★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-6565.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Forums 1/19/2003 22:48

Linux Security Week - January 20th 2003

By LinuxSecurity.com Contributors
Posted By: Benjamin D. Thomas
1/19/2003

This week, perhaps the most interesting articles include "Open Source Security: Better Protection at a Lower Cost," "OWASP Top Ten 'Dumb Security Mistakes that Programmers Make'," "Authprogs SSH Command Authenticator," and "Intelligence Gathering: Watching a Honeypot at Work."

ENCRYPTION + AUTHENTICATION = TRUST You may think people will regard your business as trustworthy because you've got a 128-bit encryption certificate, but encryption does not guarantee trust. Thawte believes in rigorous authentication! Download our FREE Authentication Guide

 

LINUX ADVISORY WATCH - This week, advisories were released for wget, xpdf, openldap, libmcrypt, impsql, bugzilla, mod_php, cups, dhcpd, kde, leafnode, libpng, postgresql, mysql, vim, and ethereal. The distributors include Caldera, Debian, Mandrake, Red Hat, SuSE, and Yellow Dog.

Concerned about the next threat? EnGarde is the undisputed winner!
Hardened Linux Puts Hackers EnGarde! Winner of the Network Computing Editor's Choice Award, EnGarde "walked away with our Editor's Choice award thanks to the depth of its security strategy..." Find out what the other Linux vendors are not telling you.
LinuxSecurity Feature Extras:
Newest Members of the Team - Just to give everyone an idea about who writes these articles and feature stories that we spend so much of our time reading each day, I have decided to ask Brian Hatch and Duane Dunston, the newest members of the LinuxSecurity.com team, a few questions.

Secure Passwordless Logins with SSH Part 3 - Setting up your accounts to allow identity-based authentication gives you several new options to allow passwordless access to those accounts. This week we'll see how well we can restrict the access granted to these identities.

 

Take advantage of our Linux Security discussion list!  This mailing list is for general security-related questions and comments. To subscribe send an e-mail to security-discuss-request@linuxsecurity.com with "subscribe" as the subject.

Thank you for reading the LinuxSecurity.com weekly security newsletter. The purpose of this document is to provide our readers with a quick summary of each week's most relevant Linux security headlines.


Host Security News:

January 17th, 2003 -- STADRIN Authentication -- The Rekonix LTD company have introduced today a new version of their popular strong authentication system STADRIN 1.1.5 targeting the Linux platform using PAM authentication schemes with a Vasco tokens backend. The new version makes the implementation process more easy and allows simple coexistence with current running authentication schemes for a simple switching to new one.

http://www.linuxsecurity.com/articles/vendors_products_article-6559.html

January 16th, 2003 -- Open Source Security: Better Protection at a Lower Cost -- At first glance, the idea of using open source software for a firewall or other security application seems counterintuitive, even absurd. Why would a corporation use code that's available to anyone - hackers, cyber-terrorists, disgruntled employees - to protect their most vital information assets?

http://www.linuxsecurity.com/articles/forums_article-6550.html

January 16th, 2003 -- Decrypting The Secret To Strong Security -- The open-source movement argues that it's better because "lots of eyes can look at it and find the bugs." Those who favor proprietary software offer two counterarguments: The first is that a lot of hostile eyes can also look at open-source code--which, they say, is likely to benefit attackers more than anyone else.

http://www.linuxsecurity.com/articles/forums_article-6553.html

January 15th, 2003 -- Linux Trojan Starts Circulating -- An explolit for the Linux mpg123 mp3 player has started circulating, following the release of the code for the same by the Gobbles security group. Anti-virus software maker Symantec has christened it as Trojan.Linux.JBellz.

http://www.linuxsecurity.com/articles/host_security_article-6544.html

January 14th, 2003 -- OWASP Top Ten "Dumb Security Mistakes that Programmers Make" -- The Open Web Application Security Project (OWASP) has released their Top Ten List of Dumb Programmer Mistakes in order to help organizations understand and improve the security of their web applications and web services. This list was created to focus government and industry on the most serious of these vulnerabilities.

http://www.linuxsecurity.com/articles/security_sources_article-6537.html

January 14th, 2003 -- Experts Pinpoint Top Web Site Security Flaws -- A group of security experts on Monday released a list of Web site flaws that it believes are the primary culprits in undermining the security of online applications. In a 23-page report, the Open Web Applications Security Project said that the OWASP Top Ten is intended to help developers and corporate security administrators close the holes that allow attackers into many companies.

http://www.linuxsecurity.com/articles/security_sources_article-6538.html

January 13th, 2003 -- Open-Source Group Names 10 Scariest Web Vulnerabilities -- The Open Web Application Security Project today released a list of the top 10 vulnerabilities in Web applications and services. The group said it wants to focus government and private-sector attention on common weaknesses "that require immediate remediation."

http://www.linuxsecurity.com/articles/general_article-6529.html


Network Security News:

January 17th, 2003 -- Network Security: Best Practices -- Believe it or not, best practices in network security begin with a top-down policy. Policy begins with understanding what it is you need to protect and what it is you need to protect against. The levels of responsibility need to be understood, and that implies that security is everyone's job, as each employee understands how he or she contributes to the organization.

