LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Security Week: February 6th, 2012
Linux Advisory Watch: February 3rd, 2012
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Hacker releases Symantec source code  08 February 2012 
Source: Reuters - Posted by Anthony Pell   
Hacks/Cracks A hacker released the source code for antivirus firm Symantec's pcAnywhere utility on Tuesday, raising fears that others could find security holes in the product and attempt takeovers of customer computers.
 
Trustwave admits issuing 'man-in-the-middle' digital certificate  08 February 2012 
Source: InfoWorld - Posted by Anthony Pell   
Cryptography Digital Certificate Authority (CA) Trustwave revealed that it has issued a digital certificate that enabled an unnamed private company to spy on SSL-protected connections within its corporate network, an action that prompted the Mozilla community to debate whether the CA's root certificate should be removed from Firefox.
 
Something fishy about Google Chrome's Safe Browsing API, lab says  08 February 2012 
Source: CSO Online - Posted by Dave Wreski   
Vendors/Products From the start, Google's Safe Browsing API was designed to spot malicious web pages so users wouldn't get trapped in them. Google identifies these sites through its own algorithms and user notification.
 
Mozilla explains user-tracking proposal for Firefox  08 February 2012 
Source: The Register UK - Posted by Dave Wreski   
Latest News In a story published yesterday your humble Reg writer wrongly confused Mozilla's Telemetry project with the open-source outfit's so-called Metrics Data Ping proposal. Mozilla has been in touch to clear things up.
 
Passive Network Fingerprinting; p0f Gets Fresh Rewrite  07 February 2012 
Source: Dark Reading - Posted by Anthony Pell   
Network Security In the network security world, nmap is the king for fingerprinting systems and services over the network. It can help identify the operating system (OS), type, and version of a network service, and vulnerabilities that might be present.
 
How (And Why) Attackers Choose Their Targets  07 February 2012 
Source: Dark Reading - Posted by Anthony Pell   
Hacks/Cracks Every day, we hear another story about a company whose sensitive data has been breached. Press releases, tweets, customer support email, and followup articles all provide insight into the kind of information that’s been compromised, the company’s plans to investigate, and how affected parties can protect themselves.
 
The in-depth guide to data destruction  07 February 2012 
Source: CSO Online - Posted by Dave Wreski   
Privacy A key part of any information security strategy is disposing of data once it's no longer needed. Failure to do so can lead to serious breaches of data-protection and privacy policies, compliance problems and added costs.
 
Hackers wanted $50,000 to keep Symantec source code private  07 February 2012 
Source: CNET - Posted by Dave Wreski   
Latest News As part of a sting operation, Symantec told a hacker group that it would pay $50,000 to keep the source code for some of the its flagship security products off the Internet, the company confirmed to CNET this evening.
 
Linux Security Week: February 6th, 2012  06 February 2012 
Source: LinuxSecurity Contributors - Posted by Benjamin D. Thomas   
Linux Security Week Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines.
 
Operation Ghost Click DNS servers to shut down in March  06 February 2012 
Source: CNET - Posted by Dave Wreski   
Intrusion Detection One of the more widespread malware efforts over the past few years was the DNSChanger scam, which installed a Trojan horse that would change the DNS server settings on affected computers to divert traffic to rogue servers.
 
Linux Advisory Watch: February 3rd, 2012  03 February 2012 
Source: LinuxSecurity Contributors - Posted by Benjamin D. Thomas   
Linux Advisory Watch Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system.
 
Kernel guru Greg Kroah-Hartman joins Linux Foundation  03 February 2012 
Source: InfoWorld - Posted by Anthony Pell   
Security Projects One of the principle maintainers of the Linux kernel, Greg Kroah-Hartman, has joined the Linux Foundation as a fellow, the same position held by Linux creator Linus Torvalds, the foundation announced. Kroah-Hartman previously worked at Suse Linux, also as a fellow.
 
Critical PHP vulnerability being fixed - Update  03 February 2012 
Source: H Security - Posted by Anthony Pell   
Vendors/Products The PHP developers are working to fix a critical security vulnerability in PHP that they introduced with a recent security patch. The current stable release is affected; however, it is not yet clear whether the questionable patch was also applied to older versions.
 
Mozilla releases Firefox 10 browser with nine security fixes  03 February 2012 
Source: Infosecurity US - Posted by Anthony Pell   
Vendors/Products Mozilla has released the latest version of its browser, Firefox 10, with fixes for nine security flaws, including five critical vulnerabilities.
 
    
Partner

 

Latest Features
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Using the sec-wall Security Proxy
sec-wall: Open Source Security Proxy
Sponsor:

 

Yesterday's Edition
Mozilla explains user-tracking proposal for Firefox
Something fishy about Google Chrome's Safe Browsing API, lab says
Trustwave admits issuing 'man-in-the-middle' digital certificate
Hacker releases Symantec source code
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2012 Guardian Digital, Inc. All rights reserved.