<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>nixCraft &#187; Security Alert</title> <atom:link href="http://www.cyberciti.biz/tips/category/security-alert/feed" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/tips</link> <description>This is a Linux sys admin journal by Vivek about sys admin work, Linux tips &#38; tricks, hacks, news and more.</description> <lastBuildDate>Wed, 24 Apr 2013 18:50:55 +0000</lastBuildDate> <language>en-US</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.5.1</generator> <item><title>Slowloris DoS Tool: It Can Bring Down Apache 1.x/2.x</title><link>http://www.cyberciti.biz/tips/apache-http-dos-tool-released.html</link> <comments>http://www.cyberciti.biz/tips/apache-http-dos-tool-released.html#comments</comments> <pubDate>Fri, 19 Jun 2009 14:50:39 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Apache]]></category> <category><![CDATA[Networking]]></category> <category><![CDATA[News]]></category> <category><![CDATA[PF Firewall]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[UNIX]]></category> <category><![CDATA[Windows server]]></category> <category><![CDATA[accf]]></category> <category><![CDATA[apache dos attack]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[denial of service attack]]></category> <category><![CDATA[distributed denial of service ddos attack]]></category> <category><![CDATA[dns ddos attack]]></category> <category><![CDATA[dos attack]]></category> <category><![CDATA[dos tool]]></category> <category><![CDATA[incoming connections]]></category> <category><![CDATA[kernel module]]></category> <category><![CDATA[lighttpd]]></category> <category><![CDATA[memory exhaustion]]></category> <category><![CDATA[proxy]]></category> <category><![CDATA[squid]]></category> <category><![CDATA[web server]]></category> <category><![CDATA[webservers]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=5138</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/apache' title='See all Apache Webserver related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/apachelogo.gif' border='0' /></a></div> Apache Security Update - a flaw In Apache can be used to carry out DoS. Slowloris is a new Apache DoS tool which can use slow Internet links to bring down Apache servers, rather than flooding networks. Most D/DoS tool requires faster net connections but this tool works with minimal bandwidth.  This tool can lead to a DoS attack on Apache 1.x, 2.x, dhttpd, GoAhead WebServer, and Squid, while MS IIS6.0, IIS7.0, and lighttpd are confirmed not vulnerable to this attack.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/apache-http-dos-tool-released.html/feed</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>Important: Openssl Security Update [CVE-2008-5077]</title><link>http://www.cyberciti.biz/tips/cve20085077-important-openssl-security-update.html</link> <comments>http://www.cyberciti.biz/tips/cve20085077-important-openssl-security-update.html#comments</comments> <pubDate>Thu, 08 Jan 2009 21:58:45 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[CentOS]]></category> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[fedora linux]]></category> <category><![CDATA[FreeBSD]]></category> <category><![CDATA[GNU/Open source]]></category> <category><![CDATA[Howto]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[News]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[Slackware]]></category> <category><![CDATA[Suse Linux]]></category> <category><![CDATA[Sys admin]]></category> <category><![CDATA[asc]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[certificate chain]]></category> <category><![CDATA[CVE-2008-5077]]></category> <category><![CDATA[digital signature]]></category> <category><![CDATA[dsa]]></category> <category><![CDATA[evp]]></category> <category><![CDATA[fedora]]></category> <category><![CDATA[general purpose]]></category> <category><![CDATA[google]]></category> <category><![CDATA[important security]]></category> <category><![CDATA[industry strength]]></category> <category><![CDATA[malicious server]]></category> <category><![CDATA[man in the middle attack]]></category> <category><![CDATA[openssl project]]></category> <category><![CDATA[patch cd]]></category> <category><![CDATA[secure sockets layer]]></category> <category><![CDATA[security issue]]></category> <category><![CDATA[security team]]></category> <category><![CDATA[transport layer security]]></category> <category><![CDATA[yum]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4283</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/unix' title='See all UNIX(R) related articles/tips'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/unix-logo.gif' border='0' /></a></div> Linux / BSD and UNIX like operating systems includes software from the OpenSSL Project. The OpenSSL is commercial-grade, industry-strength,  full-featured Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as general purpose cryptography library. <br
/><br
