★ wanayoo — archive 1999 http://www.linuxsecurity.com/index.htmlNouvelle recherche | Portail wanayoo
Advertise Here

Resources
Documentation
  FAQs, HOWTOs,
Whitepapers,
Newsletters, Glossary,
Publications...
Security Sources
  Security News Sites,
Archives...

Forums
  Mailing Lists,
Discussion Groups...
Firewalls
  Packet Filters,
Proxies,
Projects...
Host Security
  Scanners,
Access Control,
Auditing...
Cryptography
  Network,
Filesystem,
Authentication,
Mail, VPNs...
Network Security
  Scanners,
Monitors,
Design...

Intrusion Detection
  Host, Network,
Projects...

Organizations/Events
  CERT, SANS,
Bugtraq...

Server Security
  WWW, FTP,
Kernel...

Vendors/Products
  Crypto,
IDS, Audit,
Newsletters...
Projects
  Crypto,
Distributions...






News
And The Loser Is ...
Host Security
 May 17, 2000 1:24 -ZDNet
May 17 --
ZDNet has a few comments on the recent SecurityFocus research from bugtraq data. "before the Linux fans start popping open their champagne bottles, they'll be horrified to know that the different distributions aggravate problems almost matched NT and were . . .
Tough Love?
Host Security
 May 17, 2000 1:16 -ZDNet
May 17 --
ZDNet also has a few comments on a "Linux variant" of the recent MS worm. They must have read Bruce Schneier's Crypto-Gram article, which I thought was a better one on the topic. Still worth reading. "Compounding . . .
SSH: From Secure Administration to Virtual Private Networking
Cryptography
 May 16, 2000 23:50 -LinuxToday
May 16 --
OpenSSH is an inexpensive improvement well worth the minimal effort required to install and configure it. You can also use SSH to set up simple "circuit level" VPNs. In this article, we take a hands-on look at the two . . .
Call For Papers
Organizations Events
 May 16, 2000 19:17 -NDSS
May 16 --
The Network and Distributed System Security Symposium is looking for authors for information on PKI, security policy, authentication, firewalls, and a handful of other exciting topics. . . .
Guide to Home Networking
Host Security
 May 16, 2000 19:6 -justLinux [LinuxToday]
May 16 --
This justlinux article discusses the security (or lack thereof) of a home DSL connection, and how the author went about detecting the intruder. "What I found in /dev/.oz was a real shocker. There were several binaries with names like, . . .
Zope Lassos Pesky Trojan
Projects
 May 16, 2000 15:39 -LinuxMall [LinuxToday]
May 16 --
Zope Weekly News has reported a problem with its security model that appears to be potentially pervasive and not necessarily Zope-specific. This is the first installation in a three-part series on Zope's efforts to rein in the trojan, which will . . .
Security Scanners for Linux
Network Security
 May 16, 2000 13:1 -Linux.com --  Posted by:Benjamin D. Thomas
May 16 --
This paper discusses the differnt types of security scanners available for Linux. "A scanner is a program that automatically detects security weaknesses in a remote or localhost.". Scanners are important to Internet security because they reveal weaknesses in the . . .
New DDoS tools developed
Network Security
 May 16, 2000 10:2 -NW Fusion
May 16 --
More information on the "mstream" DDoS attack tool. "A new distributed denial-of-service (DDoS) tool found recently in computers at several universities may be able to avoid defenses put up by Web sites after a rash of DDoS attacks in February . . .
Security draws extra millions
General
 May 16, 2000 8:26 -Federal Computer Week   --Benjamin D. Thomas
May 16 --
"The Senate last week responded to the growing menace of cyberattacks by adding $76.8 million to the fiscal 2001 Defense authorization bill to kick-start a new information security scholarship program and a security institute. The Information Security Scholarship . . .
Six Sanguine Senators Slam Spam
General
 May 16, 2000 7:42 -Computer Currents --   Posted by:Benjamin D. Thomas
May 16 --
In a bid to "protect" consumers from unsolicited commercial e-mail--unaffectionately known as spam--a pair of senators Friday introduced legislation that would allow Internet service providers to sue spammers who violate certain codes of conduct. . . .
Intel releases security implementation
Vendors/Products
 May 15, 2000 23:9 -InfoWorld
May 15 --
Intel on Monday announced the release of the open-source specification and reference implementation of its CDSA (Common Data Security Architecture) version 2, release 3.0 through the company Web site. The security specification will simplify the assignment of security technology . . .
Crypto-Gram May 15
Cryptography
 May 15, 2000 18:20 -Counterpane
May 15 --
Crypto-Gram is a free monthly newsletter providing summaries, analyses, insights, and commentaries on computer security and cryptography. This month Bruce Schneier discusses ILOVEYOU, more on Microsoft kerberos, and what it's going to take before we learn from previous mistkes. . . .
Features
    Build a Secure System with LIDS
LIDS ( Linux Intrusion Detection System) is a Linux kernel patch to enhance the Linux kernel. In this article, we will talk about LIDS, including what it can do and how to use it to build a secure linux system.
 
    Introduction To Authentication
In this feature, David Corcoran, founder of the Linux SmartCard Project, describes Unix passwords, their insecurities, RSA, and using RSA PAM authentication and possible attacks.
 
 
Advisories
KNapster Vulnerability 5/11/2000
It is possible for anyone to obtain any user-readable file by sending a properly formed "GET" command that contains the full path of the file. This vulnerability exists because knapster fails to check that the requested file is an explicitly shared MP3 file before providing it.
 
Red Hat, Inc. Bug Fix Advisory 5/11/2000
Various bugs in the SGML tools shipped with Red Hat Linux 6.2 have been fixed. These include: the install-catalog script could not properly remove some catalogs, the docbook-3.0 catalog entry references non-existent files, the stylesheets have a bug that causes problems when producing tex output
 
Secure Shell Authentication Vulnerability 5/10/2000
The RedHat Linux RPM ssh-1.2.27-8i.src.rpm from Zedz.net contains a PAM patch which contains faulty logic allowing users to essentially pass through the username/password authentication step and gain shell access.
 
FreeBSD: gnapster port allows remote users to view local files 5/9/2000
The gnapster port (version 1.3.8 and earlier) contains a vulnerability which allows remote gnapster users to view any file on the local system which is accessible to the user running gnapster.
 
Poll
Q.How Security Conscious is Your Organization?

Strict and enforced security policy in place
Moderate concern, but not first priority
Weak, people using 'password' for their password
Passwords taped to the monitor

[ Results ]

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000