Just days after a security researcher blasted its Java patching system, Sun Microsystems has issued a critical update to the consumer version of its Java software.
Read more »Internet Explorer Linked to Firefox Security Hole
In an interesting twist on browser-based security issues, security researchers said they have found a flaw in which Microsoft's Internet Explorer can cause Mozilla's Firefox to execute remote malicious code. Security firm Secunia released an advisory Tuesday, ranking the flaw as highly critical. The vulnerability is confirmed on Firefox 2.0.0.4 on a fully-patched version of Windows XP SP2.
Read more »Feds snub open source for 'smart' radios
By effectively siding with what is known in cryptography circles as "security through obscurity," the controversial idea that keeping security methods secret makes them more impenetrable, the FCC has drawn an outcry from the software radio set and raised eyebrows among some security experts.
Read more »Category: Government Tags:
- Login to post comments
Open source security arrives with Untangle
A few months after launching this blog I asked why there was no open source security.
Now there is. Untangle has released its network gateway under GPVv2. CEO (and blogger) Bob Walters compares his product to SONICwall and Watchguard, saying “we’ll sell services and premium products on top of it.”
- Login to post comments
Linux Less Secure Than Vista
I have been hearing a lot lately about how Windows Vista is being said to be more secure overall than the popular Linux distros in the market today.
Read more »Category: Opposition Tags:
- Login to post comments
Set-up a Ubuntu webcam security system
"Have you ever wanted to spy see on what is going on in your home while you are away? Motion is a piece of open source software that acts as a motion detector."
Read more »Category: High End Tags:
- Login to post comments
Patches - New Firm Eager to Slap Patents on Security Patches
a new firm is offering to work with you on a vulnerability patch that they will then patent and go to court to defend. You'll split the profits with the firm, Intellectual Weapons, if they manage to sell the patch to the vendor.
Read more »Intrusion detection with Snort on Red Hat Enterprise Linux 5
We're going to demonstrate how to quickly install and run the open source IDS sensor Snort on Red Hat Enterprise Linux 5 (RHEL 5). The instructions below will also generally work for RHEL 4, CentOS 4 and 5, as well as Fedora Core 5 and 6.
Read more »Category: High End Tags:
- Login to post comments
Microsoft's audacity at its best: "Our software is less of a security risk than Linux, Mac OS X"
"Wow. Sometimes, you read things like this and you wonder if Microsoft employees inhabit the same universe. Apparently, they haven't been following the rampant, constant security holes discovered and exploited in Windows over the past decade."
Read more »Category: High End Tags:
- Login to post comments
Detect insider threats with Linux auditing
Organizations of all sizes need to mitigate the risk of insider threats. Misconduct by authorized users represents a grave threat to an organization. According to the 2005 Computer Security Institute and Federal Bureau of Investigation Computer Crime and Security Survey, organizations reported that computer intrusions from inside sources accounted for nearly half of all incidents.
Read more »Microsoft: We patch faster than Apple, Novell, Red Hat - LinuxWorld
Windows users were at risk for in-the-wild vulnerabilities fewer days on average last year than users of rival operating systems from Apple, Novell, Red Hat and Sun, a Microsoft executive claimed.
Read more »Category: Community Tags:
- Login to post comments
Red Hat And IBM Add Security Certification
Red Hat Enterprise Linux 5 running on IBM servers now meets government security standards allowing Linux to be used in homeland security projects and command-and-control operations.
Read more »Category: End User Tags:
- Login to post comments
OpenOffice.org 2.2.1 fixes bugs, enhances security
The OpenOffice.org community yesterday released a bugfix and security update of the latest OO.org release and dubbed it version 2.2.1. No new features have been added since version 2.2 was released in late March, a team spokesperson said in the release announcement.
Read more »Category: End User Tags:
- Login to post comments
Safari for Windows, 0day exploit in 2 hours
The logic behind this vulnerability is quite simple and the vulnerability class has been known and understood for years, namely that of protocol handler command injection. A browser typically consists of a multitude of different URL schemes, some of which are handled by internal functions and others that are handed off to external applications
Read more »- Login to post comments
Google Says Microsoft Web Servers are Used to Distribute Malware
Microsoft's Internet Information Services (IIS) Web servers are more than twice as likely to deliver malware to unsuspecting users than the open source Apache Web server, according to a recent security survey performed by Internet search giant Google. That's quite an allegation, coming as it does from one of Microsoft's chief competitors.
[...]
Read more »