This week, perhaps the most interesting articles include "Building an In-Depth Defense," "TCP session hijacking: A primer," and "Using PHP Securely." Also this week, if you are using Snort, you may want to read the following: "Survey of Log Analysis Tools for Snort," and the "Updated Snort FAQ." This week, advisories were released for cfingerd, hangterm, xinetd, w3m, samba, gnupg, fetchmail, freebsd kernel, openssl, allcommerce, sudo, and xloadimage. The vendors include Debain, EnGarde, FreeBSD, Mandrake, Red Hat, and Trustix.
http://www.linuxsecurity.com/articles/forums_article-3330.html
FREE Thawte Apache SSL Guide- Worried about Web security for your Apache servers? Find out how to implement SSL from the Apache experts. Get a FREE Thawte Apache SSL Guide and find the answers to all your Apache SSL security issues and more at: http://www.gothawte.com/rd15.html
EnGarde Secure NewsBrief: Issue I - Welcome to the first issue of the EnGarde Secure NewsBrief. This monthly newsletter contains details on EnGarde development, usage tips, news & reviews pertaining to EnGarde, and information on the latest software released by Guardian Digital for EnGarde.
http://www.linuxsecurity.com/articles/forums_article-3326.html
Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines.
Host Security News:
July 12th, 2001 -- PortSentry -- Administrators must stay aware of updates to software as well as the latest system compromise techniques. Due to this difficult task, system security is often not maintained and is lacking in many areas. This is illustrated by the increased number of reports that entail system compromise. This dilemma changed for me when I discovered the freeware tools offered by Psionic Software, Inc. called PortSentry and Logcheck.
http://www.linuxsecurity.com/articles/host_security_article-3328.html
July 11th, 2001 -- Trojan Ports List -- The guys at Neohapsis have put together a list of ports on which trojans run. Greg Shipley writes, "One of our guys (Mike Janowski) put together a pretty comprehensive list of common UDP/TCP port numbers, including many common apps, and some not-so-common ones (i.e. video games, trojans, etc.)
http://www.linuxsecurity.com/articles/intrusion_detection_article-3317.html
July 10th, 2001 -- Using PHP Securely -- The following article tries to explain how to use PHP on your server in a secure manner. This includes how to safely install it, remove samples and set up security specific options. It is very important to make sure that the server where PHP will be installed is secured before attempting to develop PHP applications. There are many useful articles on the SANS website as well as other places on the Internet to accomplish this.
http://www.linuxsecurity.com/articles/server_security_article-3306.html
Network Security News:
July 15th, 2001 -- Protect Yourself With Firewalls -- If you access the Net from home using a DSL or cable modem (CM) connection that is always on, you definitely need a firewall. Why? Well, most hacks on the Internet happen because of automated port scans: "robots" scanning the Internet for open ports.
http://www.linuxsecurity.com/articles/firewalls_article-3338.html
July 13th, 2001 -- Exorcise FTP, Telenet And Other Evil Daemons -- Telnet and ftp send passwords over the network in clear text that can be easily sniffed. You should replace them with more modern tools such as ssh and scp. SSLtelnet/SSLftp are also available but do not seem to be in such wide use.
http://www.linuxsecurity.com/articles/network_security_article-3335.html
July 12th, 2001 -- Top 10 Security Mistakes -- The following are some notable, less-than-bright errors that people and IT professionals commit when it comes to computer security. People regularly lock their houses, demand airbags in their vehicles and install smoke alarms in their homes. But put them in front of a computer, and you'd think the word security was magically erased from their brains.
http://www.linuxsecurity.com/articles/general_article-3323.html
July 12th, 2001 -- Survey of Log Analysis Tools for Snort -- Snort is a lightweight network intrusion detection system capable of logging every possible trace of intrusion attempts into a text file, syslog, XML, libpcap format, or a database.
http://www.linuxsecurity.com/articles/intrusion_detection_article-3325.html
July 11th, 2001 -- Building an In-Depth Defense -- Enabling access to critical applications and data while maintaining the confidentiality, integrity and availability of these resources can be a daunting task. One of the first steps to completing it is to use network segmentation and access-control methodologies.
http://www.linuxsecurity.com/articles/intrusion_detection_article-3318.html
July 11th, 2001 -- TCP session hijacking: A primer -- Session hijacking. What a powerful name. For me personally, the name conjures up mental pictures of airplanes with masked gunmen and bomb-laden buses. In actuality, session hijacking is far less physically dangerous and way more financially rewarding. The risk of a SWAT team shooting you while you are hijacking a session is also extremely low as opposed to hijacking airplanes.
http://www.linuxsecurity.com/articles/network_security_article-3320.html
Cryptography News:
July 15th, 2001 -- Crypto-Gram July 15, 2001 -- Crypto-gram is a free monthly newsletter providing summaries, analyses, insights, and commentaries on computer security and cryptography. This issue covers phone hacking, the best security references for the month, and an essay on monitoring.
http://www.linuxsecurity.com/articles/cryptography_article-3339.html
Vendor/Product/Tools News:
July 10th, 2001 -- Snort Version 1.8 Release -- Many private companies are turning to the military and law enforcement agencies to find computer forensics and security professionals. Some officers are leaving their posts for jobs in the corporate world, sometimes doubling or even tripling their salaries.
http://www.linuxsecurity.com/articles/intrusion_detection_article-3309.html
July 10th, 2001 -- Snort FAQ Updated -- Hot on the heels of the Snort-1.8 release, Dragos Ruiu has updated his FAQ for the snort network intrusion detection system. Be sure to see our feature story covering installing, configuring and using snort on your network.
http://www.linuxsecurity.com/articles/intrusion_detection_article-3310.html
General News:
July 15th, 2001 -- Hackers in Suits? Gadzooks! -- For nine years, Defcon has been known as the world's most exuberant party for hackers and hacker hopefuls who gather in sin city for a rollicking good time. Conference organizers call it the "annual computer underground party for hackers," and Defcon is known as much for its technical content as its beer-tinged hijinks.
http://www.linuxsecurity.com/articles/organizations_events_article-3340.html
July 11th, 2001 -- U.S. military backs open-source security -- Continuing its support of open-source operating systems, the U.S. Department of Defense granted $1.2 million to a community project aimed at adding advanced security features to FreeBSD, an open-source variant of Unix. NAI Labs, the advanced research group of security-software maker Network Associates, announced the grant Monday.
http://www.linuxsecurity.com/articles/government_article-3315.html
July 9th, 2001 -- The Enemy Within -- "The first denial-of-service attack hit the next morning, a Thursday, and crashed the company's application server. Somebody sitting at a computer in a downtown Manhattan Kinko's had gained access to ITTI's server using an internal development password. The server was brought back online, only to be hit again two minutes later, says Goldberg.
http://www.linuxsecurity.com/articles/general_article-3302.html