General Esm W900
Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines.

LinuxSecurity.com Feature Extras:

Review: The Official Ubuntu Book - If you haven't used Linux before, are new to Ubuntu, or would like a quick update on the latest in open source advancements for the desktop, then The Official Ubuntu Book is a great place to start. Authored by a group of some of the most experienced open source administrators and developers, this 400-page user guide details everything you need to know about how to make the most of your Ubuntu, Kubuntu (Ubuntu with KDE), and Xubuntu (Ubuntu with Xfce) computer.

Review: Zabbix 1.8 Network Monitoring - If you have anything more than a small home network, you need to be monitoring the status of your systems to ensure they are providing the services they were designed to provide. Rihards Olups has created a comprehensive reference and usability guide for the latest version of Zabbix that anyone being tasked with implementing should have by their side.


Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.

Facebook Introduces Disposable Passwords (Oct 13)

Moving to enhance online security, Facebook on Tuesday said that it will soon offer users the ability to receive one-time passwords on their mobile phones and that it has already enabled the ability to sign out of Facebook remotely.

Trojan forces Firefox to secretly store passwords (Oct 13)

A trojan recently analysed by Webroot is said to rely on retrieving web page passwords from a browser's password storage, rather than logging a user's keyboard inputs. To make sure it will find all the interesting passwords in Firefox, the malware, called PWS-Nslog, makes some changes to jog the browser's memory.

PCI encryption: PCI Council calls point-to-point encryption immature (Oct 13)

The PCI Security Standards Council (PCI SSC) issued its first guidance document outlining the point-to-point encryption market, warning merchants of the possibility of vendor lock-in and calling current implementations too immature to properly evaluate.

Vulnerabilities in Xpdf affect several open source products (Oct 13)

According to a report from Red Hat, two vulnerabilities in the free PDF reader Xpdf can be exploited via manipulated PDF documents to compromise a victim's system. The flaws are reportedly due to an uninitialised pointer and an array index error.

Opera delivers fixes in security, usability (Oct 13)

Plugged security holes and stability fixes come to fans of the Opera browser as its Norwegian publisher released version 10.63 on Tuesday.

Six enterprise security leaks you should plug now (Oct 12)

In modern enterprises, there's a similar perception of invulnerability. Yet, for every large organization that glides through the year without any mishaps, there are many stories about perilous break-ins, Wi-Fi sniffing snafus and incidents where Bluetooth sniper rifles were used to steal company secrets.

G2 doesn't have rootkit, it's just the same old NAND lock (Oct 12)

Policy group New America has written a scathing blog entry that criticizes the HTC G2 for including a "hardware rootkit" that prevents users from installing custom firmware on the device. The report appears, however, to be based on a misunderstanding of technical issues raised in an XDA discussion thread.

To Catch A Hacking Bird (Oct 12)

The best way to secure your business, so the advice of many an IT security consultant appears to increasingly be, is to think like a hacker. Only by understanding how the bad guys get at your data can you truly prevent them succeeding: to catch a hacking bird, you have to become a hacking bird.

Most large companies hit by hack attacks, survey shows (Oct 12)

Is this year turning out to be even worse for getting hacked than last year? That's what a survey of 350 IT and network professionals would indicate, with large companies in particular reporting this to be worse than last in terms of suffering at least one network intrusion of their user machines, office network or servers.

Security failings to blame for major attacks, says Verizon (Oct 11)

The lack of a secured infrastructure is typically the reason hackers are able to gain access to enterprise servers and from there, implant malware to launch an attack, according to Verizon.

(Oct 11)

IT reseller CDW LLC found that 25% of 7,000 customers polled had experienced a network disruption of four hours or more within the past year.

(Oct 11)

In the slowly recovering economy, telecommuting has become an essential way for businesses to retain valuable workers, increase productivity, and support "green" initiatives. But from a security perspective, telecommuting can also be dangerous -- if you don't have the right technologies in place.

(Oct 7)

Many email users around the world have been unable to send messages because of ongoing technical problems with a popular service designed to prevent spam from reaching its intended destination.

(Oct 7)

A new XSS (cross site scripting) vulnerability was identified on Paypal.com earlier today, found by a researcher who goes by the name d3v1l and disclosed on both Security-Shell and XSSed. That bug would allow a malicious hacker to insert code on the site that could potentially be used to access a user's account.

Voice-routing call fingerprint system fights 'vishing' (Oct 7)

Security researchers in the States say they have developed a cunning new method of "fingerprinting" voice calls that could offer a route to trustworthy caller ID and a barrier against so-called "vishing" or voice phishing.

