Linux.com

NewsVac: News from around the Web

  • Which Top Apps Have the Most Security Holes? 11 months, 2 weeks ago
    Some of the most-used applications on Windows today are also some of the most vulnerable to security flaws. And it's often the user's fault.
  • MySQL 5.1 Takes Off Despite Controversy 11 months, 2 weeks ago
    Ten days after first being officially released as generally available (GA), software, Sun Microsystems is now claiming its open source MySQL 5.1 database server is being well received. It's a claim that stands in contrast to the initial claim of MySQL founder Monty Widenius who last week published a long diatribe discussing the multiple failures of MySQL 5.1.
  • RIM Aims to Boost Security Technology 11 months, 2 weeks ago
    Research in Motion is making a $66 million dollar hostile bid to acquire security cryptography company Certicom Corp.
  • Microsoft and RSA partner on Data Loss Prevention 11 months, 3 weeks ago
    Microsoft and EMC's RSA on Thursday announced an expanded technology partnership around digital rights management in the enterprise.
  • Growth in Internet crime calls for growth in punishment 11 months, 3 weeks ago
    Internet crime is now more prevalent and more professional than ever before. F-Secure believes that against a background of steeply increasing Internet crime, the obvious inefficiency of the international and national authorities in catching, prosecuting and sentencing Internet criminals is a problem that needs to be solved.
  • Expand your user-authentication options with mouse dynamics 11 months, 3 weeks ago
    In this article, learn how to apply the open source tools cnee and Perl in mouse-click dynamics to measure the more subtle characteristics of human-computer interaction. Also, learn how to use the number and hold time of mouse-click events to help authenticate users.
  • Set up a SSH-based point to point connection 11 months, 3 weeks ago
    OpenSSH version 4.3 introduced a new feature: the ability to create on-the-fly "Virtual Private Networks" via the tunnel driver (the so-called "tun" driver). This allows you to create a network interface that bridges two physically disparate network segments in different locations. This article explains how to use SSH to set up SSH-based point to point connections with OpenSuse 11.0 which can then be used to create routes that create virtual private networks.
  • Mobile eID security issues examined by ENISA 12 months ago
    In the near future, we will pay our taxes, buy metro tickets or open bank accounts over our phone. Mobile devices, national ID-cards, smart phones and PDAs, will play an ever more important role in the digital environment. However, as is the case with many new technologies, the pervasive use of mobile devices also brings new security and privacy risks. ENISA looks at different use-cases for electronic authentication using mobile devices. They identify the security risks which need to be overcome, give an opinion about their relevance, and present mechanisms that help in mitigating these risks.
  • Worst-ever software security blooper? 1 year ago
    T-Mobile has issued an over-the-air fix for a laughable Android security bug that caused anything typed into its G1 phone to be interpreted by a root shell process. Prior to the fix, hackers briefly enjoyed root shell access, leading to such fun as Debian installations on
  • Yoggie opens up its miniature hardware firewall 1 year ago
    Yoggie Security Systems launched its new Open Firewall Pico and Open Firewall SOHO, the first open hardware firewalls based on its Gatekeeper technology. The Open Firewall products are extremely powerful Linux-based miniature computers with 520 MHz ARM CPU, 128 RAM and 128 Flash memory. These unique products will enable developers, security professionals and hobbyists to experiment with Yoggie's own open source hardware firewall for the first time.
  • Chinks Appear in WPA's Wireless Security Armor 1 year ago
    A partial crack could signal problems ahead, given today's wide reliance on WPA for wireless security.
  • Install and Configure Nagios to Administer a Networking System 1 year ago
    Learning Nagios 3.0 is a new book from Packt that will introduce Nagios to System Administrators who are interested in monitoring and maintaining their systems. Written by Wojciech Kocjan, this book will help users understand how Nagios works, and help set up and configure its latest version.
  • G1 is Jailbroken 1 year ago
    Well, it didn't take too long. G1 is jailbroken. Full system access, read and write, has been obtained. And this method is quite easy. A few folks at the xda-developers forum discovered you can start telnet on the device by downloading PTerminal from Android Market, and then you can telnet to the device from your computer.
  • Critical vulnerability in Adobe Reader 1 year ago
    Core Security Technologies issued an advisory disclosing a vulnerability that could affect millions of individuals and businesses using Adobe’s Reader PDF file viewing software. Engineers from CoreLabs determined that Adobe Reader could be exploited to gain access to vulnerable systems via the use of a specially crafted PDF file with malicious JavaScript content. Successful exploitation of the vulnerability requires that users open a maliciously crafted PDF file thereby allowing attackers to gain access to vulnerable systems and assume the privileges of a user running Acrobat Reader. Adobe Reader version 9, which was released in June 2008, is not vulnerable to the reported problem.
  • Android-Powered G1 Mobile Phone Flaw Patched 1 year ago
    On October 24th, as Lisa reported, a serious vulnerability was discovered in the Google Android powered G1 mobile phone. Though security researchers classified the flaw in the Android browser as serious, Google assured users that the risk wasn't necessarily as dire as it seemed, due to the way the Android operating system restricts each application to its own area.
  • More News

