Security
News
- +
Experts to Feds: Sign the DNS root ASAP 26/11/2008 07:35:00
US government urged to deploy DNS security measures, but through ICANN not VeriSignInternet security gurus and leading vendors are urging the US federal government to rapidly deploy security and authentication mechanisms at the top level of the DNS hierarchy, which is known as the root zone. - +
IETF: Should we ignore the Kaminsky bug? 21/11/2008 07:41:00
Standards body debates fixing DNS or pushing new security schemeThe Internet engineering community is grappling with what to do about a serious flaw in the DNS discovered mid-year, and the ongoing debate brings to mind a famous quotation from Voltaire: "The perfect is the enemy of the good." - +
Mozilla fixes 11 new flaws in Firefox, six critical 14/11/2008 08:44:00
It also patches Firefox 2.0; just one more update coming for older browserMozilla on Wednesday patched 11 vulnerabilities in Firefox 3.0 -- and 12 bugs in the older Firefox 2.0 -- that could be used to compromise computers and steal information. - +
Survey: 1 in 4 DNS servers still vulnerable to Kaminsky flaw 11/11/2008 08:39:00
Annual report shows 25 percent of DNS servers still susceptible to cache poisoning via the Kaminsky flaw, 40 percent vulnerable to distributed denial of service attacksDespite industry efforts to lock down DNS servers, one in four remain vulnerable to cache poisoning due to the well-documented Kaminsky flaw identified earlier this year and another 40 percent could be considered a danger to themselves and others, recent research shows. - +
Mac, Linux, BSD open for attack: Kaspersky 20/10/2008 13:14:00
Hackers playground as users choose flexibility over security.Looming attacks will soon pop the security bubble enjoyed by Linux and Macintosh users, according to Russian security expert Eugene Kaspersky.
Features
- +
How CAPTCHA got trashed 15/07/2008 09:02:49
The wiggly words are now most useful for malware authorsCAPTCHA used to be an easy and useful way for Web administrators to authenticate users. Now it's an easy and useful way for malware authors and spammers to do their dirty work. - +
Fedora's FreeIPA offers identity, security services 14/07/2008 11:16:57
An ambitious open source project hopes to provide a unified directory and authentication server, but needs more interoperability work to become a viable competitor for Novell Identity Manager or Microsoft Active Directory.Fedora 9, released last month, included the first release of FreeIPA, a new free/open source project that comes out of Red Hat with the goal of becoming a complete and integrated security information management solution. In this article we take a look at exactly what FreeIPA is, both what it can do now and what its developers hope it will be capable of in the future. It seems destined to become a key feature of Red Hat Enterprise Linux 6, and with Fedora 9 released and FreeIPA tightly integrated, now seems to be the perfect time to explore this new technology. - +
SQL injections: What they are, how to stop them 19/05/2008 11:44:04
SQL injection experiencesSQL injection experiences. - +
10 ways the Chinese Internet is different from yours 13/05/2008 11:00:08
This slideshow complements the interview with James Fallows, who has experienced "The Great Firewall of China" firsthand. What follows is a list of the differences between the Internet, as seen in the US vs. China.This slideshow complements the interview with James Fallows, who has experienced "The Great Firewall of China" firsthand. What follows is a list of the differences between the Internet, as seen in the US vs. China. - +
Stupid hacker tricks: The folly of youth 06/05/2008 18:28:18
Tech-savvy delinquents set the Net aflame with boneheaded exploits that earn them the wrong kind of fameAh, youth. Ready to take on the world, today's generation of dynamic, tech-immersed youngsters have grown up alongside the Internet. Firsthand, and sometimes single-handedly, they have advanced some of today's hottest technology trends, from peer-to-peer networking, to massively multiplayer online games, to social networks and instant messaging. And along the way, a small, sociopathic number of them have behaved very, very badly.