http://www.linuxsecurity.com/articles/security_sources_article-6561.html

January 16th, 2003 -- Avoid Wireless LAN Security Pitfalls -- Wireless Local Area Networks (WLANs) are taking off. Enterprises are turning to WLANs in droves because they offer mobility and huge cost advantages. In fact, studies show that wireless workers are more productive, less pressured and save businesses money. Gartner, Inc., for instance, finds WLANs to be cheaper to install than wired LANs, especially for small organizations. And once they're in, wireless LANs are less expensive to operate and maintain.

http://www.linuxsecurity.com/articles/network_security_article-6556.html

January 16th, 2003 -- Halting the Hacker: A Practical Guide to Computer Security -- Again, the issue of hacking is brought to my reading attention. A lot has been said on that subject during the years, both right and wrong, by various authors, from experts to media journalists. For the most part, the actual act of attack against the system, or a security breach got minor attention, versus the dollar value of damage and the level of publicity the attacker got, stepping into the spotlight.

http://www.linuxsecurity.com/articles/security_sources_article-6552.html

January 15th, 2003 -- Authprogs SSH Command Authenticator -- Introducing Authprogs, software which lets you control which machines can run authorized commands via SSH using SSH Identities.

In this article, I introduce you to authprogs, which can be used to control what commands can be run on a host-by-host basis.

http://www.linuxsecurity.com/articles/documentation_article-6547.html

January 15th, 2003 -- Intelligence Gathering: Watching a Honeypot at Work -- The purpose of this article is share with the security community the data I collected from my honeypot. There are many papers available that explain how to set up honeypots and the risks one takes when running a honeypot. While this paper will briefly cover touch upon these topics, it is written for people who want to understand what data honeypot will provide them.

http://www.linuxsecurity.com/articles/intrusion_detection_article-6540.html

January 14th, 2003 -- Spread of Handheld Devices Raises Security Questions -- Wireless security is a major concern for agencies that deal with ever-more tech-savvy employees bringing to work handheld devices that don't mesh with federal security guidelines, said CDW Government Inc. president James R. Shanks.

http://www.linuxsecurity.com/articles/government_article-6539.html

January 13th, 2003 -- Instant Insecurity: Security Issues of Instant Messaging -- Instant messaging is an increasingly popular method for communicating over the Internet. Instant messaging (IM) is a real-time supplement to and, in some regards, a replacement for e-mailing. Unlike e-mail, instant messaging allows users to see whether a chosen friend or co-worker is connected to the Internet.

http://www.linuxsecurity.com/articles/security_sources_article-6531.html

January 13th, 2003 -- The Enterprise Authentication Game -- The biggest vulnerability in most enterprise networks is the authentication system -- especially if it relies solely on passwords. Protecting a computer network using employee-created passwords is like protecting a jewelry store on a busy street with one small lock -- and hiding the key underneath the doormat.

http://www.linuxsecurity.com/articles/security_sources_article-6528.html


General News:

January 17th, 2003 -- Rumsfeld Orders .mil Web Lockdown -- U.S. defense secretary Donald Rumsfeld this week directed the armed service to strip military Web sites of information that could benefit adversaries, citing a terrorist training manual and a year-long review of the Department of Defense's 700-gigabyte Web presence.

http://www.linuxsecurity.com/articles/government_article-6560.html

January 17th, 2003 -- At What Price Security? -- The U.S. Department of Homeland Security, the agency set up to reduce America's vulnerability to terrorism, is expected to spend close to $6 billion on information technology in its first two years, according to a report from the investigative arm of Congress.

http://www.linuxsecurity.com/articles/general_article-6562.html

January 17th, 2003 -- The All-Important Confidentiality Policy -- Technology company's lifeblood depends on the secrecy of its intellectual property. Most companies safeguard sensitive trade secrets with confidentiality agreements--but many of these agreements aren't as comprehensive as they need to be.

http://www.linuxsecurity.com/articles/privacy_article-6558.html

January 15th, 2003 -- Transmeta Embeds Security Features in Mobile Chip -- Chipmaker Transmeta has announced it will be the first company to release a mobile chip that includes security features built in at the processor level. The company said it has received designs for its Crusoe TM5800 processor, an x86 chip designed to protect data, deter intellectual property theft and provide a tamper-resistant environment.

http://www.linuxsecurity.com/articles/vendors_products_article-6543.html

January 13th, 2003 -- How Sharing Thwarts Hacks -- Two Harvard University security researchers have developed a model showing that enterprises that share their sensitive data about network attacks and security breaches are less attractive targets and, hence, less likely to be attacked.

http://www.linuxsecurity.com/articles/forums_article-6527.html

 

Run Your Power Generating Plant On Linux - Securely
Jan 20

ISS Eyes Brass Ring of Security Management
Jan 20

I Poisoned P2P Networks For The RIAA - whistleblower
Jan 20

Game Server Flaw Poses Attack Threat
Jan 20

The Canary in the Data Mine
Jan 20

Linux Security Week - January 20th 2003
Jan 19

Linux Security Newsletters - Subscribe Today!
Jan 19

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000