Linux Today: Linux News On Internet Time.








Most Read Stories

Editor's Picks

Linux 4.10 rc6
Linus Torvalds: So this week seemed very calm, and rc6 looked like it was going to be a nice tiny release. (Jan 29, 2017)

Linux Top 3: Arch Anywhere, Bitkey and Vinux
LinuxPlanet: From Arch to bitcoin to a Linux distribution to help those that are visually challenged... (Jan 23, 2017)

More on LinuxToday

Linux Today - Security

Google Patches 58 Android Vulnerabilities in February Security Update
(Feb 07, 2017, 23:00) (0 talkbacks)

eWEEK: Once again, Stagefright Android mediaserver flaws are being patched by Google to help protect Android users from potential security risks.

Gentoo Developer: Is The Linux Desktop Less Secure Than Windows 10?
(Feb 07, 2017, 19:00) (0 talkbacks)

Phoronix: Gentoo Linux developer Hanno Böck, presented on Feb. 5 at FOSDEM 2017 over some Linux desktop security shortcomings and how Microsoft Windows 10 is arguably more secure out-of-the-box.

OpenVAS - Vulnerability Assessment install on Kali Linux
(Feb 07, 2017, 05:00) (0 talkbacks)

HowToForge: This tutorial documents the process of installing OpenVAS 8.0 on Kali Linux rolling.

An Introduction to the Shorewall Firewall Tool
(Feb 06, 2017, 14:00) (0 talkbacks)

Linux.com: Shorewall is an open source firewalling tool that makes the task of network security easier.

How to configure ufw to forward port 80/443 to internal server hosted on LAN
(Feb 06, 2017, 04:00) (0 talkbacks)

 Nixcraft: UFW is an acronym for uncomplicated firewall.

Metasploit Targets Hardware for IoT Security Penetration Testing
(Feb 03, 2017, 12:00) (0 talkbacks)

eWEEK: Open-source Metasploit penetration testing framework adds new hardware support, enabling researchers to target IoT devices, starting with automotive.

How-to configure FirewallD zones bound by source IPs
(Feb 03, 2017, 07:00) (0 talkbacks)

Some network services should only be exposed to other computers on the same trusted network.

Privacy-Focused Tails 2.10 Linux Includes Security Updates, New Tools
(Feb 02, 2017, 23:00) (0 talkbacks)

eWEEK: The Amnesic Incognito Live System, also known more simply as Tails, is a privacy-focused Linux distribution loaded with tools and features to help users stay somewhat anonymous on the internet.

Aqua Security Provides Nano-Segmentation for Containers
(Feb 02, 2017, 13:00) (0 talkbacks)

eWEEK: Container Security Platform 2.0 release aims to help further segment application container traffic and adds new support for secrets management.

Facebook Delegated Recovery Protocol Offers New Password Reset Option
(Feb 01, 2017, 12:00) (0 talkbacks)

eWEEK: New open-source effort debuts to help improve the state of secure account recovery across internet services, starting with GitHub.

How To Configure SSH Key-based Authentication In Linux
(Feb 01, 2017, 07:00) (0 talkbacks)

 ostechnix: As we all know, SSH, also known as Secure Shell, is the cryptographic network protocol that allows you to securely communicate/access a remote system over unsecured network, for example Internet.

Protecting Your Privacy With Firefox on Linux
(Jan 31, 2017, 19:00) (0 talkbacks)

Linuxconfig: Privacy and security are becoming increasingly important topics.

OpenSSL issues new patches as Heartbleed still lurks
(Jan 31, 2017, 08:00) (0 talkbacks)

InfoWorld: The latest OpenSSL update may only address moderate-severity vulnerabilities, but admins shouldn't get lax about staying current with the patches

Generate SSL Certificates With LetsEncrypt Debian Linux
(Jan 30, 2017, 13:00) (0 talkbacks)

In case you haven't realized already, encryption is important.

ClamAV Antivirus Scanner For Linux (Review + Installation + Usage)
(Jan 30, 2017, 07:00) (0 talkbacks)

Malware, Viruses and Trojans on Linux are rare but not impossible as many would have you believe.

In Search of an Open Source DNS Server
(Jan 27, 2017, 12:00) (0 talkbacks)

FOSSforce: You'd think that in this day and age finding a free and open DNS server would be easy...

Allow Or Deny SSH Access To A Particular User Or Group In Linux
(Jan 27, 2017, 09:00) (0 talkbacks)

This brief tutorial explains how to allow or deny SSH access to a particular user or a group in Linux.

How to install LXD container under KVM or Xen virtual machine
(Jan 27, 2017, 08:00) (0 talkbacks)

 Nixcraft: You can implement the Linux container (LXD/LXC) to partition a your cloud server

Linux Networking with Connect2SSH
(Jan 26, 2017, 15:00) (0 talkbacks)

Connect2SSH is a BASH based script that allows for easier and quicker management of SSH and SSHFS sessions to unlimited hosts.

