Thank you for reading the LinuxSecurity.com weekly security newsletter.
The purpose of this document is to provide our readers with a quick
summary of each week's most relevant Linux security headlines. Big news this week is the AT&T security breach, the Linux IRC trojan/malware, a statement just released today from Dell that Ubuntu is more secure than Windows, and a couple of great book reviews and other feature stories. Read on!
|
(Dec 9) |
|
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.
|
|
Ubuntu 'more secure' than Windows, says Dell (Jun 14) |
|
Dell reckons Ubuntu offers more protection than Windows online as it convinces consumer PC shoppers they shouldn't be scared of Linux.In a statement flagged here by TheVarGuy.com, Dell picked on security as one of ten reasons why people should buy PCs running Canonical's Linux rather than Microsoft's operating system.
|
|
Google Wi-Fi Data Capture Unethical, But Not Illegal (Jun 14) |
|
Google is under global scrutiny for its "accidental" gathering of wi-fi data while driving about photographing the world with its Street View camera cars. In the court of public opinion Google's actions cross ethical boundaries, but whether or not the activities were illegal depends on the laws in place for the given jurisdiction. Businesses in the United States should understand that the interception of publicly available data traversing the airwaves is probably not illegal.
|
|
Another way to get protection for application-level attacks (Jun 14) |
|
I am a fan of modsecurity (modsecurity) as a fast and cheap way to get decent protection for application layer attacks. But, as you know, risks are increasing and when the risk analysis performed to your organization shows that application disruptions have a big impact to the core business, it's time to strengthen controls and think about delivering protection from the code itself.
|
|
Linux Trojan Raises Malware Concerns (Jun 14) |
|
I've got good news and bad news for those of the misguided perception that Linux is somehow impervious to attack or compromise. The bad news is that it turns out a vast collection of Linux systems may, in fact, be pwned. The good news, at least for IT administrators and organizations that rely on Linux as a server or desktop operating system, is that the Trojan is in a game download so it should have no bearing on Linux in a business setting.
|
|
IRC server had backdoor in source code for months - Update (Jun 14) |
|
The developers of the open source IRC server UnrealIRCd have had to report that the file servers of the project were compromised several months ago and the IRC servers code, Unreal3.2.8.1.tar.gz was replaced by a version with a backdoor. The backdoor allows anyone to execute commands on the server running UnrealIRCd, with the privileges of the user running the IRC daemon,
|
|
(Jun 11) |
|
Microsoft and outside security researchers accused a Google engineer of failing to follow the responsible disclosure etiquette his own company promotes by disclosing a Windows XP-related flaw on Thursday, publishing code to exploit it and giving Microsoft only five days to fix it.
|
|
Drupal clarifies security rules after White-House gaper (Jun 11) |
|
Webmasters running unfinished modules for Drupal do so at their own risk after the open-source CMS updated its guidelines on fixing security vulnerabilities.
|
|
(Jun 11) |
|
Results from the 2010 Eclipse User Survey reveal interesting trends surrounding open source usage and opinions. Although it would be a stretch to say that these results from the 457 respondents represent the overall market, they do provide an interesting picture of development decisions being made by companies that are oriented to open source adoption.
|
|
New Open-Source OS Will Feature 'Disposable' Virtual Machines (Jun 10) |
|
A new open-source operating system will come with the option of creating one-time, disposable virtual machines on the fly as a way to protect against malicious files.
|
|
'Brute force' script snatched iPad e-mail addresses (Jun 10) |
|
The harvesting of over 100,000 iPad 3G owners' e-mail addresses was not a hack or a classic data breach, but a brute force attack of a minor feature AT&T offered to Apple customers, experts said Wednesday.
|
|
(Jun 10) |
|
Google pushed out an update for the stable branch of its Chrome browser Wednesday. The update, for Windows, Mac, and Linux, addresses multiple security bugs including nine tagged as high-level problems.
|
|
(Jun 9) |
|
Former hacker Adrian Lamo has claimed to be the source who informed on a US soldier accused of sending the Wikileaks whistleblowing site video footage of a helicopter shooting unarmed Iraqi civilians.
|
|
(Jun 9) |
|
Passwords may be the security equivalent of the "close door" button in an elevator -- something you expect to be present, but which only serves as a psychological placebo.
|
|
Free Bradley Manning! (Jun 9) |
|
No good deed goes unpunished, and that is especially true when it comes to whistleblowers who expose the murderous machinations of the US government: SPC Bradley Manning, a 22-year-old intelligence analyst stationed at Forward Operating Base Hammer in the vicinity of Baghdad, was arrested two weeks ago for having supposedly sent Wikileaks the "Collateral Damage" video of US troops shooting Iraqi civilians.