/> The Google security team discovered a flaw in the way OpenSSL checked the verification of certificates. An attacker in control of a malicious server,  or able to effect a "man in the middle" attack, could present a malformed SSL/TLS signature from a certificate chain to a vulnerable client and bypass validation. <br
/><br
/> This update has been rated as having important security impact on FreeBSD, all version of Ubuntu / Debian, Red Hat (RHEL), CentOS, Fedora and other open source operating system that depends upon OpenSSL.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/cve20085077-important-openssl-security-update.html/feed</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Debian GNU/Linux 4.0 Update 6 Released</title><link>http://www.cyberciti.biz/tips/debian-linux-4-update-6-released.html</link> <comments>http://www.cyberciti.biz/tips/debian-linux-4-update-6-released.html#comments</comments> <pubDate>Thu, 18 Dec 2008 14:07:25 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[apt-get command]]></category> <category><![CDATA[aptitude]]></category> <category><![CDATA[arbitrary code execution]]></category> <category><![CDATA[architectures]]></category> <category><![CDATA[debian project]]></category> <category><![CDATA[gnu linux]]></category> <category><![CDATA[how to upgrade debian]]></category> <category><![CDATA[important security]]></category> <category><![CDATA[kernels]]></category> <category><![CDATA[package archive]]></category> <category><![CDATA[security problems]]></category> <category><![CDATA[stable distribution]]></category> <category><![CDATA[stable release]]></category> <category><![CDATA[upgrade debian]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4012</guid> <description><![CDATA[<p><div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/debian-linux' title='See all Debian/Ubuntu Linux related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/debianlogo.gif' border='0' /></a></div> Didn't take long to release new <a
href="http://www.cyberciti.biz/tips/debian-gnulinux-40-update-5-available.html">updated version</a>. <br
/> The Debian project is pleased to announce the sixth update of its stable distribution Debian GNU/Linux 4.0 (codename "etch").  This update mainly adds corrections for security problems to the stable release, along with a few adjustment to serious problems. This update has been rated as having important security impact. You are advised to upgrade system ASAP.</p>]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/debian-linux-4-update-6-released.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Mozilla Patches 8 Security Flaws</title><link>http://www.cyberciti.biz/tips/mozilla-patches-8-security-flaws.html</link> <comments>http://www.cyberciti.biz/tips/mozilla-patches-8-security-flaws.html#comments</comments> <pubDate>Wed, 17 Dec 2008 18:02:43 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[GNU/Open source]]></category> <category><![CDATA[Linux desktop]]></category> <category><![CDATA[Mozilla]]></category> <category><![CDATA[OS X]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[UNIX]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[windows vista]]></category> <category><![CDATA[accessibility]]></category> <category><![CDATA[bengali]]></category> <category><![CDATA[crash]]></category> <category><![CDATA[critical bugs]]></category> <category><![CDATA[esperanto]]></category> <category><![CDATA[firefox]]></category> <category><![CDATA[galician]]></category> <category><![CDATA[implementation]]></category> <category><![CDATA[languages]]></category> <category><![CDATA[license agreement]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[patches]]></category> <category><![CDATA[platforms]]></category> <category><![CDATA[previous versions]]></category> <category><![CDATA[security flaws]]></category> <category><![CDATA[security issues]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[software updates]]></category> <category><![CDATA[stability issues]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4006</guid> <description><![CDATA[<div
style="float:right;margin-top:0px;margin-left:5px;"><a
title="See all Mozilla FireFox related tips/articles" href="http://www.cyberciti.biz/tips/category/mozilla"><img
src="http://files.cyberciti.biz/cbzcache/3rdparty/firefox.png" border="0" alt="" /></a></div> Mozilla has released software updates to fix at least 8 security vulnerabilities (3 critical bugs) in its Firefox software for the Windows, Linux, Mac and other platforms. You can now download Firefox version 3.0.5. This update has been rated as having important security impact.