Thank you for reading the LinuxSecurity.com weekly security newsletter.
The purpose of this document is to provide our readers with a quick
summary of each week's most relevant Linux security headlines. This week we have Firefox security updates, network mapping, twitter security updates, and much more.
Understand: Fork Bombing Attack - As the variety of attacks and threats grow, you need to be prepared. In this HOWTO, get a feeling for the Fork Bombing Attack, what it is, how it works, where it comes from, how to deal with it and more.
Review: Hacking: The Art of Exploitation, Second Edition - If you've ever wondered what a "buffer overflow" was, or how a "denial of service" attack works beyond just a basic understanding, then there is no better book that will help you to delve into the nitty-gritty than Hacking: The Art of Exploitation, Second Edition, by Jon Erickson.
|
|
|
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.
|
|
State of the CSO 2010: Progress and peril (Jun 29) |
|
Security is very old in most respects, yet very young in others. As a corporate discipline, security unfortunately languished for years in the basement.Today, as organizations come to grips with a wide swath of risks, the 2010 State of the CSO survey shows those organizations are rapidly adopting more sophisticated view of security. Of course, there's more work to be done--most prominently in the areas of security metrics and awareness programs.
|
|
Network Security Auditing Tools and Techniques (Jun 29) |
|
There's more to network security than just penetration testing. This chapter discusses software tools and techniques auditors can use to test network security controls. Security testing as a process is covered, but the focus is on gathering the evidence useful for an audit.
|
|
(Jun 29) |
|
Passwords are fundamentally insecure and represent the biggest security threat facing organisations, says Jason Hart, senior vice-president for Europe at security firm Cryptocard.
|
|
ATM flaws could be hacker jackpot (Jun 29) |
|
A security expert has identified flaws in the design of some automated teller machines that make them vulnerable to hackers, who could make the ubiquitous cash dispensers spit out their cash holdings.
|
|
(Jun 28) |
|
The Internet Industry Association (IIA) has submitted a revised and updated code of practice for Internet service providers (ISPs) around spam emails to the Australian Communications and Media Authority (ACMA) for official registration.
|
|
Pirate Bay founding group disbands (Jun 28) |
|
The Swedish anti-copyright group Piratbyran, which gave rise to the popular file-sharing website The Pirate Bay has disbanded.Marcin de Kaminski, a founder of Piratbyran, which means "piracy bureau" in English, told BBC News "we don't feel we are needed" any more.
|
|
Mozilla tweaks new plug-in protection (Jun 28) |
|
Mozilla pushed out a minor update to Firefox on Saturday, slightly adjusting the new plug-in crash protection feature that was introduced last week. Firefox 3.6.6 for Windows and Linux delays the amount of time that the plug-in protection module will wait before terminating an unresponsive plug-in.
|
|
(Jun 28) |
|
Network flow analysis is the art of studying high volume network traffic. Rather than capture every single packet, flow analysis allows network administrators to selectively record and filter network data, so they're only collecting the data they really need. Flow analysis makes difficult tasks like real-time network monitoring, user profiling, security analysis, and data mining dead simple.
|
|
(Jun 28) |
|
For weeks now, the United States military has been holding an Army intelligence analyst, Bradley Manning, in connection with the release of classified materials to the whistle-blower Web site Wikileaks. He is suspected of being the source of the 2007 video of an Apache helicopter killing 12 civilians in Iraq, including two Reuters journalists. More ominously, he is feared to have leaked 260,000 secret diplomatic cables.
|
|
Twitter ordered to tighten security (Jun 28) |
|
Twitter has been ordered to set up and maintain a comprehensive information security programme and allow a third-party review of that programme every two years for 10 years.
|
|
Twitter Hacker Gets Slap on the Wrist (Jun 27) |
|
A French court this week convicted a man accused of hacking into the Twitter accounts of President Barack Obama and other celebrities, as well as obtaining private Twitter business documents that were eventually published on TechCrunch.
