Thank you for reading the LinuxSecurity.com weekly security newsletter.
The purpose of this document is to provide our readers with a quick
summary of each week's most relevant Linux security headlines.
Review: The Official Ubuntu Book - If you haven't used Linux before, are new to Ubuntu, or would like a quick update on the latest in open source advancements for the desktop, then The Official Ubuntu Book is a great place to start. Authored by a group of some of the most experienced open source administrators and developers, this 400-page user guide details everything you need to know about how to make the most of your Ubuntu, Kubuntu (Ubuntu with KDE), and Xubuntu (Ubuntu with Xfce) computer.
Review: Zabbix 1.8 Network Monitoring - If you have anything more than a small home network, you need to be monitoring the status of your systems to ensure they are providing the services they were designed to provide. Rihards Olups has created a comprehensive reference and usability guide for the latest version of Zabbix that anyone being tasked with implementing should have by their side.
|
|
|
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.
|
|
(Oct 15) |
|
Which are the software world's most attacked applications? All applications are attacked to some extent but as time has gone on a favourite list has started to emerge based on two fundamental weaknesses: how widely used that application happens to be and how many software vulnerabilities, known and unknown, have been uncovered in it.
|
|
Six enterprise security leaks you should plug now (Oct 12) |
|
In modern enterprises, there's a similar perception of invulnerability. Yet, for every large organization that glides through the year without any mishaps, there are many stories about perilous break-ins, Wi-Fi sniffing snafus and incidents where Bluetooth sniper rifles were used to steal company secrets.
|
|
(Oct 14) |
|
One of the big differences between Linux and Windows is that Linux users don't typically have "root," or administrator, access. That's a very good thing for security, and it's something you should take care to preserve by not running as root unnecessarily.
|
|
Here's a crazy security idea - ditch Windows for Ubuntu 10.10 Linux (Oct 15) |
|
After some days with the latest Ubuntu Linux desktop release, I was planning to devote a few graphs to extolling its many virtues.
|
|
(Oct 14) |
|
Of the 40,000 networks identified in the six cities, just under 20,000 had no password or the most basic form of security encryption, the research for card protection and insurance company CPP found.
|
|
Security failings to blame for major attacks, says Verizon (Oct 11) |
|
The lack of a secured infrastructure is typically the reason hackers are able to gain access to enterprise servers and from there, implant malware to launch an attack, according to Verizon.
|
|
To Catch A Hacking Bird (Oct 12) |
|
The best way to secure your business, so the advice of many an IT security consultant appears to increasingly be, is to think like a hacker. Only by understanding how the bad guys get at your data can you truly prevent them succeeding: to catch a hacking bird, you have to become a hacking bird.
|
|
Trojan forces Firefox to secretly store passwords (Oct 13) |
|
A trojan recently analysed by Webroot is said to rely on retrieving web page passwords from a browser's password storage, rather than logging a user's keyboard inputs. To make sure it will find all the interesting passwords in Firefox, the malware, called PWS-Nslog, makes some changes to jog the browser's memory.
|
|
(Oct 11) |
|
In the slowly recovering economy, telecommuting has become an essential way for businesses to retain valuable workers, increase productivity, and support "green" initiatives. But from a security perspective, telecommuting can also be dangerous -- if you don't have the right technologies in place.
|
|
(Oct 11) |
|
IT reseller CDW LLC found that 25% of 7,000 customers polled had experienced a network disruption of four hours or more within the past year.
|
|
G2 doesn't have rootkit, it's just the same old NAND lock (Oct 12) |
|
Policy group New America has written a scathing blog entry that criticizes the HTC G2 for including a "hardware rootkit" that prevents users from installing custom firmware on the device. The report appears, however, to be based on a misunderstanding of technical issues raised in an XDA discussion thread.
|
|
Breakthrough Encryption Solution Selected for Debut at Hacker Halted Conference (Oct 14) |
|
At the 2010 Hacker Halted Conference in Miami on October 13, 2010, SECNAP Network Security will demonstrate the ease with which cyber sniffers, eavesdroppers and hackers can intercept email messages, despite widespread user trust that email messages are private and secure.
|