LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
How would you rate the importance of default settings in security?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
Emily Ratliff: OS Security
DanWalsh LiveJournal
Security Bloggers Network
Latest Newsletters
Linux Advisory Watch: July 4th, 2008
Linux Security Week: June 30th, 2008
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Linux Events
Patching Linux Kernel, Local Root Exploit  13 February 2008  Print E-mail
User Rating:      How can I rate this item?
Source: keneltrap - Posted by Bill Keys   
Host Security Patches for a much publicized Linux kernel local root exploit were released today as 2.6.24.2, 2.6.23.16, and 2.6.22.18. The latest bug, labeled as CVE-2008-0600, was introduced by the vmsplice() system call and added into the 2.6 kernel in 2.6.17. It is the third in a series of root exploits surrounding the same system call, the two earlier bugs being CVE-2008-0009 and CVE-2008-0010. Easily obtained exploits exist for both the older CVE-2008-0010 which affected the 2.6.23 and 2.6.24 kernels, and the latest CVE-2008-0600, allowing a local non-root user to gain root permissions. You mostly likely heard about the local root exploit patch which was released a few days ago. Any exploit dealing with the root users can be a serious problem. Have you patched your Linux Kernel yet?

Write Comment (1 Comments)

 
Open Source Tool of the Month: Nmap looks better than ever!  06 February 2008  Print E-mail
User Rating:      How can I rate this item?
Source: Linux.com - Posted by Ryan Berens   
Host Security In this review from Linux.com, you get into some of the details on our Open Source tool of the month. The Zenmap front end for Nmap is covered, its new enhancements as well as what to do with the Command Wizard. It also covers some of the basics on port scanners too... Sometimes criticized for helping the bad guys find opening in the cracks of sites on the Internet, their real value is in allowing network security pros -- and those trying to protect their own machines and networks -- to test their own defenses. They can help ordinary users learn more about networking and network security.

Write Comment

 
Anti Tamper Module for Apache  23 January 2008  Print E-mail
User Rating:      How can I rate this item?
Source: DarkNet - Posted by Bill Keys   
Host Security AntiTamper is an Apache 2.x module that could be used to prevent some sort of url and cookie tampering.

Specifically, AT could stop a lot of those malicious bots that take advantage from search engines. Moreover, attack techniques like HTTP Response Splitting and session hijacking/fixation will be mitigated. I am interested if anyone has tested out mod_anti_tamper. I like using mod_security but mod_anti_tamper look like it will work well side my side with mod_security increase a web servers security.

Write Comment

 
Gotroot Modsecurity Rules for Apache - Anti-spam and Security  03 January 2008  Print E-mail
User Rating:      How can I rate this item?
Source: DarkNet - Posted by Bill Keys   
Host Security ModSecurity is an open source intrusion detection and prevention engine for web applications (or a web application firewall). Operating as an Apache Web server module or standalone, the purpose of ModSecurity is to increase web application security, protecting web applications from known and unknown attacks. Anything which helps Web application to be more secure is a very good thing. Have you implemented ModSecurity on your Apache server?

Write Comment

 
Would We Need Antivirus For Desktop Linux?  13 December 2007  Print E-mail
User Rating:      How can I rate this item?
Source: Information Week - Posted by Ryan Berens   
Host Security Linux is often known for being a staple of security. Whether its about the kernel itself, the secured applications or in this case viruses, Linux has always been up to the challenge. what happens if the big boys like Symantec or Norton start making A/V for Linux platforms? Would it even be needed...

So what about viruses written specifically to target Linux? Yes, such beasts do indeed exist. That said, the nature of an open-source platform makes it that much easier (and faster) to close over the holes that they exploit. This is as it should be, and right now a big part of the appeal of running Linux on the desktop is that you're not a broad target for malware.

Write Comment

 
<< Start < Prev 1 2 3 Next > End >>

Results 10 - 18 of 729
    
Partner:

 

Latest Features
Security Features of Firefox 3.0
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Open Source Tool of March: ZoneMinder
Meet the Anti-Nmap: PSAD
Open Source Tool of February: Nmap!
HowTo: Secure your Ubuntu Apache Web Server
Yesterday's Edition

QuickLinks: Comunity , HOWTOs , Blogs , Features , Book Reviews , Networking ,
  Security Projects ,   Latest News ,  Newsletters ,  SELinux ,  Privacy ,  Home,
 Hardening ,   About Us,   Advertise,   Legal Notice,   RSS,   Guardian Digital

(c)Copyright 2008 Guardian Digital, Inc. All rights reserved.