|
|
Google remotely wipes apps off Android phones (Jun 27) |
|
Google has remotely removed two free apps from several hundred Android phones because the apps misrepresented their purpose and thus violated Android developer policies, according to a company spokesman.
|
|
Red Hat Enterprise Virtualization 2.2 improves scale, performance, and security (Jun 25) |
|
Linux giant Red Hat is moving the ball forward on its mission of becoming a key virtualization and cloud infrastructure player. To that end, the company has announced the latest release of its Enterprise Virtualization hypervisor, version 2.2.
|
|
Twitter Settles FTC Charges That It Failed to Protect User Data (Jun 25) |
|
Social networking site Twitter on Thursday settled Federal Trade Commission charges that "serious lapses" in data security put its users at risk.The FTC in its administrative complaint (pdf) said these security lapses allowed hackers to obtain administrative control of Twitter and send out phony tweets from users including then-President-elect Barack Obama and Fox News.
|
|
VeriSign SSL certs open to tampering, competitor warns (Jun 25) |
|
VeriSign and one of its partners have come under fire for publicly exposing webpages used to process customer security certificates, a practice a competitor claims puts some of the biggest names on the web at risk of serious targeted attacks.
|
|
(Jun 25) |
|
Byron Sonne and Kristen Peterson are life partners leading very different lives.Mr. Sonne is a computer expert whose job is to delve deep into the realm of complex electronic security networks; in his spare time, he frequents "hackerspaces" and derides the way people are monitored in their everyday lives.
|
|
Help your competitor - Advise them of vulnerability (Jun 25) |
|
Tom Bicer wrote in to tell us about some interesting development amongst the SSL certificate providers. Comodo made a press release announcing that they found some vulnerabilities related to Verisign's certificate and had advised Verisign on the vulnerabilities.
|
|
Mozilla Firefox 3.6.4 Delivers Stability and Security (Jun 24) |
|
Mozilla is updating its Firefox Web browser with new technology that is targeted at making the open source browser more stable. The Firefox 3.6.4 release also includes fixes for four critical security vulnerabilities.
|
|
Another domain adopts added DNS security (Jun 24) |
|
The Public Interest Registry, which operates the .org generic top-level domain, announced today that it has completed deployment of Domain Name System Security Extensions, which provide an additional level of security to the DNS. The full deployment tops off a two-year deployment and testing period of DNSSEC in 18 live "friends and family" domains within .org.
|
|
Reclaiming your e-mail account from a hacker (Jun 24) |
|
London. Home of Buckingham Palace, double decker buses and an e-mail sent from Covington's Kelly Ronning telling her friends that someone had stole her cash while vacationing in the English capital.
|
|
Two London teenagers arrested in cybercrime investigation (Jun 24) |
|
The Metropolitan Police's Police Central e-Crime Unit (PCeU) has arrested two teenagers in an international cybercrime investigation.The two males, aged 17 and 18, are being held in a central London police station.
|
|
Tokenization vs encryption: RSA touts tokens to reduce PCI DSS pain (Jun 24) |
|
Payment industry executives and security experts are currently debating over the right way to preserve and protect credit card data. Merchants can choose between a variety of formats, from format preserving encryption, which replaces the 16-digit credit card number with an encryption algorithm to card-based tokens, which substitute a random token with the hope that it could reduce the scope of a PCI DSS assessment.
|
|
Social Networking Bill Of Rights Released (Jun 23) |
|
In the aftermath of much-publicized breaches by heavyweights Google, Facebook, and AT&T, among others, attendees of the annual Computers, Freedom, and Privacy (CFP) conference spent last week creating a Users' Bill of Rights that is now available for public consumption, feedback, and approval.
|
|
Man accused of extortion through computer hacking (Jun 23) |
|
A hacker took over more than 100 computers and used them to extort sexually explicit videos from women and teenage girls by threatening to release their personal data, federal prosecutors charged Tuesday.
|
|
|