Linux.com : Security

Barracuda offers a new -- and free -- alternative to Spamhaus

By Robin 'Roblimo' Miller on December 17, 2008 (7:00:00 PM)

For many years Spamhaus has been top dog in the anti-spam world of DNSBL (Domain Name System Block List; also known as Realtime Blackhole Lists or RBLs). But Spamhaus is no longer a 100% free service. Even small nonprofits are now expected to pay at least $250 per year for a subscription to the Spamhaus DNSBL Datafeed Service. Now a new, free alternative to Spamhaus has arrived: the Barracuda Reputation Block List (BRBL), provided by well-known, open source-based Barracuda Networks. And Barracuda CEO Dean Drako says the company has no plans to charge for the service in the future. He says that BRBL (pronounced "barbell") "does cost us a little bit of money to run, but we think that the goodwill, the reputation and the understanding that Barracuda is providing the service will do us well in the long run."

Read the Rest - 26 comments

Protecting networks with SmoothWall Express

By Joseph R. Baxter on December 09, 2008 (9:00:00 AM)

Corporations and home users alike need firewall protection. Many choices abound, including some expensive, commercial options that only run on specialized hardware. Others, like SmoothWall Express, are freely downloadable, built on the same technology as the commercial solutions, and even deliver some superior features.

Read the Rest - 13 comments

Open source Untangle guard union's privacy

By Ian Palmer on November 24, 2008 (8:00:00 PM)

When Maine State Employees Association SEIU Local 1989 needed software to safeguard confidential information and ward off online threats, it found an open source solution. The labor union, which represents more than 15,000 public and private sector workers throughout the State of Maine, chose Untangle's open source Gateway platform, a solution that not only helps keep confidential data away from prying eyes, but also protects against spam, spyware, phishing, and viruses.

Read the Rest - Post Comment

Access remote network services with SSH tools

By Keith Fieldhouse on November 11, 2008 (9:00:00 AM)

You probably rely on the services on your own private network -- wikis, mail servers, Web sites, and other applications you've installed. What happens when you have to leave the friendly confines of your network? With minimum exposure and few simple tools, you can get all of the comforts of home anywhere you can find an Internet connection.

Read the Rest - 11 comments

Automatically mount encrypted filesystems at login with pam_mount

By Ben Martin on November 06, 2008 (4:00:00 PM)

The pam_mount project lets you unlock an encrypted filesystem automatically when you log in. The same password used to log in is used as the key to unlock the encrypted filesystem, so you only need to type it once. Using this method, you can easily share a laptop and have only a single user's home directory unlocked and mounted when he logs in. And pam_mount can mount any filesystem, not just encrypted filesystems, so you can use it, for example, with an NFS share that you are interested in but which you might not like to leave mounted when you are not logged in.

