Thank you for reading the LinuxSecurity.com weekly security newsletter.
The purpose of this document is to provide our readers with a quick
summary of each week's most relevant Linux security headlines.
Review: The Official Ubuntu Book - If you haven't used Linux before, are new to Ubuntu, or would like a quick update on the latest in open source advancements for the desktop, then The Official Ubuntu Book is a great place to start. Authored by a group of some of the most experienced open source administrators and developers, this 400-page user guide details everything you need to know about how to make the most of your Ubuntu, Kubuntu (Ubuntu with KDE), and Xubuntu (Ubuntu with Xfce) computer.
Review: Zabbix 1.8 Network Monitoring - If you have anything more than a small home network, you need to be monitoring the status of your systems to ensure they are providing the services they were designed to provide. Rihards Olups has created a comprehensive reference and usability guide for the latest version of Zabbix that anyone being tasked with implementing should have by their side.
|
|
|
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.
|
|
(Sep 27) |
|
Like you, I have also read many articles covering small business security, the authors of which have made up various lists of "top X threats" or "this year's biggest vulnerabilities," etc. So I thought it would be interesting to dig into a sampling of the data breach reports and collect some real data on causes of breaches and other security incidents in SMBs.
|
|
Pirate Bay typo-squatted by hackers (Sep 27) |
|
For years the Pirate Bay file-sharing index portal has skated on legally thin ice, but now the site's search engine popularity has ironically been hijacked by typo-squatting hackers.
|
|
Software security for developers (Sep 27) |
|
Just as software is everywhere, flaws in most of that software are everywhere too. Flaws in software can threaten the security and safety of the very systems on which they operate. The best way to prevent such vulnerabilities in software is to proactively incorporate security and other non-functional requirements into all phases of Software Development Lifecycle (SDLC).
|
|
Hackers who disrupted Comcast.net site sentenced (Sep 27) |
|
Two of the three hackers who disrupted the website Comcast Corp. maintains for its Internet customers were sentenced to 18 months in prison Friday by a federal judge in Philadelphia.
|
|
Top Five Reasons Database Security Fails In The Enterprise (Sep 27) |
|
Though database security best practices have circulated the conference circuit for years now and existing database security tools are now mature, today's typical enterprise is still far behind in shoring up its most sensitive stores of data.
|
|
The enigma of a code-breaker's death (Sep 26) |
|
On Friday, in the Bethel Methodist Chapel in Angelsey, the funeral was held of Gareth Williams. In life, he was a mathematician and an encryption specialist so highly regarded that he was seconded from GCHQ in Cheltenham to work at MI6 in London.
|
|
(Sep 24) |
|
I've said it before, use upper and lower case, use number and letter combinations and when possible, if the website allows it, use special characters. It has been documented that "Adding just one capital letter and one asterisk would change the processing time for an 8 character password from 2.4 days to 2.1 centuries."
|
|
Is your PC a sitting duck for hackers? (Sep 24) |
|
How confident are you that your computer is safe from an online attack? Chances are you rely on vendors like Microsoft and Apple to let you know when a security update is ready to be installed. (Google updates systems automatically.)
|
|
(Sep 24) |
|
Developers of Samba have warned that every edition of Samba has severe vulnerability, which cyber-criminals can abuse without difficulty. The flaw makes all Samba versions till as early as 3.0 vulnerable. Incidentally, the 3.0 version was launched over 5 years back.
|
|
(Sep 23) |
|
Preconceptions that some operating systems are safer than others are misguided, a security expert has claimed. In reality all systems have their flaws which hackers will attempt to exploit and, despite some people's belief Linux and Mac users are safer, all are vulnerable, said David Jacoby, a senior security researcher at Kaspersky.
|
|
OAuth 2.0 API security tool used by Facebook too easy to crack (Sep 23) |
|
The emerging OAuth 2.0 web API authorisation protocol, already deployed by Facebook, Salesforce.com and others, is coming under increased criticism for being too easy to use, and therefore to spoof by malicious hackers.
