LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
How would you rate the importance of default settings in security?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
Emily Ratliff: OS Security
DanWalsh LiveJournal
Security Bloggers Network
Latest Newsletters
Linux Advisory Watch: August 8th, 2008
Linux Security Week: August 4th, 2008
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Vendors/Products
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.



Small Companies Lax About Computer Security, Report Finds..  30 July 2008 
Source: news.cnet - Posted by Bill Keys   
Large companies are valuable targets for cyber criminals, but what about the small fry? Software security firm McAfee took a gauge of opinions, finding that some small and medium-size businesses don't seem that concerned about potential hacks. At least that's what its recent survey suggested. Are not enough small companies taking computer security seriously? Do you think Linux can be a solution to these companies security needs? This article studies the role of computer security in small companies.

Write Comment

 
Popular Open Source Spam Filter Gets Boost  19 May 2008 
Source: Network World - Posted by Eckie Silapaswang   
SpamAssassin, popular open source spam-filtering software, will have deadlier aim thanks to an add-on tool that is being offered free of charge to small businesses and individuals by MailChannels.
The tool -- called Traffic Control 3 -- is an e-mail traffic-shaping package that slows down the transmission of spam into corporate e-mail systems. (Compare Messaging Security products.) MailChannels officials say Traffic Control 3 will reduce spam volumes by 50% to 75% for SpamAssassin users.

Traffic Control 3 uses a tarpitting technique that greatly reduces the speed at which spam can be transmitted to its target, hitting spammers at their one great vulnerability - their pockets. Reduced speed means less money, and spammers just aren't willing to make the compromise. What have you heard about Traffic Control 3 - anyone else know any good open source spam tar pits?

Write Comment

 
Prediction: The RSA Conference Will Shrink Like a Punctured Balloon  17 April 2008 
Source: Wired - Posted by Eckie Silapaswang   
Last week was the RSA Conference, easily the largest information security conference in the world. More than 17,000 people descended on San Francisco's Moscone Center to hear some of the more than 250 talks, attend I-didn't-try-to-count parties, and try to evade over 350 exhibitors vying to sell them stuff.
Talk to the exhibitors, though, and the most common complaint is that the attendees aren't buying.

Schneier makes an interesting comparison of anti-lock brakes to security products near the end of the article that sheds new light on how the security industry is evolving. Do you feel this is for better or worse?

Write Comment

 
EnGarde Secure Community 3.0.19 Now Available!  15 April 2008 
Source: EnGarde Secure Linux Developers - Posted by Ryan W. Maple   
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.19 (Version 3.0, Release 19). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.

Write Comment

 
Network Security Converges With Ubuntu Linux  09 April 2008 
Source: MSPmentor.net - Posted by Eckie Silapaswang   
Ubuntu, the fastest-growing version of Linux, is starting to attract interest from the managed services industry. One prime example: Untangle, which develops security solutions for managed service providers, is preparing to add support for Ubuntu within the next few months, MSPmentor has learned.

As you can tell by the rise of popularity in Linux distributions such as Ubuntu, managed service providers pay more attention due to the advantages of open source such as fair pricing and overall community. Untangle focuses on its network gateway - what other distros or MSPs have you heard about which leverages Linux?

Write Comment (2 Comments)

 
SecurityCompass Exploit-Me - Firefox Web Application Testing Tools  25 March 2008 
Source: Darknet.org - Posted by Eckie Silapaswang   
Exploit-Me is a suite of Firefox web application security testing tools. Exploit-Me tools are designed to be lightweight and easy to use. Instead of using a proxy like many web application testing tools, Exploit-Me integrates directly with Firefox. It currently consists of two tools, one for XSS and one for SQL Injection.

Lightweight and portable is always a benefit for web application exploitation tools. Take a look at this open-source plugin for Firefox and see how it fares against today's web applications.