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/mozilla-patches-8-security-flaws.html/feed</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Security Update: Debian Linux Kernel Local / Remote Vulnerabilities</title><link>http://www.cyberciti.biz/tips/linux-2624-packages-fix-several-vulnerabilities.html</link> <comments>http://www.cyberciti.biz/tips/linux-2624-packages-fix-several-vulnerabilities.html#comments</comments> <pubDate>Thu, 04 Dec 2008 18:54:14 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[kernel]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[CVE-2008-3528]]></category> <category><![CDATA[CVE-2008-4554]]></category> <category><![CDATA[CVE-2008-4576]]></category> <category><![CDATA[CVE-2008-4618]]></category> <category><![CDATA[CVE-2008-4933]]></category> <category><![CDATA[CVE-2008-4934]]></category> <category><![CDATA[CVE-2008-5025]]></category> <category><![CDATA[CVE-2008-5029]]></category> <category><![CDATA[CVE-2008-5134]]></category> <category><![CDATA[CVE-2008-5182]]></category> <category><![CDATA[CVE-2008-5300]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[distros]]></category> <category><![CDATA[escalation]]></category> <category><![CDATA[eugene teo]]></category> <category><![CDATA[ext2]]></category> <category><![CDATA[ext3]]></category> <category><![CDATA[filesystem]]></category> <category><![CDATA[important security]]></category> <category><![CDATA[infinite loop]]></category> <category><![CDATA[kernel panic]]></category> <category><![CDATA[linux kernel]]></category> <category><![CDATA[memory corruption]]></category> <category><![CDATA[milos]]></category> <category><![CDATA[offsets]]></category> <category><![CDATA[output error messages]]></category> <category><![CDATA[problem description]]></category> <category><![CDATA[security holes]]></category> <category><![CDATA[security updates]]></category> <category><![CDATA[semantics]]></category> <category><![CDATA[stable distribution]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=3774</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/debian-linux' title='See all Debian/Ubuntu Linux related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/debianlogo.gif' border='0' /></a></div> Debian project today released a pair of security updates to plug at least ten security holes in its core called Linux kernel. Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. This update has been rated as having important security impact.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/linux-2624-packages-fix-several-vulnerabilities.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Debian PHP 5 Security Issues</title><link>http://www.cyberciti.biz/tips/debian-php-5-security-issues.html</link> <comments>http://www.cyberciti.biz/tips/debian-php-5-security-issues.html#comments</comments> <pubDate>Thu, 27 Nov 2008 04:49:16 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Apache]]></category> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[lighttpd]]></category> <category><![CDATA[php]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[aptitude]]></category> <category><![CDATA[cve]]></category> <category><![CDATA[CVE-2009-2626]]></category> <category><![CDATA[CVE-2009-2687]]></category> <category><![CDATA[CVE-2009-3291]]></category> <category><![CDATA[CVE-2009-3292]]></category> <category><![CDATA[default limit]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[denial of service attacks]]></category> <category><![CDATA[disruptions]]></category> <category><![CDATA[exhaustion]]></category> <category><![CDATA[existing services]]></category> <category><![CDATA[file names]]></category> <category><![CDATA[file uploads]]></category> <category><![CDATA[image data]]></category> <category><![CDATA[jpeg images]]></category> <category><![CDATA[new option]]></category> <category><![CDATA[php 5]]></category> <category><![CDATA[security issues]]></category> <category><![CDATA[serious security]]></category> <category><![CDATA[temporary file]]></category> <category><![CDATA[temporary files]]></category> <category><![CDATA[web server]]></category> <category><![CDATA[x509 certificates]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=6093</guid> <description><![CDATA[<div
style="float:right;margin-top:0px;margin-left:5px;"><a
title="See all Debian/Ubuntu Linux related tips/articles" href="http://www.cyberciti.biz/tips/category/debian-linux"><img
src="http://files.cyberciti.biz/cbzcache/3rdparty/debianlogo.gif" border="0" alt="" /></a></div> Debian 5 php5 package has serious security issues as follows:
To prevent Denial of Service attacks by exhausting the number of available temporary file names, the max_file_uploads option introduced in PHP 5.3.1 has been backported.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/debian-php-5-security-issues.html/feed</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>FreeBSD Kernel Critical Update: arc4random predictable sequence vulnerability</title><link>http://www.cyberciti.biz/tips/cve-2008-5162-freebsd-arc4random.html</link> <comments>http://www.cyberciti.biz/tips/cve-2008-5162-freebsd-arc4random.html#comments</comments> <pubDate>Tue, 25 Nov 2008 12:49:44 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[FreeBSD]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[cryptographic purposes]]></category> <category><![CDATA[cryptographic strength]]></category> <category><![CDATA[CVE-2008-5162]]></category> <category><![CDATA[freebsd kernel]]></category> <category><![CDATA[freebsd system]]></category> <category><![CDATA[key stream]]></category> <category><![CDATA[predictable