Interviews
- +
At the front lines of protecting the Internet 03/09/2008 08:35:00
VeriSign's CTO on securing the DNS infrastructure and whether new identity certificates add any valueVeriSign is in many ways synonymous with managing the Web, thanks to its handling of key DNS root servers and of name resolution for .com, .net, and other domains. In recent years, it's had both strong ups and strong downs. - +
Chinese Internet censorship: An inside look 13/05/2008 10:32:56
Cisco, VPNs and other topics related to Internet access in ChinaJames Fallows, national correspondent for US publication The Atlantic Monthly, has experienced "The Great Firewall of China" firsthand, an experience people from around the world will share this summer when the Olympics comes to that country. Based in Beijing, Fallows has researched the underlying technology that the Chinese use for Internet censorship, and he explained it in a recent article titled "The Connection Has Been Reset." We e-mailed Fallows questions about how the Chinese government controls Internet content available to its citizens, and here's what he had to say (Check out our slideshow on the 10 ways the Chinese Internet is different from yours). - +
A stick of RAM, a can of air, and wow 11/03/2008 12:41:43
Researcher explains the 'cold boot' hack attackEver more computers are carrying ever more confidential data -- trade secrets, personal information of clients and constituents, and national security information. Encrypted hard disks requiring hardware keys or passwords are supposedly the way to keep that information safe. - +
Oxer on hardware hacking and the meaning of (Second) Life 14/02/2008 08:52:19
What happens when you knock down the boundaries between the real and virtual world?Jonathan Oxer is technical director of a Web application development company called Internet Vision Technologies and for the past couple of years has been president of the Linux Australia community group. At January's Linux.conf.au in Melbourne he presented a tutorial entitled Hardware / Software Hacking: Joining Second Life to the Real World. Computerworld recently spoke to Oxer about how he is knocking down the boundaries between the real and virtual world. Oxer also sheds light on his how his lifetime obsession with electronics has transformed his home-life into a software controlled environment. - +
Mozilla security chief on protecting Firefox users 05/02/2008 08:06:05
Window Snyder says browser vendors must work together -- and not blame usersWindow Snyder has the somewhat offbeat title of "chief security something-or-other" at Mozilla, where she is responsible for overseeing efforts to boost the security of the company's open-source offerings, including the Firefox browser.
Opinions
- +
Partially disclosing vulnerabilities does no one any good 30/09/2008 12:00:00
Partially disclosing vulnerabilities and building up hype before disclosing full details appears to be on the increase. Only problem is that it isn't doing anyone any good.What if I was to tell you that I have a secret that could end the Internet as you know it? What if I was only going to tell you at a fee-based conference once speculation had gone on for a month or more? How would you respond to that? - +
Wider implications of the Red Hat breach 29/08/2008 09:11:00
Red Hat's recent server breach isn't the first time that a Linux distribution has been targeted by attackers, but it could be one of the most important attacks in terms of the recovery and mitigation processes.Reports of data losses and system breaches are almost becoming passe but from time to time events happen that take on a life of their own and have effects far beyond what the initial breach would normally represent. - +
Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21
BackTrack is the quickest way to get access to hundreds of (legal) hacking toolsVersion 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools. - +
How to avoid the Debian SSH key attacks 16/05/2008 08:35:57
It only took two days, but viable, simple attacks against the weak Debian SSH key generation flaw have surfacedIf you are running a Debian-based Linux system and haven't already caught up with the announcement [1] that there was a major flaw with the generation of SSH, OpenVPN, DNSSEC, SSL/TLS session keys and X.509 certificate key material, you might want to update your system to address the problem. - +
Pentagon hacks and Google Maps 11/03/2008 09:56:12
Pentagon gets owned via an ordinary spear phishing attackI have this nosy but absent-minded Uncle. He likes to paw through my emails, peruse my web history, and tap my phones. But when it comes to protecting his own, more important secrets, he's mostly clueless.
Additional Resources
LinuxWorld Member Login
F-Secure Warns About a Worm Affecting Corporate Networks 2009-01-08 16:42:00+11
Fortinet Cures Mobile Phone “Curse of Silence/CurseSMS” Attack 2009-01-07 16:30:00+11
SEAGATE SHIPS DESKTOP HARD DRIVE WITH WORLD’S HIGHEST AREAL DENSITY – 500GB PER DISK 2009-01-06 15:34:00+11
New FileMaker Pro 10 Ships With Sleek New Interface and Breakthrough Reporting and Automating Features 2009-01-06 12:21:00+11
Lexar extends KODAK offering with Secure Digital High-Capacity, High-Speed Memory Card 2009-01-06 09:36:00+11
Sponsored Links