New Tor Security Updates Patch DoS Bug That Let Attackers Crash Relays, Clients
(Jan 26, 2017, 15:00) (0 talkbacks)

The most important bug fixed in the Tor 0.2.9.9 and Tor 0.3.0.2 Alpha versions is a denial-of-service (DoS) vulnerability that could allow an attacker to crash relays and clients

Firefox 51 Improves Security Notifications for Insecure Forms, Adds WebGL2 Support
(Jan 25, 2017, 10:00) (0 talkbacks)

eWEEK: Mozilla patches 24 security vulnerabilities in Firefox and now alerts users when they attempt to enter information into web forms that are not secure.

How to Run sudo Command Without Entering a Password in Linux
(Jan 25, 2017, 08:00) (0 talkbacks)

 tecmint: In case you are running Linux on a machine that you normally use alone, say on a laptop, entering a password each time you invoke sudo can become so boring in the long run.

How to create a new sudo user on Ubuntu Linux server
(Jan 24, 2017, 06:00) (0 talkbacks)

Nixcraft: In Linux (and Unix in general), there is a SuperUser named root.

How to Hide Apache Version Number and Other Sensitive Info
(Jan 24, 2017, 05:00) (0 talkbacks)

tecmint: Sometimes having less information is better for security

DB Ransom Attacks Spread to CouchDB and Hadoop
(Jan 23, 2017, 15:01) (0 talkbacks)

The erasure of data on improperly secured databases has broadened to include Apache-Hadoop's distributed storage and the NoSQL CouchDB.

Keeping Linux devices secure with rigorous long-term maintenance
(Jan 23, 2017, 07:00) (0 talkbacks)

In this ELCE talk, Jan Libbe of Pengutronix reveals how syncing with upstream projects can keep Linux devices secure and functional for 10 years and beyond.

How To Check The Password Complexity In Linux
(Jan 20, 2017, 13:00) (0 talkbacks)

 ostechnix: There are plenty of tools and websites are available to test the password complexity.

How to search exploits in metasploit?
(Jan 19, 2017, 13:00) (0 talkbacks)

blackmoreops: Searching exploits in MetaSploit made easy by SearchExploit.

Why Linux users should worry about malware and what they can do about it
(Jan 19, 2017, 06:00) (0 talkbacks)

PCWorld: Don't drop your guard just because you're running Linux.

It's time to patch BIND before your DNS servers lock up
(Jan 19, 2017, 04:00) (0 talkbacks)

ZDnet: A new set of BIND problems have emerged, and you should patch them before your servers get crunched by a DDoS attack.

Find Linux Exploits by Kernel version
(Jan 18, 2017, 11:00) (0 talkbacks)

blackmoreops: This is possibly the easiest way to find Linux Exploits by Kernel version.

Pwn2Own 2017 Takes Aim at Linux, Servers and Web Browsers
(Jan 18, 2017, 10:00) (1 talkbacks)

eWEEK: 10th anniversary edition of Pwn2Own hacking contest offers over $1M in prize money to security researchers across a long list of targets including Virtual Machines, servers, enterprise applications and web browsers.

3 Lessons in Web Encryption from Let’s Encrypt
(Jan 18, 2017, 09:00) (0 talkbacks)

Linux.com: We’re incredibly close to a Web that is more encrypted than not, says Josh Aas in this update from the Let’s Encrypt project.

Resolve to Follow These 8 Steps for Better Data Security in 2017
(Jan 18, 2017, 07:00) (0 talkbacks)

eWEEK: Simple steps, lather, rinse repeat.

Ultimate Cheat Sheet for Penetration Testers
(Jan 17, 2017, 07:00) (0 talkbacks)

This ultimate cheat sheet for Penetration testers is a high level overview for typical penetration testing environment ranging from nmap, sqlmap, ipv4, enumeration, fingerprinting etc.

5 Essential Tips for Securing Your WordPress Sites
(Jan 17, 2017, 04:00) (0 talkbacks)

In this post, we will provide some of the most common ways of securing and strengthening a WordPress site.

How to secure MongoDB on Linux
(Jan 16, 2017, 12:00) (0 talkbacks)

Nixcraft: Given the recent ransomware attacks on MongoDB, here is a detailed guide on how to secure access to MongoDB.

sshpass: Login To SSH Server / Provide SSH Password Using A Shell Script
(Jan 13, 2017, 10:00) (0 talkbacks)

Nixcraft: How do I login over ssh without using password less RSA / DSA public keys?

Docker 1.12.6 Fixes Privilege Escalation Vulnerability
(Jan 12, 2017, 14:00) (0 talkbacks)

InternetNews.com: Docker's first container engine release of 2017 provides a fix for an interesting security vulnerability.

WordPress 4.7.1 Updates for 8 Security Issues
(Jan 12, 2017, 10:00) (0 talkbacks)

eWEEK: Just over a month after the first WordPress 4.7 release, new incremental update debuts fixing 62 bugs, including a security flaw in the popular PHPMailer email library that was first publicly reported in December 2016.

Receive news via our XML/RSS feed

LinuxToday Security Archives