sequence]]></category> <category><![CDATA[random data]]></category> <category><![CDATA[random number generator]]></category> <category><![CDATA[rc4]]></category> <category><![CDATA[security branch]]></category> <category><![CDATA[security hole]]></category> <category><![CDATA[sockstat Command]]></category> <category><![CDATA[stable release]]></category> <category><![CDATA[stream generator]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=3659</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/freebsd' title='See all FreeBSD related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/freebsd_logo_sm.png' border='0' /></a></div> FreeBSD today released a core (kernel) patched to plug "arc4random predictable sequence vulnerability" security hole in its operating systems version 6.x and 7.x stable release. When the arc4random random number generator is initialized, there may be inadequate entropy to meet the needs of kernel systems which rely on arc4random; and it may take up to 5 minutes before arc4random is reseeded with secure entropy from the Yarrow random number generator. All security-related kernel subsystems that rely on a quality random number generator are subject to a wide range of possible attacks. This update has been rated as having important security impact.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/cve-2008-5162-freebsd-arc4random.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Security Alert: Streamripper buffer overflow bug</title><link>http://www.cyberciti.biz/tips/cve20074337-cve20084829-streamripper.html</link> <comments>http://www.cyberciti.biz/tips/cve20074337-cve20084829-streamripper.html#comments</comments> <pubDate>Sat, 08 Nov 2008 19:09:39 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[apt-get command]]></category> <category><![CDATA[buffer overflow bug]]></category> <category><![CDATA[buffer overflows]]></category> <category><![CDATA[CVE-2007-4337]]></category> <category><![CDATA[CVE-2008-4829]]></category> <category><![CDATA[parsing]]></category> <category><![CDATA[playlist]]></category> <category><![CDATA[sid]]></category> <category><![CDATA[stable distribution]]></category> <category><![CDATA[streamripper]]></category> <category><![CDATA[unstable distribution]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=3859</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/debian-linux' title='See all Debian/Ubuntu Linux related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/debianlogo.gif' border='0' /></a></div> Multiple buffer overflows involving HTTP header and playlist parsing have been discovered in streamripper (CVE-2007-4337, CVE-2008-4829). ]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/cve20074337-cve20084829-streamripper.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Red Hat Enterprise Linux 5 IMPORTANT Security Update [ 4-Nov-2008 ]</title><link>http://www.cyberciti.biz/tips/red-hat-enterprise-linux5-critical-security.html</link> <comments>http://www.cyberciti.biz/tips/red-hat-enterprise-linux5-critical-security.html#comments</comments> <pubDate>Tue, 04 Nov 2008 21:35:30 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[kernel]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[News]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[checks]]></category> <category><![CDATA[cr4]]></category> <category><![CDATA[critical security]]></category> <category><![CDATA[CVE-2006-5755 CVE-2007-5907 CVE-2008-2372 CVE-2008-3276 CVE-2008-3527 CVE-2008-3833 CVE-2008-4210 CVE-2008-4302]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[enterprise linux]]></category> <category><![CDATA[failure]]></category> <category><![CDATA[implementation]]></category> <category><![CDATA[important security]]></category> <category><![CDATA[kernel updates]]></category> <category><![CDATA[linux kernel]]></category> <category><![CDATA[page cache]]></category> <category><![CDATA[privileged information]]></category> <category><![CDATA[privileges]]></category> <category><![CDATA[reboot]]></category> <category><![CDATA[red hat enterprise]]></category> <category><![CDATA[rhel 5]]></category> <category><![CDATA[security flaws]]></category> <category><![CDATA[setuid]]></category> <category><![CDATA[system kernel]]></category> <category><![CDATA[tavis]]></category> <category><![CDATA[yum]]></category> <category><![CDATA[yum command]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=3434</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/redhatfedora-linux' title='See all Redhat/CentOS/Fedora Core related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/rhlogo.gif' border='0' /></a></div> Red Hat today released kernel updates to fix at least 15 security flaws in its core called Linux kernel. RHEL users can grab the latest updates from RHN website or by simply running yum update command. This update has been rated as having important security impact.