Read the Rest - 6 comments

Portrait: Metasploit godfather H.D. Moore

By Tina Gasperson on October 30, 2008 (6:00:00 PM)

The Metasploit Project develops a set of security tools to create and execute exploit code on remote computers. Some people say Metasploit makes the job easier for black hat hackers who attack networks looking for vulnerabilities to take advantage of; others says the tool helps network security administrators do a better job of finding and repairing weaknesses before the bad guys get to them. H.D. Moore, the 20-something creator of the Metasploit Project, says it all depends on your perspective.

Read the Rest - 5 comments

Four password lockers that can help you keep your Web logins secure

By Ben Martin on October 21, 2008 (9:00:00 AM)

It is good practice to use a different password for each Web site you need to log in to. Good passwords tend to be long and contain a wide selection of characters. That can make remembering all your passwords difficult. But you can make things easier on yourself by storing passwords for various Web sites in an encrypted file on your computer. I'll take a look at a four programs that give you easy access to your passwords when you need them and protect the password file itself against compromise.

Read the Rest - 19 comments

Let PAM take care of GNU/Linux security for you

By Federico Kereki on October 14, 2008 (9:00:00 AM)

When they hear the word PAM, most people think of a certain blonde Canadian Playmate, but readers of this Web site surely will recognize the basic element of Linux security: the Pluggable Authentication Modules. So let's talk about how this PAM works, and look at some examples of how it is used.

Read the Rest - 6 comments

Security scans with OpenVAS

By Federico Kereki on October 09, 2008 (9:00:00 AM)

As important as security is, remaining current with every development is hard, and evaluating possible vulnerabilities across a network can be quite a chore. You need a way to both automate tests and make sure you're running the most appropriate and up-to-date tests. Open Vulnerability Assessment System (OpenVAS) is a network security scanner that includes a central server and a graphical front end. The server allows you to run several different network vulnerability tests (NVT) written in Nessus Attack Scripting Language (NASL), which OpenVAS updates frequently.

Read the Rest - Post Comment

Protect your network with pfSense firewall/router

By Cory Buford on October 03, 2008 (9:00:00 AM)

pfSense is a free, powerful firewall and routing application that allows you to expand your network without compromising its security. Started in 2004 as a child project of m0n0wall -- a security project that focuses on embedded systems -- pfSense has had more than 1 million downloads and is used to protect networks of all sizes, from home offices to large enterprises. pfSense has an active development community, and more features are being added in each release to further improve its flexibility, scalability, and, of course, security.

Read the Rest - 10 comments

Simplify system security with the Uncomplicated Firewall

By Michael Anckaert on October 01, 2008 (4:00:00 PM)

The Uncomplicated Firewall (UFW) is a new tool from Ubuntu whose goal is to make configuration of the built-in Linux packet filter less complicated and more secure for novice users.

Read the Rest - 12 comments

Setting up your own certificate authority with gnoMint

By Ben Martin on September 30, 2008 (9:00:00 AM)

gnoMint is a desktop application that lets you easily manage your own certificate authority (CA). Many secure communications technologies use digital certificates to ensure that the party or service they are connecting with is not an impostor. For many people, the main exposure to digital certificates comes when they visit an HTTPS Web site and see a certificate to validate that they have contacted the right Web server.

Read the Rest - 3 comments

Track your missing laptop with Adeona

By Nathan Willis on September 23, 2008 (9:00:00 PM)

Almost every laptop on sale today comes equipped with the Kensington security slot on the side or back, through which you can connect a theft-deterring locked steel cable. The system's down sides are (a) that a would-be thief can damage or destroy your equipment trying to yank the cable out, and (b) that you have to buy the cable separately. As an alternative, the free software utility Adeona won't preemptively deter theft, but it will help you track down your stolen equipment and better the chances of its recovery by police.

