LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
How would you rate the importance of default settings in security?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
Emily Ratliff: OS Security
DanWalsh LiveJournal
Security Bloggers Network
Latest Newsletters
Linux Advisory Watch: May 9th, 2008
Linux Security Week: May 5th, 2008
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Hacks/Cracks
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.



Firefox Infects Vietnamese Users With Trojan Code  08 May 2008 
Source: Wired - Posted by Eckie Silapaswang   
Mozilla, the maker of the open source Firefox browser, is redoubling its efforts to check user created add-ons for viruses and Trojans after it discovered that a language pack on its official add-on page had been infected for months with rogue code, the organization reported Wednesday.

Anyone who has installed the Vietnamese language pack for Firefox could be in danger of having malicious code in their system. Be sure to uninstall this add-on pack if you have recently installed it - unless you enjoy banner ads and opening up your system for future exploits.

Write Comment

 
GCC and Pointer Overflows  30 April 2008 
Source: lwn.net - Posted by Bill Keys   
On April 4, CERT put out a scary advisory about the GNU Compiler Collection (GCC). This advisory raises some interesting issues on when such advisories are appropriate, what programmers must do to write secure code, and whether compilers should perform optimizations which could open up security holes in poorly-written code. Are you a c programmer? This article shows you how to make your code a little more secure. It's a very an important skill to have so take a look.

Write Comment

 
Targeted Attacks Using Malicious PDF Files  25 April 2008 
Source: SANs - Posted by Eckie Silapaswang   
Dating back to the end of February, we have been tracking test runs of malicious PDF messages to very specific targets. These PDF files exploit the recent vulnerability CVE-2008-0655.
Ever since the end of March, beginning of April, the amount of samples seen in the wild has significantly increased. Interestingly enough, there is almost no "public, widespread" exploitation. All reports are limited to very specific, targeted attacks. However, due to the wide scope of these attacks, and the number of targets we know of, we feel a diary entry was in order.

Remember the old saying of "if it ain't broke, don't fix it"? It appears this exploit seems very focused on targeting not only the vulnerability mentioned in the article, but the very facet of sticking with stable software. Nothing is apparently "broken" about Adobe Acrobat v7, however as you can tell by the diary entry, updating is the key to preventing "it ain't broke" software from having to be "fixed" due to exploits such as this one.

Write Comment

 
Malicious Microprocessor Opens New Doors for Attack  16 April 2008 
Source: Network World - Posted by Eckie Silapaswang   
For years, hackers have focused on finding bugs in computer software that give them unauthorized access to computer systems, but now there's another way to break in: Hack the microprocessor.
On Tuesday, researchers at the University of Illinois at Urbana-Champaign demonstrated how they altered a computer chip to grant attackers back-door access to a computer. It would take a lot of work to make this attack succeed in the real world, but it would be virtually undetectable.

It's actually kind of funny that they decided to mention that this system was "running the Linux operating system". Regardless of the OS, a hardware level exploit such as this poses such a bigger threat than just OS security. Although this type of exploit is much harder to deploy rather than software, this article poses interesting situations on how exactly it can be carried out.

Write Comment (1 Comments)

 
Open Source Conference for Chicago Hackers  27 March 2008 
Source: flourishcon - Posted by Bill Keys   
This goes out to all the web hackers out there. If you're a proud user of a web application framework and you think it's superior to all others, we invite you to prove it. Flourish is having a web application framework showdown and we need you to come defend yours. There will be food and the site you build goes to a deserving non-profit. So far, we've got someone for Ruby on Rails, CakePHP and web2py. Send an email to info@flourishconf.comThis e-mail address is being protected from spam bots, you need JavaScript enabled to view it if you want to participate. Do you have a favorite web application framework? Do you use it because you think it's secure. This conference seems to be a good test to see how secure web application frameworks are.