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/red-hat-enterprise-linux5-critical-security.html/feed</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Debian Upgrade: GNU/Linux 4.0 Update 5 Available</title><link>http://www.cyberciti.biz/tips/debian-gnulinux-40-update-5-available.html</link> <comments>http://www.cyberciti.biz/tips/debian-gnulinux-40-update-5-available.html#comments</comments> <pubDate>Fri, 24 Oct 2008 11:05:05 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[Howto]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[debian etch update server]]></category> <category><![CDATA[debian install kernel-headers]]></category> <category><![CDATA[debian update]]></category> <category><![CDATA[debian upgrade]]></category> <category><![CDATA[debian upgrade howto]]></category> <category><![CDATA[debian-update-4]]></category> <category><![CDATA[how to upgrade debian]]></category> <category><![CDATA[update debian]]></category> <category><![CDATA[upgrade debian]]></category> <category><![CDATA[upgrading debian remotely]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=3176</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/debian-linux' title='See all Debian/Ubuntu Linux related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/debianlogo.gif' border='0' /></a></div> The industry strength community driven enterprise grade Debian GNU/Linux version 4.0 stable update 5 has been released and available for immediate downloaded as well as updates via apt-get package manager.  This update mainly adds corrections for security problems to the stable release, along with a few adjustment to serious problems. All users are advised to upgrade system.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/debian-gnulinux-40-update-5-available.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Critical Red Hat Enterprise Linux Kernel Update</title><link>http://www.cyberciti.biz/tips/critical-red-hat-enterprise-linux-kernel-update.html</link> <comments>http://www.cyberciti.biz/tips/critical-red-hat-enterprise-linux-kernel-update.html#comments</comments> <pubDate>Wed, 01 Oct 2008 08:44:57 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[GNU/Open source]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[package management]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[CVE-2007-6417]]></category> <category><![CDATA[CVE-2007-6716]]></category> <category><![CDATA[CVE-2008-2931]]></category> <category><![CDATA[CVE-2008-3272]]></category> <category><![CDATA[CVE-2008-3275]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[important security]]></category> <category><![CDATA[information leak]]></category> <category><![CDATA[kernel package]]></category> <category><![CDATA[linux kernel]]></category> <category><![CDATA[overrun]]></category> <category><![CDATA[packet loss]]></category> <category><![CDATA[reboot]]></category> <category><![CDATA[red hat]]></category> <category><![CDATA[samba servers]]></category> <category><![CDATA[security fixes]]></category> <category><![CDATA[security holes]]></category> <category><![CDATA[stopping traffic]]></category> <category><![CDATA[tobias klein]]></category> <category><![CDATA[virtual machines]]></category> <category><![CDATA[yum]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=3002</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/redhatfedora-linux' title='See all Redhat/CentOS/Fedora Core related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/rhlogo.gif' border='0' /></a></div> Red Hat issued an update version of Linux operating system core called kernel that plugs various security holes for RHEL 5.x. This update has been rated as having important security impact. All users are advised to upgrade kernel package. ]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/critical-red-hat-enterprise-linux-kernel-update.html/feed</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Security Alert: How To Stop Firefox Clickjacking Exploit Attack</title><link>http://www.cyberciti.biz/tips/firefox-stop-clickjacking-attack.html</link> <comments>http://www.cyberciti.biz/tips/firefox-stop-clickjacking-attack.html#comments</comments> <pubDate>Fri, 26 Sep 2008 09:03:55 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[CentOS]]></category> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[fedora linux]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Linux desktop]]></category> <category><![CDATA[Mozilla]]></category> <category><![CDATA[OS X]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[windows vista]]></category> <category><![CDATA[apple safari]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[Clickjacking]]></category> <category><![CDATA[desktop operating systems]]></category> <category><![CDATA[digg]]></category> <category><![CDATA[firefox]]></category> <category><![CDATA[fundamental flaw]]></category> <category><![CDATA[malicious scripts]]></category> <category><![CDATA[malicious website]]></category> <category><![CDATA[ms ie]]></category> <category><![CDATA[msnbc]]></category> <category><![CDATA[noscript]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2966</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/mozilla' title='See all Mozilla FireFox