★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-6481.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Forums 1/6/2003 0:02

Linux Security Week - January 6th 2003

By LinuxSecurity.com Contributors
Posted By: Benjamin D. Thomas
1/6/2003

This week, perhaps the most interesting articles include "Linux Security Strong As Ever," "The Message is the Medium: Selecting a Mail System," "Cryptosystems: Configuring IPSec," and "Six Top Security Issues For Executives."

LINUX ADVISORY WATCH - This week, advisories were released for typespeed, cyrus-imapd, openldap, bugzilla, dhcpd, fetchmail, cups, xpdf, leafnode, squirrelmail, and mysql. The distributors include Conectiva, Debian, Gentoo and SuSE.

Concerned about the next threat? EnGarde is the undisputed winner!
Hardened Linux Puts Hackers EnGarde! Winner of the Network Computing Editor's Choice Award, EnGarde "walked away with our Editor's Choice award thanks to the depth of its security strategy..." Find out what the other Linux vendors are not telling you.
LinuxSecurity Feature Extras:
No 'A' Word In Time - Maintaining accurate time is required for security. Many tools and devices exist to ensure that accurate time is maintained on an organization's system. It makes the job of analysis and system administration much easier to deal with, as well.

If It Ain't Broke See If It's Fixed - Attackers are still compromising servers with well-known attacks. General awareness can assist the busy administrators and users to protect their systems from these kinds of attacks. SANS provides a list of the Top 20 most common security vulnerabilities, how to identify each, and what can be done to protect   against these vulnerabilities.
 

[ Linux Advisory Watch ] - [ Linux Security Week ] - [ PacketStorm Archive ] - [ Linux Security Documentation ]

 

Take advantage of our Linux Security discussion list!  This mailing list is for general security-related questions and comments. To subscribe send an e-mail to security-discuss-request@linuxsecurity.com with "subscribe" as the subject.

Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines.


Host Security News:

January 3rd, 2003 -- Linux Security Strong As Ever -- Linux security is as strong as ever, despite recent statistics that say otherwise. Perhaps in response to the excessive publicity given to the strong security associated with Linux and open source software, it's no surprise that a number of commentators are making a high-profile argument that Linux, just like every other platform, does indeed have security issues. Members of the open source community have always known that Linux is not immune from security threats, so there is no argument there. What is in question is the final conclusion that these commentators are drawing, which is that Linux is less secure than Microsoft Windows.

http://www.linuxsecurity.com/articles/security_sources_article-6475.html

December 31st, 2002 -- Updated "Secure Programming for Linux and Unix HOWTO" Available -- This book provides a set of design and implementation guidelines for writing secure programs for Linux and Unix systems. Such programs include application programs used as viewers of remote data, web applications (including CGI scripts), network servers, and setuid/setgid programs.

http://www.linuxsecurity.com/articles/documentation_article-6464.html

December 30th, 2002 -- The Message is the Medium: Selecting a Mail System -- Life was good. Acme Widgets had ten employees and modest but steady growth. Tanya Hunter, administrative assistant and part-time IT staff, implemented an e-mail system for the company. After reading some trade magazines and the recommendations of a couple of mailing lists, the package she chose handled both text and binary attachments, was easy to install and support, and was free.

Fast-forward ten years, and everything has changed.

http://www.linuxsecurity.com/articles/security_sources_article-6454.html


Network Security News:

January 2nd, 2003 -- Un-Wired -- Without an abundance of expensive equipment or an Internet Service Provider, Croshere and Popkoff surf the Web all over the Palo Alto area, often by simply driving around and letting their iBooks -- which come with a built-in antenna and optional wireless Internet card -- track wireless connections at homes and businesses.

http://www.linuxsecurity.com/articles/network_security_article-6473.html

December 31st, 2002 -- Cryptosystems: Configuring IPSec -- In the next two articles, I'll demonstrate how to configure and troubleshoot an IPSec VPN on a FreeBSD system. When I first started configuring VPNs, I quickly discovered two things. First, there is more than one way to configure a VPN correctly .

http://www.linuxsecurity.com/articles/network_security_article-6460.html

December 30th, 2002 -- Six Top Security Issues For Executives -- Sun Tzu, a legendary Chinese strategist born more than 2,000 years ago, taught the importance of knowing both your enemy and yourself: If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat.

http://www.linuxsecurity.com/articles/security_sources_article-6459.html


General News:

January 4th, 2003 -- Are Hacking Defenses Winning the War? -- The federally funded Computer Emergency Response Team (CERT) reports that "incidents" -- which includes anything from a single host computer being hacked to hundreds of thousands of affected sites -- are on the upswing.

http://www.linuxsecurity.com/articles/hackscracks_article-6480.html

January 2nd, 2003 -- Security scare -- Gartner's security experts say if your organisation doesn't use a multi-layered security strategy, it does not have a commercial future. Gartner's IT Symposium has been a great source of stimulation and hugely influential for our technology planning throughout the years.

http://www.linuxsecurity.com/articles/general_article-6468.html

December 31st, 2002 -- Tough Year Ahead For IT Security -- IT managers should brace themselves for a tough 2003 fighting the world's virus, worm, and Trojan horse writers, according to predictions made Monday by security expert Roger Thompson, the author of the WormWatch Web site.

http://www.linuxsecurity.com/articles/forums_article-6467.html

December 31st, 2002 -- The Future of Viruses -- In 2002, users and companies got a respite from the disruptive viruses of 2001. But a more sophisticated generation of worms is on the way. The year 2002 may have been a relatively quiet for virus attacks, but security experts say that this is likely to be the calm before the storm.

http://www.linuxsecurity.com/articles/network_security_article-6462.html

December 30th, 2002 -- So Many Holes, So Few Hacks -- Experts who discover and report security holes seem to be far more industrious than the malicious hackers willing or able to exploit those holes. Despite the thousands of hackable holes that lurk in e-mail, on websites, in files and operating systems, most users' computers are never afflicted with more than the virtual version of a sniffle.

http://www.linuxsecurity.com/articles/hackscracks_article-6455.html

Surveillance Plan Worries GOP Senator
Jan 22

Home grown crypto is bad crypto. (+contest)
Jan 22

The Promise of Security
Jan 22

VPN Software Is Not Created Equal
Jan 22

AMD Boosts Wireless Security with New Memory Chip
Jan 22

Detecting Wireless LAN MAC Address Spoofing
Jan 22

The Turkey That Bites
Jan 22

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000