Write Comment

 
Ongoing IFrame Attack Proving Difficult to Kill  18 March 2008 
Source: ars Technica - Posted by Eckie Silapaswang   
One of the factors that make an ongoing malware attack so difficult to stop is the speed with which the assault can evolve. Over the past 12 days, an IFrame injection attack that originally focused on ZDNet Asia has been spreading across the 'Net, changing targets and payloads on an almost daily basis. An iFrame (short for inline frame) is an element of HTML that's used to embed HTML from another source into a webpage. The timeline of the attack is provided below, thanks in no small part to security consultant Dancho Danchev, who has kept a play-by-play account of the IFrame attack on his blog.

Read on for an interesting analysis of the injection method and how it is leveraging SEO engines. How do you feel this should be properly mitigated and countered?

Write Comment

 
Inguma 0.0.7.2 Released for Download - Penetration Testing Toolkit  17 March 2008 
Source: Darknet.org - Posted by Eckie Silapaswang   
For those that don’t know, Inguma is an open source penetration testing and vulnerability research toolkit written completely in Python. The environment is mainly oriented to attack Oracle related systems but, anyway, it can be used against any other kind of systems.

Open source exploit frameworks continue to evolve and improve - Inguma seems to have its focus upon Oracle systems. How do you feel this matches up against other frameworks such as Metasploit?

Write Comment

 
Root under fire: vmsplice() exploit  20 February 2008 
Source: www.linuxworld.com - Posted by Ryan Berens   
This recent kernel exploit has been spreading around the Internet quickly in recent days. So what is it, exactly? What is it really doing and how does it allow a cracker to exploit the root privileges in your system? Jonathan Corbet chimes in with one of the best overviews of the exploit, why it's a problem, how it got here, and what's being done to address it:

"Unlike a number of other recent vulnerabilities which have required special situations (such as the presence of specific hardware) to exploit, these vulnerabilities are trivially exploited and the code to do so is circulating on the net.

Write Comment (1 Comments)

 
Firefox Bug Opens Browser to Hackers  25 January 2008 
Source: PCadvisor - Posted by Bill Keys   
A new bug in Firefox could be used by attackers to scout out a system prior to mounting a more thorough assault, according to Mozilla's head of security.

The flaw, said Window Snyder, Mozilla's chief security officer, is in the browser's chrome protocol - 'chrome' is the Firefox term for its user interface - as she responded to reports of the vulnerability and the public posting of a proof-of-concept exploit. What do you think about this latests Firefox bug?

Write Comment

 
DNS Attack Could Signal Phishing 2.0  20 December 2007 
Source: PC World - Posted by Bill Keys   
Researchers at Google and the Georgia Institute of Technology are studying a virtually undetectable form of attack that quietly controls where victims go on the Internet. The study, set to be published in February, takes a close look at "open recursive" DNS servers, which are used to tell computers how to find each other on the Internet by translating domain names like google.com into numerical Internet Protocol addresses. Criminals are using these servers in combination with new attack techniques to develop a new generation of phishing attacks. What is so new about the possible attacks on DNS servers? We all know they are very vulnerable to attack because they are so visible and important to the Internet

Write Comment (1 Comments)

 
<< Start < Prev 1 2 3 Next > End >>

Results 1 - 10 of 1215
    
Partner:

 

Latest Features
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Open Source Tool of March: ZoneMinder
Meet the Anti-Nmap: PSAD
Open Source Tool of February: Nmap!
HowTo: Secure your Ubuntu Apache Web Server
SSH: Best Practices
Yesterday's Edition
sshpass - Non-Interactive SSH Password Authentication
Computer Forensics Procedures, Tools, and Digital Evidence Bags: What They Are and Who Should Use
Firefox Infects Vietnamese Users With Trojan Code
A Guide to Cryptography in PHP

QuickLinks: Comunity , HOWTOs , Blogs , Features , Book Reviews , Networking ,
  Security Projects ,   Latest News ,  Newsletters ,  SELinux ,  Privacy ,  Home,
 Hardening ,   About Us,   Advertise,   Legal Notice,   RSS,   Guardian Digital

(c)Copyright 2008 Guardian Digital, Inc. All rights reserved.