related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/firefox.png' border='0' /></a></div> Really scary exploit attack in wild, which affects all browsers under any desktop operating systems including MS IE, Linux, Apple safari, Opera, Firefox and Adobe flash. Any website that uses CSS and IFRAME (used to serve ads) can be used to attack on end users as attacker is able to take control of the links that your browser visits. In this article I will share few tips to stop this deadly attack until final patch is released by vendors. ]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/firefox-stop-clickjacking-attack.html/feed</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Security Alert: Debian OpenSSH packages Fix Denial of Service</title><link>http://www.cyberciti.biz/tips/debian-openssh-packages-fix-denial-of-service.html</link> <comments>http://www.cyberciti.biz/tips/debian-openssh-packages-fix-denial-of-service.html#comments</comments> <pubDate>Tue, 16 Sep 2008 21:09:28 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[package management]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[Ubuntu Linux]]></category> <category><![CDATA[apt-get command]]></category> <category><![CDATA[CVE-2008-4109]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[dos vulnerability]]></category> <category><![CDATA[internal database]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[login attempts]]></category> <category><![CDATA[openssh server]]></category> <category><![CDATA[problem login]]></category> <category><![CDATA[service vulnerability]]></category> <category><![CDATA[signal handler]]></category> <category><![CDATA[zombie]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2921</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/debian-linux' title='See all Debian/Ubuntu Linux related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/debianlogo.gif' border='0' /></a></div> Debian Linux project released the Openssh security updates for computers powered by its Debian Linux operating systems. It has been discovered that the signal handler implementing the login timeout in Debian's version of the OpenSSH server uses functions which are not async-signal-safe, leading to a denial of service vulnerability.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/debian-openssh-packages-fix-denial-of-service.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Critical Red hat / Fedora Linux Openssh Security Update</title><link>http://www.cyberciti.biz/tips/red-hat-fedora-linux-servers-compromised.html</link> <comments>http://www.cyberciti.biz/tips/red-hat-fedora-linux-servers-compromised.html#comments</comments> <pubDate>Fri, 22 Aug 2008 16:08:38 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[CentOS]]></category> <category><![CDATA[fedora linux]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[News]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[computer systems]]></category> <category><![CDATA[critical security]]></category> <category><![CDATA[CVE-2007-4752]]></category> <category><![CDATA[enterprise linux]]></category> <category><![CDATA[intruder]]></category> <category><![CDATA[intrusion]]></category> <category><![CDATA[openssh]]></category> <category><![CDATA[red hat enterprise]]></category> <category><![CDATA[red hat network]]></category> <category><![CDATA[security measures]]></category> <category><![CDATA[system login]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2766</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/redhatfedora-linux' title='See all Redhat/CentOS/Fedora Core related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/rhlogo.gif' border='0' /></a></div> Last week one or more of Red Hat's servers got cracked. Now, it has been revealed that both Fedora and Red Hat servers have been compromised. As a result Fedora is changing their package signing key. The intruder was able to sign a small number of OpenSSH packages relating only to Red Hat Enterprise Linux 4 (i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64 architecture only).  This update has been rated as having critical security impact.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/red-hat-fedora-linux-servers-compromised.html/feed</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>CentOS / Red Hat Enterprise Linux 5.2 Poor NFS Performance and Solution</title><link>http://www.cyberciti.biz/tips/centos-rhel-poor-nfs-write-performance.html</link> <comments>http://www.cyberciti.biz/tips/centos-rhel-poor-nfs-write-performance.html#comments</comments> <pubDate>Fri, 22 Aug 2008 09:41:58 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Apache]]></category> <category><![CDATA[CentOS]]></category> <category><![CDATA[data center]]></category> <category><![CDATA[File system]]></category> <category><![CDATA[High performance computing]]></category> <category><![CDATA[Howto]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[Networking]]></category> <category><![CDATA[package management]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[Storage]]></category> <category><![CDATA[Sys