like a quick update on the latest in open source advancements for the desktop, then The Official Ubuntu Book is a great place to start. Authored by a group of some of the most experienced open source administrators and developers, this 400-page user guide details everything you need to know about how to make the most of your Ubuntu, Kubuntu (Ubuntu with KDE), and Xubuntu (Ubuntu with Xfce) computer.

Review: Zabbix 1.8 Network Monitoring - If you have anything more than a small home network, you need to be monitoring the status of your systems to ensure they are providing the services they were designed to provide. Rihards Olups has created a comprehensive reference and usability guide for the latest version of Zabbix that anyone being tasked with implementing should have by their side.


Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.

(Jan 24)

A Web hack that can endanger online banking transactions is ranked the No. 1 new Web hacking technique for 2010 in a top 10 list selected by a panel of experts and open voting.

5 open source security projects to watch (Jan 26)

Data security is always top of mind for CIOs and CSOs, and there is no shortage of challenges when it comes to picking the right tool for the job. With network and software vulnerabilities growing at a perpetual rate, good security software can help defend against many of the large-scale threats that occur locally and from all over the Internet.

(Jan 28)

The convenience promised by the Internet often seems to evaporate when you log in every morning. First comes the user name and password needed to boot up your smartphone or computer. Next, a different password to access your e-mail. Want a book at Amazon.com (AMZN)? Another password (what was your first pet's name again?) and often your credit-card information and address.

Announce: OpenSSH 5.7 released (Jan 24)

OpenSSH 5.7 has just been released. OpenSSH is a 100% complete SSH protocol version 1.3, 1.5 and 2.0 implementation and includes sftp client and server support. Read on for a description of the improvements, including Elliptic Curve Cryptography, sftp performance improvements, and much more.

Hackers turn back the clock with Telnet attacks (Jan 28)

A new report from Akamai Technologies shows that hackers appear to be increasingly using the Telnet remote access protocol to attack corporate servers over mobile networks.

Low-cost SSL proxy could bring cheaper, faster security; defeat threats like Firesheep (Jan 26)

Researchers have found a cheaper, faster way to process SSL/TLS with off-the-shelf hardware, a development that could let more Web sites shut down cyber threats posed by the likes of the Firesheep hijacking tool.

Linux 2.6.37 Kernel Promises to Unlock OS (Jan 24)

Linus Torvalds is starting 2011 off with a bang with the release of the 2.6.37 Linux kernel. The new kernel is the first release since 2.6.36 debuted in October. The goal of the new 2.6.37 kernel is to provide developers with improved Linux performance, security and scalability.

Google Starts Censoring BitTorrent, RapidShare and More (Jan 28)

It's taken a while, but Google has finally caved in to pressure from the entertainment industries including the MPAA and RIAA. The search engine now actively censors terms including BitTorrent, torrent, utorrent, RapidShare and Megaupload from its instant and autocomplete services. The reactions from affected companies and services are not mild, with BitTorrent Inc., RapidShare and Vodo all speaking out against this act of commercial censorship.

Half of federal Web sites fail DNS security test (Jan 27)

Half of U.S. government Web sites are vulnerable to commonplace DNS attacks because they haven't deployed a new authentication mechanism that was mandated in 2008, a new study shows.

Quirky moments at Black Hat DC 2011 (Jan 26)

A Black Hat Conference is nothing if not quirky as security geeks try every stunt possible to show what a clueless world we live in when it comes to security. Anyway, here are some such moments from this week's event:

(Jan 26)

This article describes in some detail how to install Samhain, the host based intrusion detection system. I am not going to ramble on about what host based intrusion detection is or why to use it, as there are plenty of articles already covering those subjects. This article is just to show you how to get Samhain up and running in a client / server configuration with a couple bells and whistles thrown in for fun.

BitTorrent Sites Hacked By Secret Government Unit? Not So Fast.. (Jan 25)

In the early hours of Saturday morning, panic set in on two large European BitTorrent trackers. ArenaBG and Zamunda, a pair of sites with a history of being targeted by the Bulgarian authorities, were reported down. According to several mainstream media reports, they had been taken offline by the country's anti-mafia unit and/or hacked by a secret government department. Big news or crazy rumor?