Most infrastructure firms feel ready for cyberattacks (Oct 7)

Nearly half of those who work in critical infrastructure systems worldwide expect their company to be targeted by a computer attack over the next year, a new survey has found.

Hackers hijack internet voting system in Washington DC (Oct 7)

An internet voting system designed to allow District of Columbia residents to cast absentee ballots has been put on hold after computer scientists exploited vulnerabilities that would have allowed them to rig elections and view secret data.

Criminal Hackers Create 3 Million Fraudulent Websites Annually (Oct 7)

A recent study shows that organized criminals create approximately 8,000 malicious websites every day, or over 57,000 each week.

Keeping the masses safe on the Internet (Oct 7)

Recognizing that all the technology in the world can't protect the Internet from attacks, the security industry is targeting an education campaign at the weakest link--the computer users.

Waging crypto wars 2.0 (Oct 7)

I was drawn to security in the early 90s during the crypto battle against the U.S. government, which was trying to force companies to adopt broken encryption with built in backdoors, like the failed Clipper Chip. Fortunately, the crypto wars were won by the side of reason, not least because of activists hoarding crypto technology in offshore locations.

Outgrowing QuickBooks? Maybe open source ERP can help (Oct 7)

Recent surveys have found that small and medium-size businesses are increasingly willing to consider open source tools. Not surprisingly, small businesses and large enterprises are predisposed to different categories of open source software. Survey data suggest that ERP is one category where small businesses are more likely to adopt open source than their large enterprise peers.

Man ordered to pay Facebook $1bn (Oct 7)

A Canadian man has been ordered to pay Facebook $1bn Canadian for a barrage of more than four million penis-enlargement ads he posted on user walls in 2008.

Hackers hijack open-source internet voting system (Oct 6)

An internet voting system designed to allow District of Columbia residents to cast absentee ballots has been put on hold after computer scientists exploited vulnerabilities that would have allowed them to rig elections and view secret data.

Two Top Tools for Cracking the PDF Nut (Oct 6)

Okular and Evince are two excellent, versatile PDF viewers for the Linux platform. The big difference between the two rests in the interface. Evince has a much simpler design. Okular is more focused on a graphical view. If all you do is view documents, then either of these two programs will serve your needs well.

Hackers break into Cryptome whistleblowing site (Oct 6)

The Cryptome whistleblowing website was hacked last weekend in an attack that could have compromised sensitive data, possibly including the email addresses of top secret sources for leaks sent to the site.

(Oct 6)

Recent attacks that use the increasingly popular Zeus Trojan are demonstrating that widely used methods of out-of-band authentication might be flawed, experts say.

Four months jail for refusing to disclose password (Oct 6)

A UK court sentenced a 19 year old to four months in prison because he refused to give authorities the password for an encrypted file on his PC. Oliver Drage, 19, of Liverpool was arrested in May 2009 by police who had seized his computer in connection with an investigation into child sexual exploitation.

(Oct 5)

The self-styled campaigners who launched DDoS attacks on a range of prominent copyright and anti-piracy organisations last week have threatened further attacks in an interview with security company, Panda Security.

iPhone apps transmit users' UDIDs (Oct 5)

Some two thirds of popular Apple iPhone applications transmit users' UDIDs, leading to potential security concerns, a new study has warned.

MySQL update addresses DoS vulnerability (Oct 5)

Oracle has released version 5.1.51 of MySQL, a security update that addresses a Denial of Service (DoS) vulnerability in the open source database. According to security specialist Secunia, an error in the processing of arguments passed to the LEAST() or GREATEST() functions could be exploited by a malicious user to cause a server crash, leading to a DoS condition. All versions up to and including 5.1.50 are reportedly affected.

Why cyber security is crucial for government (Oct 5)

In 2007, the UK government admitted that its revenue and customs department lost the details of 25 million individuals (nearly 40% of the population). The incident caused a public outrage and the British prime minister was forced to apologise to the nation.

Is your computer a zombie? (Oct 5)

You might think that since you use a personal laptop at home, and not a computer at a cafe, you are safe from hackers. Well, think again. Hackers don't even need to have physical access to your computer to be privy to all the information it contains.

Fedora 14 Linux Boosts Security with OpenSCAP (Oct 5)

Security is always a primary concern for enterprise IT managers, with a constant need to ensure that systems are kept updated and properly configured to prevent exploits. A new tool debuting in the upcoming Red Hat-sponsored Fedora 14 Linux release could prove a key ingredient in enabling properly secured systems.

4 Open and Free Disk and NAS Encryption Projects (Oct 5)

As usual, the Free/Open Source software world provides the best security utilities for Windows, and for Linux and Mac as well. Eric Geier rounds up four encryption utilities for both local and network storage.