admin]]></category> <category><![CDATA[Troubleshooting]]></category> <category><![CDATA[Tuning]]></category> <category><![CDATA[bugs]]></category> <category><![CDATA[centos nfs]]></category> <category><![CDATA[CVE-2008-1294]]></category> <category><![CDATA[CVE-2008-2136]]></category> <category><![CDATA[CVE-2008-2812]]></category> <category><![CDATA[enterprise linux]]></category> <category><![CDATA[kernel packages]]></category> <category><![CDATA[linux nfs]]></category> <category><![CDATA[nfs server]]></category> <category><![CDATA[red hat enterprise]]></category> <category><![CDATA[redhat nfs]]></category> <category><![CDATA[rhel 5]]></category> <category><![CDATA[server performance]]></category> <category><![CDATA[update redhat kernel]]></category> <category><![CDATA[update rhel kernel]]></category> <category><![CDATA[web server]]></category> <category><![CDATA[yum command]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2759</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/troubleshooting' title='See all Troubleshooting related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/configure.png' border='0' /></a></div> A few days ago I noticed that NFS performance between a web server node and NFS server went down by 50%. NFS was optimized and the only thing was updated Red Hat kernel v5.2. I also noticed same trend on CentOS 5.2 64 bit edition.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/centos-rhel-poor-nfs-write-performance.html/feed</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Postfix Mail Server Security Update [moderate security impact]</title><link>http://www.cyberciti.biz/tips/postfix-mail-server-security-update-moderate-security-impact.html</link> <comments>http://www.cyberciti.biz/tips/postfix-mail-server-security-update-moderate-security-impact.html#comments</comments> <pubDate>Mon, 18 Aug 2008 22:10:28 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Linux]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[Mail server]]></category> <category><![CDATA[package management]]></category> <category><![CDATA[Postfix]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[arbitrary files]]></category> <category><![CDATA[centos 5]]></category> <category><![CDATA[centos linux]]></category> <category><![CDATA[internal database]]></category> <category><![CDATA[security vulnerabilities]]></category> <category><![CDATA[server security]]></category> <category><![CDATA[ubuntu]]></category> <category><![CDATA[up2date]]></category> <category><![CDATA[yum]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2703</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/postfix' title='See all Postfix Mail Server related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/postfix-logo.gif' border='0' /></a></div> Postfix MTA updated to fix security vulnerabilities such as incorrectly checks the ownership of a mailbox. In some configurations, this allows for appending data to arbitrary files as root. This update has been rated as having moderate security impact.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/postfix-mail-server-security-update-moderate-security-impact.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>dnsmasq Dns Cache Software Security Update To Fix DNS Spoofing Attacks</title><link>http://www.cyberciti.biz/tips/linux-update-dnsmasq-dnscache-software.html</link> <comments>http://www.cyberciti.biz/tips/linux-update-dnsmasq-dnscache-software.html#comments</comments> <pubDate>Tue, 12 Aug 2008 06:55:27 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[BIND Dns]]></category> <category><![CDATA[CentOS]]></category> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[fedora linux]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[package management]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[apt-get command]]></category> <category><![CDATA[cache server]]></category> <category><![CDATA[cache software]]></category> <category><![CDATA[caching software]]></category> <category><![CDATA[centos linux]]></category> <category><![CDATA[CVE-2008-1447]]></category> <category><![CDATA[dns cache]]></category> <category><![CDATA[dnsmasq]]></category> <category><![CDATA[rhel 5]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[software security]]></category> <category><![CDATA[yum command]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2650</guid> <description><![CDATA[<div
style='float:right;margin-top:0px;margin-left:5px;'><a
href='http://www.cyberciti.biz/tips/category/redhatfedora-linux' title='See all Redhat/CentOS/Fedora Core related tips/articles'><img
src='http://files.cyberciti.biz/cbzcache/3rdparty/rhlogo.gif' border='0' /></a></div> Red Hat has shipped a new version of its dnsmasq caching  software to plug source UDP port bug. This could have made DNS spoofing attacks (CVE-2008-1447) easier. Dnsmasq is lightweight <a
