General Esm W900
Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines. This week we have a great review of the Erickson book "Hacking: The Art of Exploitation", and a discussion of "Fork Bomb" attacks by contributor Anand Jahagirdar.

LinuxSecurity.com Feature Extras:

Understand: Fork Bombing Attack - Thanks to Anand Jahagirdar for this feature!

As the variety of attacks and threats grow, you need to be prepared. In this HOWTO, get a feeling for the Fork Bombing Attack, what it is, how it works, where it comes from, how to deal with it and more.

Review: Hacking: The Art of Exploitation, Second Edition - If you've ever wondered what a "buffer overflow" was, or how a "denial of service" attack works beyond just a basic understanding, then there is no better book that will help you to delve into the nitty-gritty than Hacking: The Art of Exploitation, Second Edition, by Jon Erickson.


(Dec 9)

Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.

MAC Address Spoofing for Windows, Linux and Mac (Jun 8)

Network adapters come preconfigured from the factory with their own globally unique physical or Media Access Control (MAC) address, which helps them identify themselves when communicating with other networking components. Though you can't change the permanent MAC address actually stored by the network adapter, you can make it provide a different address using your operating system (OS). We'll see how to do this with Windows, Mac OS X, and Linux.

Is Open Source Safe? (Jun 8)

The IT Department where Daniel Toth works won't let him use open source software because they believe it's a security risk. Is it?No. If anything, open-source software has the potential to be safer. Not that it always is, of course.

(Jun 8)

Symantec believes security firms should be concentrating on eradicating 'false positives' or files that are incorrectly identified as malware.The security vendor revealed it has between 10 and 40 false positives a month. However, most of these do not affect a wide number of PC users.

(Jun 8)

For those of you who, like me, are fans of the various challenges, the Honeynet Project has released challenge 4 in their 2010 forensics series.To quote from the challenge page: Challenge 4 - VoIP ... takes you into the world of voice communications on the Internet. VoIP with SIP is becoming the de-facto standard for voice communication on the Internet. As this technology becomes more common, malicious parties have more opportunities and stronger motives to take control of these systems to conduct nefarious activities. This Challenge is designed to examine and explore some of attributes of the SIP and RTP protocols. Enjoy the challenge."

Vulnerability Summary for the Week of May 31, 2010 (Jun 7)

The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.

U.S. Army arrests Wikileaks whistleblower (Jun 7)

Wikileaks vs. the U.S. Military continues. You'll recall that the U.S. Army labeled the Web site a "potential force protection, counterintelligence, operational security (OPSEC), and information security (INFOSEC) threat to the US Army." Now the Army has arrested the person who hundreds of thousands of documents, including that pretty gruesome video from a few weeks back, to the site.

WWII Enigma machine messages to be digitised (Jun 7)

During World War II, Britain's brightest minds routinely decoded encrypted German military messages, an effort believed to have significantly shortened the war and saved the country further devastation.

Open-Source Could Mean an Open Door for Hackers (Jun 7)

The ability to access the code of open-source applications may give attackers an edge in developing exploits for the software, according to a paper analyzing two years' worth of attack data. The paper, to be presented this week at the Workshop on the Economics of Information Security, correlated 400 million alerts from intrusion detection systems with known attributes of the targeted software and vulnerabilities.

Hack on e-commerce co. exposes records for 200,000 (Jun 7)

E-commerce company Digital River exposed data belonging to almost 200,000 individuals after hackers executed a "highly unusual search command" against its secured servers, according to a news report.

Everything should be encrypted, right? (Jun 6)

Here's the perfect plan to solve all those pesky security problems. Confidentiality and data leakage, secure backups, individual privacy, data integrity, identity and access management - all can be dealt with in some way by encryption. So why don't we all just use it then, and be done?

Zero-day vulnerability in Adobe Flash Player, Reader and Acrobat (Jun 6)

According to a security advisory from Adobe, there is a critical vulnerability in Flash Player 10.0.45.2 (and earlier versions) and in the authplay.dll component that ships with Adobe Reader and Acrobat 9.0; Windows, Mac OS X, Unix and Linux versions are all vulnerable. Attackers can exploit the hole to crash the software or gain control of the system and there are already reports of exploitation in the wild for all three products.

Mac OS X and Linux are no magic security bullet for Google (Jun 6)

The Financial Times reported last night that Google was going to phase out internal use of Microsoft Windows due to security concerns. The migration away from Windows is reported to have started in January, motivated by the Chinese Aurora attacks on the company that exploited a flaw in Internet Explorer 6.

(Jun 4)

As malware continues to evade signature-based antivirus and intrusion prevention systems some organizations are turning to network capturing and analysis tools to detect anomalies and respond to security threats as they happen.

OpenSSL updates fix vulnerabilities (Jun 4)

The OpenSSL developers have released versions 0.9.8o and 1.0.0a, fixing two security problems. A flaw in the ASN.1 parser can be exploited to write to invalid memory addresses using specially crafted "Cryptographic Message Syntax" (CMS) structures.

Wikileaks denies Tor hacker eavesdropping gave site its start (Jun 3)

Updated WikiLeaks has denied that eavesdropping on Chinese hackers played a key part in the early days of the whistle-blowing site.Wired reports that early WikiLeaks documents were siphoned off from Chinese hackers' activities via a node on the Tor anonymiser network, as an extensive interview with WikiLeaks' founder Julian Paul Assange by the New Yorker explains in greater depth.