General Esm W900
Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines.

LinuxSecurity.com Feature Extras:

Review: The Official Ubuntu Book - If you haven't used Linux before, are new to Ubuntu, or would like a quick update on the latest in open source advancements for the desktop, then The Official Ubuntu Book is a great place to start. Authored by a group of some of the most experienced open source administrators and developers, this 400-page user guide details everything you need to know about how to make the most of your Ubuntu, Kubuntu (Ubuntu with KDE), and Xubuntu (Ubuntu with Xfce) computer.

Review: Zabbix 1.8 Network Monitoring - If you have anything more than a small home network, you need to be monitoring the status of your systems to ensure they are providing the services they were designed to provide. Rihards Olups has created a comprehensive reference and usability guide for the latest version of Zabbix that anyone being tasked with implementing should have by their side.


Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.

(Oct 4)

If there's going to be a quick resolution to the net neutrality debate, it won't come from Congress. Democrat Senator Henry Waxman says he's dropping plans for legislation after failing to secure the backing of his Republican opponents.

In Security Outsourcers We Trust (Oct 4)

IT and business leaders acknowledge they don't have the staff or expertise to secure their data internally -- at least not without help from outside experts. If you work for a managed security service provider (MSSP), that's good news.

Anti-virus vendor trio plug website flaws (Oct 4)

White-hat hackers have uncovered vulnerabilities on the websites of anti-virus firms that created a phishing risk. Cross-site scripting (XSS) bugs of varying severity were found on the websites of Symantec (here), Eset (here) and Panda Security (here) by Team Elite, the white-hat hackers who discovered the flaws. We notified all three firms of the issue and all three responded by plugging the flaws in good time.

(Oct 1)

A cyber worm experts believe was designed to knock out Iran's nuclear facilities has the security industry seeing red -- and rightly so. Replicating the virus would be easy, say experts, thanks to an easily accessible black market for destructive programming code.

5 Things Linux Does Better Than Mac OS X (Oct 1)

Were it not for Windows' long-standing installed base and overwhelming market dominance, it seems unlikely that anyone would argue seriously for the merit of the operating system, plagued as it is by high prices, security problems and vendor lock-in.

(Oct 1)

October is National Cyber Security Awareness Month. Consumers must be employ the latest in security technology and the same intuition they use in the "offline" world. "Cyber criminals are opportunistic," says Consumer Affairs Director Mary Clement. "They seek out vulnerabilities on computers to send spam and phishing e-mails, or try to trick consumers into providing information that allows them to wipe out bank accounts and steal identities."

(Oct 1)

Security firm PandaLabs recently spoke with hacker group Anonymous about its global cyber-war with the pro-copyright industry. Called "Operation Payback," the DDoS assault was triggered by a similar attack on file sharing sites by an Indian firm. Now Anonymous is in offensive mode and looking to sign on more members by sending out flyers and recruiting people through Facebook, Digg, Reddit and other sites.

Trust No One, Monitor Everyone? (Oct 1)

The so-called Zero Trust model for security proposed by Forrester Research earlier this month has revived debate about the way organizations secure their networks.

A Tale of Two Root Exploits, and Why We Shouldn't Panic (Sep 30)

"The article is alarmist," said Slashdot blogger Barbara Hudson, referring to a warning about a kernel bug. "It was ONE shared-hosting public-facing server at iWeb.com, among their tens of thousands of servers. "Are you running a publicly-facing shared-host server? No? Then don't worry about it, and when your distro comes out with a new kernel, just update."

(Sep 30)

Security breaches aren't just for the White House anymore. October is National Cyber Security Awareness Month, and the National Cyber Security Alliance is looking to raise awareness among college students to help them stay safe and secure online.

VoIP Abuse Project Blacklists Attackers (Sep 30)

A security expert at a managed services provider has kicked off a project to expose and blacklist the networks hosting VoIP attacks against his and other companies' VoIP PBX servers. The VoIP Abuse Project uses a honeypot to gather as much data as it can from incoming VoIP attacks, including the IP address and a recording of what the call was sending.