|
|
Researchers release point-and-click website exploitation tool (Jun 9) |
|
Researchers have released software that exposes private information and executes arbitrary code on sensitive websites by exploiting weaknesses in a widely used web development technology.
|
|
Tool for cracking encrypted session data (Jun 9) |
|
Two researchers have released a tool which can be used to crack web server-encrypted session data contained in cookies and parameters hidden in HTML pages. The method used by Juliano Rizzo and Thai Duong's Padding Oracle Exploitation Tool (Poet) can also be used to crack CAPTCHAS.
|
|
Google pays $2,000 for report of a vulnerability in Chrome (Jun 9) |
|
Google has paid out its highest sum yet, $2,000, for the discovery of a vulnerability found in its Chrome browser. The recipient is developer Sergey Glazunov, who found a DOM method-related means of circumventing the same origin policy.
|
|
MAC Address Spoofing for Windows, Linux and Mac (Jun 8) |
|
Network adapters come preconfigured from the factory with their own globally unique physical or Media Access Control (MAC) address, which helps them identify themselves when communicating with other networking components. Though you can't change the permanent MAC address actually stored by the network adapter, you can make it provide a different address using your operating system (OS). We'll see how to do this with Windows, Mac OS X, and Linux.
|
|
Is Open Source Safe? (Jun 8) |
|
The IT Department where Daniel Toth works won't let him use open source software because they believe it's a security risk. Is it?No. If anything, open-source software has the potential to be safer. Not that it always is, of course.
|
|
(Jun 8) |
|
Symantec believes security firms should be concentrating on eradicating 'false positives' or files that are incorrectly identified as malware.The security vendor revealed it has between 10 and 40 false positives a month. However, most of these do not affect a wide number of PC users.
|
|
(Jun 8) |
|
For those of you who, like me, are fans of the various challenges, the Honeynet Project has released challenge 4 in their 2010 forensics series.To quote from the challenge page: Challenge 4 - VoIP ... takes you into the world of voice communications on the Internet. VoIP with SIP is becoming the de-facto standard for voice communication on the Internet. As this technology becomes more common, malicious parties have more opportunities and stronger motives to take control of these systems to conduct nefarious activities. This Challenge is designed to examine and explore some of attributes of the SIP and RTP protocols. Enjoy the challenge."
|
|
Vulnerability Summary for the Week of May 31, 2010 (Jun 7) |
|
The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.
|
|
U.S. Army arrests Wikileaks whistleblower (Jun 7) |
|
Wikileaks vs. the U.S. Military continues. You'll recall that the U.S. Army labeled the Web site a "potential force protection, counterintelligence, operational security (OPSEC), and information security (INFOSEC) threat to the US Army." Now the Army has arrested the person who hundreds of thousands of documents, including that pretty gruesome video from a few weeks back, to the site.
|
|
WWII Enigma machine messages to be digitised (Jun 7) |
|
During World War II, Britain's brightest minds routinely decoded encrypted German military messages, an effort believed to have significantly shortened the war and saved the country further devastation.
|
|
Open-Source Could Mean an Open Door for Hackers (Jun 7) |
|
The ability to access the code of open-source applications may give attackers an edge in developing exploits for the software, according to a paper analyzing two years' worth of attack data. The paper, to be presented this week at the Workshop on the Economics of Information Security, correlated 400 million alerts from intrusion detection systems with known attributes of the targeted software and vulnerabilities.
|
|
Hack on e-commerce co. exposes records for 200,000 (Jun 7) |
|
E-commerce company Digital River exposed data belonging to almost 200,000 individuals after hackers executed a "highly unusual search command" against its secured servers, according to a news report.
|
|
Everything should be encrypted, right? (Jun 6) |
|
Here's the perfect plan to solve all those pesky security problems. Confidentiality and data leakage, secure backups, individual privacy, data integrity, identity and access management - all can be dealt with in some way by encryption. So why don't we all just use it then, and be done?
|
|
Zero-day vulnerability in Adobe Flash Player, Reader and Acrobat (Jun 6) |
|
According to a security advisory from Adobe, there is a critical vulnerability in Flash Player 10.0.45.2 (and earlier versions) and in the authplay.dll component that ships with Adobe Reader and Acrobat 9.0; Windows, Mac OS X, Unix and Linux versions are all vulnerable. Attackers can exploit the hole to crash the software or gain control of the system and there are already reports of exploitation in the wild for all three products.
|
|
Mac OS X and Linux are no magic security bullet for Google (Jun 6) |
|
The Financial Times reported last night that Google was going to phase out internal use of Microsoft Windows due to security concerns. The migration away from Windows is reported to have started in January, motivated by the Chinese Aurora attacks on the company that exploited a flaw in Internet Explorer 6.
|