E-Mail:

Security

Botnets Are Go!

Honestly, I am not really sure how this is news? While it is true that malware and yes, botnets can be used on poorly secured servers run by inexperienced administrators, I really think this article is blowing things out of proportion.
What most people need to realize is that this is something that has both been [...]

Just How Secure Is Linux?

It’s a question that haunts so many new comers to the penguin way of computing - do they need an antivirus? While many of us find the very idea amusing, this article serves as a reminder that it is going to be a cold day in Hell before we have the kind of malware issues [...]

Newbies Knows No Bounds

Found this today and I must admit, as absurd as the idea of Ubuntu being “hacked” sounds, all one really needs to do is dig deeper into the details. Based on what I have read myself, I am of the mind that there is clearly someone using remote desktop to take advantage of a rather [...]

OpenSSH Encryption Flawed?

Great, it looks like I am not able to have the same confidence in OpenSSH that I once had. Or perhaps, this is not that big of a deal after all? To be fair though, the odds are pretty low that I have anything to worry about so long as I take the usual precautions. [...]

AVG Is Back And This Time - It Works

The last time I tried AVG for Linux, it was completely useless. Not due to a lack of need for an anti-virus in Linux. Anyone wanting to protect an NTFS partition used with Windows might as well be able to do so from their Linux install. No, rather due to the fact that AVG for [...]

Exploit code released for Nvidia flaw

Alright, so is this Nvidia code bug fixed or isn’t it? From what I am seeing, it appears that there are some conflicting reports.
Exploit code has been published for a security flaw in Nvidia’s Linux graphics driver that could let a remote intruder take over a system.
The proof-of-concept code shows how an attacker could launch [...]

Linux worm turns on Mambo and PHP

Hey Mambo and PHP users, you might want to make yourself aware of the security alert going around with regard to a nasty Linux worm working its way through certain systems.

What Will Apple Do When the Malware Comes?

For the most part, the idea of malware in Linux and OS X has been all but laughable. Still, I would challenge folks to tell me that having an outbreak in the future would be impossible. Sure, we do have that great Unix-styled security with limited access by default. But who’s to say what the [...]

Windows - unsafe on any network

Personally, I think it’s unbelievable how unaware some folks are when it comes to now securing an OS properly. The article below really sums it all up I think…

ClamAV hole sees Linux vendors rush out updates

I suppose some might argue that this is what we should expect from an Open Source antivirus. Speaking for myself, I think it could happen to any antivirus app…

Novell SUSE Linux Enterprise Server Remote Manager Heap Overflow

I can’t get the current iDefence vulnerabilities page - I suspect it is because there are far too many people trying to get that page served to them (to do my part I’ve stopped trying to get it…) This info is from the e-mail that was sent to the mailing list. Sorry about [...]

Linux/BSD still exposed to WMF exploit through WINE!

George Ou writes on ZDNet.com Blogs,
While news of Microsoft’s official patch for the WMF exploit reaches the web, I just received an email from H D Moore (founder of the metasploit project and creator of the original proof-of-concept WMF exploit code) that WINE was still vulnerable to the WMF exploit. He was kind enough [...]

Opera Command Line URL Shell Command Injection

Secunia Advisory: SA16907
Critical: Highly critical -
Impact: System access -
Where: From remote -
Solution Status: Vendor Patch -
Software: Opera 7.x, Opera 8.x

Secunia Research has discovered a vulnerability in Opera, which can be exploited by malicious people to compromise a user’s system.

The vulnerability is caused due to the shell script used to launch Opera parsing shell commands that are [...]

Nine principles of security architecture

Apparently getting into the groove with security architecture is not as cut and dry as we once thought?

Linux Real, HelixPlayer Users at Risk

Well, this certainly blows. Apparently the Real Player for Linux has some flaws that could spell trouble for ‘Joe-User’ out there. With any luck, the flaw will be fixed here soon. Until then, I think that I will skip over this myself.

Peter van der Linden’s Guide to Linux: A Lesson in Encryption, Part 1

With most people, when they think encryption, they think of things like PGP encryption. But how many of us truly understand it? Not as many as we might like to think apparently. Good thing there are guides like this to help us along the way.

Thunderbird Command Line URL Shell Command Injection

A vulnerability has been discovered in Thunderbird, which can be exploited by malicious people to compromise a user’s system.
The vulnerability is caused due to the shell script used to launch Thunderbird is parsing shell commands that are enclosed within backticks in the URL provided via the command line. This can e.g. be exploited to execute [...]

Mozilla Command Line URL Shell Command Injection

“Secunia Advisory: SA16846
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Mozilla 1.7.x
A vulnerability has been discovered in Mozilla Suite, which can be exploited by malicious people to compromise a user’s system.
For more information: SA16869
This vulnerability can only be exploited on Unix / Linux based environments.
The vulnerability has been confirmed in version 1.7.11. Other versions [...]

Firefox Command Line URL Shell Command Injection

“Secunia Advisory: SA16869
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Mozilla Firefox 1.x

No magic bullet for security

I am too tired today and will refrain from getting onto my soapbox. I will say for the record that while MS works hard at using the word security, they still need to do something about their own track record before most people will ever take them seriously when compared to OSS in the security [...]

27 queries / 0.259 seconds.