Thank you for reading the LinuxSecurity.com weekly security newsletter.
The purpose of this document is to provide our readers with a quick
summary of each week's most relevant Linux security headlines. This week we have news on the HTTPS Everywhere plugin for Firefox, "The Truth About Vulnerability Scanners", cryptography news, Apple hacks on the rise, and much more.
LinuxSecurity.com
Feature Extras:
Understand: Fork Bombing Attack - Thanks to Anand Jahagirdar for this feature! As the variety of attacks and threats grow, you need to be prepared. In this HOWTO, get a feeling for the Fork Bombing Attack, what it is, how it works, where it comes from, how to deal with it and more.
Review: Hacking: The Art of Exploitation, Second Edition - If you've ever wondered what a "buffer overflow" was, or how a "denial of service" attack works beyond just a basic understanding, then there is no better book that will help you to delve into the nitty-gritty than Hacking: The Art of Exploitation, Second Edition, by Jon Erickson.
|
|
|
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.
|
|
Firefox extension delivers always-on encryption (Jun 21) |
|
Privacy campaigners the Electronic Frontier Foundation and the Tor Project have jointly released a beta version of a Firefox extension that encrypts all connections to compatible websites.
|
|
Dell u-turns on Ubuntu security (Jun 21) |
|
Last week, we commented on the fact that Dell was hyping up the Linix distribution Ubuntu on its web site, much to the detriment of Microsoft's Windows.Dell was proud of the fact it has been flogging Ubuntu-equipped machines since 2007 and we can only assume it makes more margin on such machines since it doesn't have to pay Microsoft its Windows tax.
|
|
Apple accused of hushing up security update (Jun 21) |
|
Apple has been accused of secretly adding a security update to its operating system without telling users, or anyone else. The update released last week included protection against a Trojan that could allow a hacker to take control of your machine.
|
|
(Jun 21) |
|
At this point in the identity management process it is time to consider what access the company's job functions should have to begin creating roles and rules. This is the first step in automating provisioning and de-provisioning. Even without automation, creating and managing the roles and rules will make manual provisioning (and auditing!) quite a bit faster and definitely more accurate.
|
|
eNom fails to act on bogus online pharmacies (Jun 21) |
|
The world's second-largest seller of website addresses knowingly helped groups that sell counterfeit pharmaceuticals to US residents in violation of federal laws, a research report alleges.
|
|
(Jun 21) |
|
Ex-hacker and alleged "war crimes collaborator" Adrian Lamo has garnered a great deal of attention lately from his role in outing Wikileaks leaker Bradley Manning, a young U.S. Military official who was leaking sensitive documents, including some which Lamo believed endangered national security.
|
|
Firefox add-on encrypts Facebook and Twitter (Jun 21) |
|
Firefox users worried about Internet eavesdropping are being offered a new way to encrypt their interaction with a range of popular websites, including Facebook and Twitter.
|
|
(Almost) Universal perl CGI exploitation (Jun 21) |
|
This works on the perl pipe bug. It'll take an arg that's the address of a website and it's cgi script with some args to the script then figure out if it can exploit it and how. It's worked on everything I've tried it on, though I have limited test boxes. It's pretty dirty but it works.
|
|
High-living hacker swaps Porsche for porridge (Jun 18) |
|
A 21-year-old hacker was banged up yesterday for frauds netting him a Porsche,
|