LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Advisory Watch: January 27th, 2012
Linux Advisory Watch: January 20th, 2012
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Linux Advisory Watch: January 27th, 2012  27 January 2012 
Source: LinuxSecurity Contributors - Posted by Benjamin D. Thomas   
Linux Advisory Watch Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system.
 
Hacking stunt: Stealing smartphone crypto keys using plain old radio  27 January 2012 
Source: Network World - Posted by Alex   
Hacks/Cracks Encryption keys on smartphones can be stolen via a technique using radio waves, says one of the world's foremost crypto experts, Paul Kocher, whose firm Cryptography Research will demonstrate the hacking stunt with several types of smartphones at the upcoming RSA Conference in San Francisco next month.
 
Judges set timetable for McKinnon case resolution  27 January 2012 
Source: The Register UK - Posted by Anthony Pell   
Government Senior judges have set a timetable to speed up resolution in the long-running Gary McKinnon extradition case, effectively setting a deadline for the Home Office to respond to evidence that McKinnon is too infirm to withstand the stress of a US trial and likely imprisonment over alleged Pentagon hacking offences.
 
Apache Shiro 1.2.0 enhances its password hashing  27 January 2012 
Source: H Security - Posted by Anthony Pell   
Security Projects Just over fourteen months since its first release as an Apache top-level project, the Apache Shiro developers have released version 1.2.0, the first major update to the Shiro application security framework.
 
Hackers ramping up their firepower, says study  27 January 2012 
Source: Infosecurity US - Posted by Dave Wreski   
Intrusion Detection Hackers have increased their firepower by 30% when they go after websites, according to Imperva’s second Web Application Attack Report (WAAR).
 
Security Software Aims To Trick Hackers  27 January 2012 
Source: WebPro News - Posted by Dave Wreski   
Latest News Hacker attacks are increasing and Web sites need new defenses to protect their data. That’s where Mykonos comes in, a security company that protects Web sites from attacks by wasting a hacker’s time instead of using an easily breakable wall.
 
DNSSEC Error Caused NASA Website To Be Blocked  26 January 2012 
Source: Dark Reading - Posted by Anthony Pell   
Server Security The hazards of early DNSSEC adoption: A misconfiguration in NASA’s Domain Name System Security Extensions (DNSSEC) implementation on its website caused Comcast’s network to block users from the site last week.
 
Hacktivists Turn To DNS Hijacking  26 January 2012 
Source: Dark Reading - Posted by Alex   
Hacks/Cracks Hacktivists have added a new tactic to their arsenal: redirecting all of the traffic from a target company's website.
 
Google stirs up privacy hornet's nest  26 January 2012 
Source: Network World - Posted by Dave Wreski   
Privacy Google has whipped up a privacy brouhaha with a blog post announcing that the company is rewriting its privacy policy , consolidating user information across its services.
 
Hackers use videoconferencing cameras to spy on boardroom meetings  26 January 2012 
Source: Tech World - Posted by Dave Wreski   
Privacy Teleconferencing vendors say they're trying to strike the right balance between security and usability after security researchers found they could dial in to the conference lines of major companies and manipulate video cameras to spy on boardrooms.
 
Hackers Breached Railway Network, Disrupted Service  25 January 2012 
Source: Wired - Posted by Alex   
Latest News Hackers attacked computers at an an unidentified railway company, disrupting railway signals for two days in December, according to a government memo obtained by Nextgov.
 
Google to combine users' data across its services  25 January 2012 
Source: Network World - Posted by Alex   
Privacy Google will be able to combine data from several Google services when a Google Accounts user is signed in, as part of a rewritten set of privacy policies that the company announced on Tuesday.
 
O2 sends users' phone numbers to web sites  25 January 2012 
Source: H Security - Posted by Dave Wreski   
Hacks/Cracks An O2 user, Lewis Peckover, found that the mobile phone company has been adding the phone number of any subscriber using its mobile network to the HTTP headers of web requests. The header, x-up-calling-line-id, appears to be inserted by the transparent proxies that O2 uses so it can downgrade images and insert JavaScript into the returned HTML.
 
Linux vendors rush to patch privilege escalation flaw after root exploits emerge  25 January 2012 
Source: PC Advisor - Posted by Dave Wreski   
Latest News Linux vendors are rushing to patch a privilege escalation vulnerability in the Linux kernel that can be exploited by local attackers to gain root access on the system.
 
    
Partner

 

Latest Features
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Using the sec-wall Security Proxy
sec-wall: Open Source Security Proxy
Sponsor:

 

Yesterday's Edition
Security Software Aims To Trick Hackers
Hackers ramping up their firepower, says study
Apache Shiro 1.2.0 enhances its password hashing
Judges set timetable for McKinnon case resolution
Hacking stunt: Stealing smartphone crypto keys using plain old radio
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2012 Guardian Digital, Inc. All rights reserved.