Security
The Top 5 Most Overlooked Open Source Vulnerabilities for 2007
Submitted by Ty on December 13, 2007 - 3:00pm"For year-end 2007, we have compiled the Top 5 Most Overlooked Open Source Vulnerabilities encountered during 2007. We came up with this list after reviewing over 300 million lines of code and spending literally thousands of hours of analysis across a wide range of industries - including technology, financial services and government, among others."
Top Ten Security 2008
Submitted by Ty on December 11, 2007 - 12:00pm"Two weeks ago I was in L.A., jumping from meeting after meeting, and at the end of every meeting, I asked everyone what they saw in the Identity and Access Management road ahead. I got some great answers, which you can peruse right here, and just this morning, I got these additional answers from Baber Amin of Novell, and definitely thought they were worth adding to the discussion. And hey, it is the holidays, so I can certainly forgive a little lateness."
Breach Security's ModSecurity Open Source Web Application Firewall
Submitted by Ty on December 6, 2007 - 10:00amBreach Security announced today that the Breach Security WebDefend web application firewall has earned certification by ICSA Labs, an independent division of Verizon. WebDefend is one of the first web application firewall products to achieve this distinction.
New Hardeware Monitoring and Security Tools from "Linux Firewalls"
Submitted by engarde on December 3, 2007 - 2:00pmGuardian Digital is happy to announce the release of EnGarde Secure Community 3.0.18 (Version 3.0, Release 18). This release includes many updated packages and bug fixes, some feature enhancements to Guardian Digital WebTool and the SELinux policy, and a few new features.
IBM Lotus Notes for Linux Multiple Insecure File Permission Vulnerabilities
Submitted by Ty on November 29, 2007 - 9:00amMultiple vulnerabilities have been identified in IBM Lotus Notes for Linux, which could be exploited by malicious users to bypass security restrictions and potentially compromise a vulnerable system. These issues are caused due to insecure permissions being set on extracted binaries and the installdata file when executing the installer program, which could be exploited by a local attacker to modify arbitrary files such that subsequent installs performed by the root user could deploy malicious content or code to end user systems.
Linux Kernel Multiple Denial of Service Vulnerabilities
Submitted by Ty on November 19, 2007 - 1:00pmSome vulnerabilities have been reported in the Linux Kernel, which can be exploited by malicious, local users and by malicious people to cause a DoS (Denial of Service). The vulnerabilities are reported in versions prior to 2.6.23.8.
EnGarde Secure Linux 3.0.17 Released
Submitted by engarde on October 9, 2007 - 11:00amLaunched by Guardian Digital with: brand new daemon control functionality, improved password shadowing, load balancing improvements and much more. EnGarde Secure Linux is a fully-functional platform engineered from the ground up for high levels of security explicitly for server operations.
Attacking Log analysis tools
Submitted by Ty on October 5, 2007 - 1:00pmLog Analysis (i.e. LIDS - Log-Based Intrusion Detection) can be a very powerful tool to complement NIDS/HIDS and improve network security. I pointed out some of its benefits in the following articles: Log analysis for intrusion detection and Log analysis using OSSEC.
However, like any other technology, when not done properly, it can add new security vulnerabilities and end up causing more harm than good.
Linux is new phishing threat to eBay
Submitted by Ty on October 4, 2007 - 11:00ameBay says online criminals are getting more organized and branching out from the Windows operating system to use the open-source Linux platform.
Security drives open source technology deployment in Asia
Submitted by Ty on October 2, 2007 - 11:00amThe top most influential factor for deploying open source technology in Australia, Korea, India and the People's Republic of China is better protection against security breaches, according to a survey by IDC. "The results indicate that organizations perceived open source technology as providing better security compared to proprietary products," said Prianka Srinivasan, a software market analyst with IDC Asia/Pacific.
Smoothwall 3.0 Released
Submitted by Ty on September 26, 2007 - 2:00pmSmoothwall has released their new version of their free Web-Based firewall. The newer version has lots of new features such as, a fourth interface "Purple for wireless clients". It's also been rebuilt on the 2.6 kernel. Four different versions, 32/64 bit express and 32/64 bit Developer editions.
Advanced Security Management Tool for Linux
Submitted by Ty on August 20, 2007 - 1:00pmTrusted Computer Solutions announced the launch of Security Blanket, a system lock-down and security management tool that enables systems administrators to automatically configure and enhance the security level of the Red Hat Enterprise Linux operating platform. Supporting Red Hat Enterprise Linux 4 and 5, this Linux security solution simplifies the current arduous methods for "hardening" systems that administrators must address on a regular basis.
Launch of EnGarde Linux Community
Submitted by engarde on August 7, 2007 - 12:00pmGuardian Digital is happy to announce the release of EnGarde Secure Community 3.0.16 (Version 3.0, Release 16). This release includes many updated packages and bug fixes, some feature enhancements to Guardian Digital WebTool and the SELinux policy, and a few new features.
Security gateway goes open source for all
Submitted by Ty on July 5, 2007 - 1:00pmUntangle has made its open source security software available free for download to network managers supporting environments of all sizes.
Untangle Brings Small Business Network Security
Submitted by sharonpr on June 26, 2007 - 10:00amOnly open source platform to unify security products providing, a free and better alternative to SonicWall and other appliance vendors.

