Read the Rest - 21 comments

Securing your network with PacketFence

By Cory Buford on September 23, 2008 (4:00:00 PM)

Network access control (NAC) aims to unify endpoint security, system authentication, and security enforcement in a more intelligent network access solution than simple firewalls. NAC ensures that every workstation accessing the network conforms to a security policy and can take remedial actions on workstations if necessary. For example, NACs can check if a workstation has antivirus software installed and, if not, NAC will limit the workstation's access to the network. In some cases, if NAC is capable of remedial measures, it can force-install an antivirus program on the workstation so that it will conform to the security policy. Although NAC can improve the security of your environment, most commercial NACs cost several thousand dollars. However, using NAC does not need to be that expensive. PacketFence, a free open source NAC application, gives you the security of NAC for free.

Read the Rest - 2 comments

Securing your network premises with Endian

By Cory Buford on September 15, 2008 (4:00:00 PM)

Unified Threat Management (UTM) devices unify all network security elements into a single device. They often include a combination of routing, firewall, intrusion detection, content filtering, URL filtering, spam filtering, VPN, and antivirus functionalities. These devices usually cost thousands of dollars and require subscriptions. However, you can secure your network and save money at the same time with Endian Firewall Community, a free, open source alternative to costly UTM devices.

Read the Rest - 3 comments

Protecting your network with Strata Guard Free

By Cory Buford on September 12, 2008 (9:00:00 AM)

Being connected to the Internet means exposure to what the outside world has to offer -- including the undesirable elements. Every time you connect to the Internet, you're exposed to threats that can compromise your network's security. Although network security solutions have evolved in recent years, so have network attack techniques. To prevent ever-evolving attacks from compromising your network, you must preemptively block malicious traffic before it enters your network. Free, open source programs, such as Snort, can do the job, but setting up a full intrusion detection system (IDS) sensor, especially in an enterprise network, takes time and isn't very user-friendly. StillSecure's Strata Guard Free can be your front line of defense to face outside threats without as much hard work.

Read the Rest - 4 comments

Protecting your MySQL database from SQL injection attacks with GreenSQL

By Ben Martin on August 25, 2008 (4:00:00 PM)

SQL injection attacks can allow hackers to execute arbitrary SQL commands on your database through your Web site. To avoid these attacks, every piece of data supplied by a user on a Web form, through HTTP Post or CGI parameters, or other means, must be validated to not contain information that is not expected. GreenSQL is a firewall for SQL -- it sits between your Web site and MySQL database and decides which SQL statements should and should not be executed. At least that's the idea -- in execution, I found some open doors.

Read the Rest - 19 comments

Set up your firewall with Firewall Builder

By Ben Martin on August 14, 2008 (9:00:00 AM)

Firewall Builder (fwbuilder) is a graphical application that can help you to configure IP traffic filtering. It can compile the filtering policy you define into many specifications, including iptables and various languages used by Cisco and Linksys routers. Separating the actual policy you define and the implementation in this way should let you change what hardware is running your firewall without having to redefine your policy for that platform.

Read the Rest - 6 comments

A hands-on look at Vyatta Community Edition 4 networking software

By Cory Buford on August 13, 2008 (4:00:00 PM)

Vyatta offers hardware and open source software for enterprise-level network infrastructure. Vyatta can turn any 32-bit x86 machine with at least one network interface into a network appliance that handles routing, firewall, and VPN tasks. The company released Vyatta Community Edition 4 in April, with improved scalability and feature enhancements. Large enterprises now have a low-cost alternative to proprietary hardware like the Cisco 7200.

Read the Rest - Post Comment

Testing Web application security using Google's ratproxy

By Keith Winston on July 29, 2008 (4:00:00 PM)

To help developers audit Web application security, Google has released an open source tool called ratproxy. It is a non-disruptive tool designed for Web 2.0 and AJAX applications that produces an easy-to-read report of potential exploits.

Read the Rest - Post Comment

  |<   <<   1   2   3   4   5   6   7   8   9   10   >>   >|


 
Tableless layout Validate XHTML 1.0 Strict Validate CSS Powered by Xaraya