Security Projects - Page 52

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Security Projects News

Developers call for web security standard

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A group of security developers has called for an industry standard for internet security testing. The group, called Ideahamster, which includes a mixture of security experts and developers, has suggested that the introduction of such a standard would make it easier . . .

Uncovering the secrets of SE Linux: Part 2

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

In an uncharacteristic move, the U.S. National Security Agency (NSA) recently released a security-enhanced version of Linux -- code and all -- to the open source community. Part 2 of this developerWorks exclusive delves deeper into the code, dissecting how the . . .

Passive Analysis of SSH (Secure Shell) Traffic

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This advisory demonstrates several weaknesses in implementations of SSH (Secure Shell) protocols. When exploited, they let the attacker obtain sensitive information by passively monitoring encrypted SSH sessions. The information can later be used to speed up brute-force attacks on . . .

Guardian Digital Presents EnGarde Secure Linux

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

EnGarde is the next generation in Linux security providing a complete suite of e-business services, intrusion alert capabilities, improved authentication and access control utilizing strong cryptography, and complete SSL secure Web-based administration capabilities. Imagine a cohesive suite of Open Source applications . . .

Apache 1.3.19 Released

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Version 1.3.19 of the Apache web server has been released. This version fixes a security bug which could lead to a directory listing being displayed in place of an error message.. . .

In Defense of Copyleft

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Software that is placed under "copyleft" -- as opposed to copyright -- may be in a legal limbo and is still reliant on the concept of copyright, an Irish legal expert says. Stallman said the GPL and copyleft helps guarantee . . .

Openhack III undefeated

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Shortly after 3 a.m. EST last Thursday, eWEEK's third Openhack interactive security test finished its 17-day run with all prizes remaining unclaimed. This is eWEEK Labs' first Openhack test in three tries that hasn't been penetrated successfully, and the credit goes . . .

Security Statement from GTK+ Team

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Below is a statement from Ownen Taylor of the GTK+ development team in regards to the recent GTK_MODULES security issue raised on BUGTRAQ. "In the opinion of the GTK+ team, the only correct way to write a setuid program with a graphical user interface is to have a setuid backend that communicates with the non-setuid graphical user interface via a mechanism such as a pipe and that considers the input it receives to be untrusted.". . .

Openroot Project

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Openroot is a computer on my network where the root password is open to anyone for learning, experimentation, or whatever. This project has been around for atleast four weeks, and has been doing well. Please visit the openroot site. . . .

Solar Designer's 2.2.17 Kernel Patch

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Solar's kernel security enhancement patch is now available for the recently-released 2.2.17 Linux kernel. "This patch is a collection of security-related features for the Linux kernel, all configurable via the new 'Security options' configuration section. In addition to the new features, . . .

China's Founder Develops New Net Security Product

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

China's Founder Electronics Co. has developed a new method of Internet security and expects that it will become one of the world's leading Internet security solutions. ... He said that most existing Internet security products worldwide are still using the traditional firewall technology whose weakness is the possession of an Internet protocol address, which can be bypassed or destroyed by hackers.. . .

StopCarnivore.org Website Launched

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A new site devoted to shutting down the FBI's Carnivore email surveillance system has launched, "Stop Carnivore", http://www.stopcarnivore.org. The site explains what Carnivore is, why it is wrong, what you can do, and how it hurts the Internet. Below is a quick summary on the major issues the site deals with. . . .