Write Comment

 
Virtualization's Secret Security Threats  14 March 2008 
Source: InfoWorld - Posted by Ryan W. Maple   
Interesting article over at InfoWorld on the security implications of virtualization: Almost any IT department worth its salt is deploying virtualization technology today to reduce power usage, make server and OS deployments more flexible, and better use storage and systems resources. But as virtualization technology gains in popularity, it may bring with it new risks, said Don Simard, the commercial solutions director at the U.S. National Security Agency, the electronic intelligence and cryptographic agency once so secret its very existence was a secret. At the same time, virtualization technology may bring new protections, he noted. There are a lot of people "drinking the Kool-AidŽ" when it comes to virtualization, and there is almost no mention of security in contrast with its obvious benefits. Do the Open Source KVM and/or Xen implementations have an advantage in this discussion? What do you think?

Write Comment

 
Open source code for driving security into web services  11 March 2008 
Source: Net-security.org - Posted by Ryan Berens   
OpenLiberty-J is based on J2SE, and open source XML, SAML, and web services libraries from the Apache Software Foundation and Internet2, including OpenSAML, a product of the Internet2 Shibboleth project. The library implements the Liberty Advanced Client functionality of Liberty Web Services standards This company provides a development architecture explicitly focusing on the deployment of secure practices for Web 2.0 Applications and development. Is this the best way to leverage web service security?

Write Comment

 
SSH Tectia 6.0; What is it?  10 March 2008 
Source: Net-security.org - Posted by Ryan Berens   
SSH Communications is a focused provider for all types of, you guessed it, SSH corporate services. It's rare to see such a focus, but their new release of their Tectia product suite provides and interesting take on how companies could package this functionality:

SSH Tectia Manager 6.0 can centrally deploy, configure, update and audit the SSH Tectia environment from a central location. Benefits of SSH Tectia version 6.0:
  • Improved SSH Tectia Client for Windows - supports transparent TCP Tunneling and automatic tunneling, in addition to the traditional Secure Shell port forwarding, making the product the ideal choice for securing virtually any TCP/IP application without modifications to applications or existing network infrastructure, saving time and valuable IT resources.
  • Ease-of-implementation - improved installation and self-configuration options, provide cost-saving fast and easy ways to replace FTP and other unsecure protocols with secure alternatives, and help meet regulatory compliance deadlines.

Write Comment

 
Why Do We Need Specialist Security Distros?  26 February 2008 
Source: http://www.packtpub.com - Posted by Ryan W. Maple   
This question is often asked - what do platforms that focus solely on security bring to the table? According to this interview with Guardian Digital by Packt Publishing, they bring quite a lot. The company develops EnGarde Secure Linux, and answers these questions and more on what makes all security platforms valuable and why is a great example

Many popular distributions, community-oriented and otherwise, take security very seriously. They have dedicated security teams that go over individual packages before they're rolled into a final release. To make sure you don't have any loose ends, these distributions and many other individual Open Source projects also publish an endless stream of security advisories and updates. Add to this security mechanisms like SELinux, AppArmor, and the upcoming TOMOYO Linux, and SMACK, and you know they mean business. So what room does this leave for specialist security distros?

Write Comment

 
<< Start < Prev 1 2 3 Next > End >>

Results 1 - 10 of 822
    
Partner:

 

Latest Features
Security Features of Firefox 3.0
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Open Source Tool of March: ZoneMinder
Meet the Anti-Nmap: PSAD
Open Source Tool of February: Nmap!
HowTo: Secure your Ubuntu Apache Web Server
Yesterday's Edition
Web 2.0, DNS Flaws Revealed at Black Hat

QuickLinks: Comunity , HOWTOs , Blogs , Features , Book Reviews , Networking ,
  Security Projects ,   Latest News ,  Newsletters ,  SELinux ,  Privacy ,  Home,
 Hardening ,   About Us,   Advertise,   Legal Notice,   RSS,   Guardian Digital

(c)Copyright 2008 Guardian Digital, Inc. All rights reserved.