|
|
Twitter 'mouseover worm hacker' Pearce Delphin is Australian schoolboy (Sep 23) |
|
It infected thousands of Twitter accounts, even reaching the White House itself. But the virus that caused havoc on the microblogging site was not started by a shadowy group of hackers - it was discovered by a 17-year-old schoolboy.
|
|
Hackers Find New Ways To Assume Identities (Sep 22) |
|
Although cyber scamming is nothing new, the way thieves use the data is constantly changing, and social media is a gateway to the latest scams. Identity theft experts fear that by sharing seemingly mundane personal details and preferences on social networking sites, people might be giving the bad guys clues about their security codes.
|
|
The Cookies You Can't Remove (Sep 22) |
|
They say that some things last forever, like diamonds or true love or Twinkies. But should browser cookies used for tracking be added to that list?
|
|
Hackers Hit Twitter More for Devilry Than Profit (Sep 22) |
|
The latest hacker to hit Twitter this week unleashed a smutty bit of code that redirected unwitting users to a porn site. Such hacks are certainly unwelcome, but they resemble the not-for-profit pranks pulled by hackers of a bygone era. Nowadays, black-hat hacking is big business. Will malware writers soon see more financial opportunities in attacking Twitter?
|
|
(Sep 22) |
|
Linux is well-known for its security advantages over many other operating systems, but that doesn't mean it's immune to problems. A Linux kernel flaw first discovered earlier this month, for example, gives hackers a way to not just gain root privileges in 64-bit Linux operating systems but also to leave a "back door" open for further exploitation later.
|
|
Vulnerability management: The basics (Sep 21) |
|
The more apps companies deploy, the more complicated vulnerability management becomes. In the rush to find every security hole and seal it off from potential hackers, it's easy to let something important slip through. That's especially true if you're an IT administrator juggling several tasks of which security is one.
|
|
(Sep 21) |
|
The past week in security saw the HDCP master key get exposed, HP's deal to purchase ArcSight and revelations about the Stuxnet worm targeting industrial systems.
|
|
Implementing two Factor Authentication on the Cheap (Sep 21) |
|
Typically, implementing two factor authentication means buying tokens or smart cards for all of your users. This can be expensive (from what I have seen $50/user is typical in smaller deployments) and it is only manageable for users with whom you have an existing relationship (employees, in some cases customers).
|
|
(Sep 21) |
|
Corporate video conferences can still be easily hacked by insiders using a freeware tool that allows attackers to monitor calls in real-time and record them in files suitable for posting on YouTube.
|
|
Linux kernel exploit roots 64-bit machines (Sep 21) |
|
Attackers have used a freely available exploit to target a number of 64-bit Linux machines, according to a Linux patch management software firm.
|
|
Fake iPhone jail-breaking tool packed with malware (Sep 21) |
|
Malicious hackers are preying on iPhone users who want to jail-break their devices, exploiting the increased interest around jail-breaking tools to launch malware attacks.
|
|
'Hacktivity 2010' tackles computer security (Sep 20) |
|
Caterpillars, roaches and worms crawl on a computer, which represents an infected computer, next to a clean one, in a display that illustrates computer safety at Hacktivity, in Budapest. The major hackers' conference wrapped up in Hungary Sunday after higlighting protection against increasingly sophisticated computer piracy as the Internet becomes ever more present in daily life.
|
|
(Sep 20) |
|
The denizens of 4chan launched a series of distributed denial of service attacks against entertainment industry websites over the weekend, protesting legal actions against torrent tracker website the Pirate Bay.
|
|
Hackers meet in 'geeks' paradise' (Sep 20) |
|
Away from the elegance of Budapest's historic centre, a dingy rock venue has been turned into a geek's paradise. The laptop screens glow in the dim light as fingers flicker quickly over keyboards. Lines of code, incomprehensible to all but the cognoscenti, are typed out.
|
|
Google Is Making Your Account Vastly More Secure With Two-Step Authentication (Sep 20) |
|
"Two-factor authentication" may be the least sexy-sounding feature I've ever written about. But if you've ever worried about being phished or having your password hacked, it could be your best friend -- because it makes it much, much harder for a hacker to break into your account.
|