Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines
This week, advisories were released for sudo, dump, lpr, php, sumrpc, zope, and analog. The vendors include Conectiva, Debian, Immunix, FreeBSD, Mandrake, Red Hat, Slackware, and Trustix. It is critical that you update all vulnerable packages.
http://www.linuxsecurity.com/articles/forums_article-2609.html
FREE SECURITY BOOKS Guardian Digital has just announced an offer for free 2 free security books with the purchase of any secure Linux Lockbox. The Lockbox is an Open Source network server appliance engineered to be a complete secure e-business solution. It can be used as a commerce server, web server, DNS, mail, and database server. Please see Guardian Digital's website for details.
http://www.guardiandigital.com/bookoffer.html
Host Security News:
February 28th, 2001 -- Be extremely wary not to taint computer evidence -- We've all seen it -- the yellow tape used to cordon off a crime scene in the movies. In terms of police work, it's called securing the scene. But how many of us realize that securing the scene for a what may be a computer crime is just as important as it is for a homicide or fire?
http://www.linuxsecurity.com/articles/intrusion_detection_article-2592.html
Network Security News:
March 1st, 2001 -- Network monitoring, access control, and booby traps using TCP Wrappers -- TCP Wrappers is one of the most common methods of access control on your Unix box. A wrapper program 'wraps' around existing daemons and interfaces between clients and the server. Good access control and logging are strong points. In this first part, we introduce you to the concept behind TCP Wrappers.
http://www.linuxsecurity.com/articles/host_security_article-2598.html
February 28th, 2001 -- Using SSH Tunneling -- They say that the Wired Equivalent Privacy protocol has been cracked. What's a wireless user to do? Tunnel. Secure Shell (SSH) is open, free, fast, secure, and easy to setup (once you know how). WEP has never provided much more than a form of access control to your wireless nodes.
http://www.linuxsecurity.com/articles/cryptography_article-2594.html
February 26th, 2001 -- Build a Floppy Firewall -- Here's how I turned an unused PC into a packet-filtering firewall using a package called floppyfw. The firewall boots off a single floppy, runs completely in RAM, and uses ipchains for the filter rules. It also does IP masquerading, port forwarding, and can log to a remote host using syslog. All this in a machine with as little as 8 MB of RAM and no hard drive.
http://www.linuxsecurity.com/articles/firewalls_article-2252.html
Cryptography News:
February 28th, 2001 -- OpenPGP set to become global standard -- OpenPGP is an Internet Engineering Task Force (IETF) ratified standard based around PGP 5, which Hush and Zimmermann hope will become a global standard as the public demand for secure communications increases. OpenPGP as a development platform can be used to develop email encryption as well as roll out digital signatures and key management systems, said Zimmermann.
http://www.linuxsecurity.com/articles/cryptography_article-2597.html
February 27th, 2001 -- PKI Primer -- This document covers five pages of definitions and explanations of the elements of public key cryptograpy. "Everything you wanted to know about Public Key Infrastructure, but were too insecure to ask. Secret Key Encryption In secret key encryption, the same key is used to encrypt and decrypt.
http://www.linuxsecurity.com/articles/cryptography_article-2590.html
Vendor/Product/Tools News:
February 28th, 2001 -- A sharp eye for security -- Companies that believe their networks can be completely protected by a phalanx of add-on security products may be in for a rude awakening. Underlying vulnerabilities, embedded and unseen many layers down in network infrastructures, may be unwitting invitations to even moderately skilled attackers.
http://www.linuxsecurity.com/articles/vendors_products_article-2596.html
February 27th, 2001 -- Computer forensics booms as importance of electronic evidence grows -- Computer forensics, once a discipline restricted to a small cloister of law enforcement officers, is now a booming business. Demand for the services is exploding as electronic evidence becomes more widely used in court and as companies become increasingly concerned about the use of computer networks for corporate spying and other mischief.
http://www.linuxsecurity.com/articles/network_security_article-2582.html
General News:
March 1st, 2001 -- BINDing the Internet -- Security experts recently made an unprecedented appeal to computer system administrators to update software to protect the Internet. The warning highlights the vulnerabilities of the digital era. Security flaws continue to be the Achilles Heel of the information revolution. There is little sign that message is sinking in.
http://www.linuxsecurity.com/articles/server_security_article-2602.html
February 27th, 2001 -- Government e-security measures inadequate -- The Government's attempt to fight hackers through the latest anti-terrorism legislation is flawed, according to legal and network security experts. Critics claim that the legislation covers attacks on utilities and hospitals, but has no provision for the prosecution of a cyber terrorist who attacks a bank or business.
http://www.linuxsecurity.com/articles/government_article-2584.html
February 26th, 2001 -- Could Linux be too open for our own good? -- That's sort of what I was feeling when I saw that the National Security Agency was releasing a secured version of Linux 2.2 into the "open source" community, along with the background on the testing models it used for verification. It was just too weird to be happening. The people behind the triple fence in Fort Meade, Md. giving out something?
http://www.linuxsecurity.com/articles/server_security_article-2580.html