(Sep 29)

I can always tell how comfortable a person is with the concept of information security when I interview them. Someone who really has a passion for it and knows their stuff will keep me on the phone for hours and take me deep into the weeds of their procedures. Someone who is uncomfortable will simply clam up.

(Sep 29)

A recent Apple patent and a strongly worded report from the National Research Council suggest that the future of biometrics lies with personalization, not security.

(Sep 29)

Wikipedia co-founder Jimmy Wales has launched a strongly-worded attack on controversial whistleblowing site Wikileaks, accusing it of risking lives with some of its recent Afghan war disclosures.

What's up with encryption? (Sep 29)

Encryption is hot. Perhaps that's because its been around so long it's no longer seen as a black art. Or perhaps security issues have grown so prevalent, everyone wants some sort of encryption as a truly secure way of stopping the pain of those problems.

DDoS attackers line up new targets (Sep 29)

Hackers are preparing to raise the stakes in their next assault on anti-piracy organisations after they crippled the website of the Australian Federation Against Copyright Theft (Afact) on Tuesday.

Google adds OAuth support to Google Apps (Sep 28)

Joining a growing number of enterprise and consumer-facing Web services, Google has added support in Google Apps for the OAuth authorization profile, the company announced Monday.

(Sep 28)

Client/server systems with SQL interfaces jockey for position against upstart NoSQL systems with intimidating (and exciting) new models for data representation, distribution and consistency. In addition, more than a dozen embedded and special purpose databases have grown up to serve the needs of applications too small or too agile to require a full RDBMS.

Spamhaus Debuts New Whitelist Service (Sep 28)

The Spamhaus Project has debuted a new whitelisting service that is designed to be the inverse of the way that most approved-sender lists work. The Spamhaus Whitelist will exclude by default any IP address or domain that sends marketing or soliciting mail at all and will require domain owners to have an inviation in order to join the whitelist.

Anti Piracy Law Firm Emails Leaked Via BitTorrent (Sep 28)

After the piracy activist group known as 4can targeted the MPAA and RIAA websites with a distributed denial of service (DDoS) attack one week ago, a group of activists has locked on a new target: anti-piracy lawyers.

(Sep 28)

Monitoring for security incidents can be tough. It's tougher when you don't know what to look for. Now, imagine trying to investigate an incident when you don't have any logs to analyze.

(Sep 27)

Like you, I have also read many articles covering small business security, the authors of which have made up various lists of "top X threats" or "this year's biggest vulnerabilities," etc. So I thought it would be interesting to dig into a sampling of the data breach reports and collect some real data on causes of breaches and other security incidents in SMBs.

Pirate Bay typo-squatted by hackers (Sep 27)

For years the Pirate Bay file-sharing index portal has skated on legally thin ice, but now the site's search engine popularity has ironically been hijacked by typo-squatting hackers.

Software security for developers (Sep 27)

Just as software is everywhere, flaws in most of that software are everywhere too. Flaws in software can threaten the security and safety of the very systems on which they operate. The best way to prevent such vulnerabilities in software is to proactively incorporate security and other non-functional requirements into all phases of Software Development Lifecycle (SDLC).

Hackers who disrupted Comcast.net site sentenced (Sep 27)

Two of the three hackers who disrupted the website Comcast Corp. maintains for its Internet customers were sentenced to 18 months in prison Friday by a federal judge in Philadelphia.

Top Five Reasons Database Security Fails In The Enterprise (Sep 27)

Though database security best practices have circulated the conference circuit for years now and existing database security tools are now mature, today's typical enterprise is still far behind in shoring up its most sensitive stores of data.

The enigma of a code-breaker's death (Sep 26)

On Friday, in the Bethel Methodist Chapel in Angelsey, the funeral was held of Gareth Williams. In life, he was a mathematician and an encryption specialist so highly regarded that he was seconded from GCHQ in Cheltenham to work at MI6 in London.