href="http://www.cyberciti.biz/faq/caching-dns-server/">ultra fast dns cache server</a> forwarder and DHCP server. It is designed to provide DNS and, optionally, DHCP, to a small network. ]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/linux-update-dnsmasq-dnscache-software.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Download Of The Day: Firefox 3.0.1 (Critical Security Update)</title><link>http://www.cyberciti.biz/tips/download-firefox-301-critical-security-update.html</link> <comments>http://www.cyberciti.biz/tips/download-firefox-301-critical-security-update.html#comments</comments> <pubDate>Fri, 18 Jul 2008 10:36:05 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[CentOS]]></category> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[Download of the day]]></category> <category><![CDATA[GNU/Open source]]></category> <category><![CDATA[Linux desktop]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[package management]]></category> <category><![CDATA[RedHat/Fedora Linux]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[UNIX]]></category> <category><![CDATA[arbitrary code]]></category> <category><![CDATA[critical security]]></category> <category><![CDATA[CVE-2008-2785]]></category> <category><![CDATA[CVE-2008-2933]]></category> <category><![CDATA[CVE-2008-3198]]></category> <category><![CDATA[download]]></category> <category><![CDATA[download firefox 3]]></category> <category><![CDATA[firefox 3]]></category> <category><![CDATA[firefox 3.0]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[malformed url]]></category> <category><![CDATA[malicious content]]></category> <category><![CDATA[malicious web]]></category> <category><![CDATA[Mozilla]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Ubuntu Linux]]></category> <category><![CDATA[Update]]></category> <category><![CDATA[web content]]></category> <category><![CDATA[yum]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2478</guid> <description><![CDATA[Firefox 3.0.1 has been released and available for download. This update has been rated as having critical security impact by the Mozilla. Use the following instructions to upgrade Firefox.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/download-firefox-301-critical-security-update.html/feed</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Ubuntu Linux Critical Kernel Vulnerabilities Fix Available</title><link>http://www.cyberciti.biz/tips/ubuntu-linux-kernel-vulnerabilities-2.html</link> <comments>http://www.cyberciti.biz/tips/ubuntu-linux-kernel-vulnerabilities-2.html#comments</comments> <pubDate>Wed, 16 Jul 2008 07:58:42 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[GNU/Open source]]></category> <category><![CDATA[Howto]]></category> <category><![CDATA[kernel]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Linux desktop]]></category> <category><![CDATA[Linux distribution]]></category> <category><![CDATA[package management]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[Ubuntu Linux]]></category> <category><![CDATA[arbitrary code]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[available memory]]></category> <category><![CDATA[canonical ltd]]></category> <category><![CDATA[CVE-2007-6282]]></category> <category><![CDATA[CVE-2007-6712]]></category> <category><![CDATA[CVE-2008-0598]]></category> <category><![CDATA[CVE-2008-1615]]></category> <category><![CDATA[CVE-2008-1673]]></category> <category><![CDATA[CVE-2008-2136]]></category> <category><![CDATA[CVE-2008-2137]]></category> <category><![CDATA[CVE-2008-2148]]></category> <category><![CDATA[CVE-2008-2358]]></category> <category><![CDATA[CVE-2008-2365]]></category> <category><![CDATA[CVE-2008-2729]]></category> <category><![CDATA[CVE-2008-2750]]></category> <category><![CDATA[CVE-2008-2826]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[destination addresses]]></category> <category><![CDATA[emulation]]></category> <category><![CDATA[kernel memory]]></category> <category><![CDATA[kernel package]]></category> <category><![CDATA[open terminal]]></category> <category><![CDATA[protocol stack]]></category> <category><![CDATA[ptrace]]></category> <category><![CDATA[security holes]]></category> <category><![CDATA[security issue]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2467</guid> <description><![CDATA[Canonical Ltd has issued updates for its Kernel package to plug multiple security holes. A security issue affects all Ubuntu Linux versions.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/ubuntu-linux-kernel-vulnerabilities-2.html/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Debian Linux Security Update: Lighttpd DoS and Gaim Package Remote Security Issues</title><link>http://www.cyberciti.biz/tips/debian-linux-security-lighttpd-dos-gaim-package-2.html</link> <comments>http://www.cyberciti.biz/tips/debian-linux-security-lighttpd-dos-gaim-package-2.html#comments</comments> <pubDate>Tue, 15 Jul 2008 18:19:58 +0000</pubDate> <dc:creator>nixCraft</dc:creator> <category><![CDATA[Debian Linux]]></category> <category><![CDATA[GNU/Open source]]></category> <category><![CDATA[lighttpd]]></category> <category><![CDATA[package management]]></category> <category><![CDATA[Security Alert]]></category> <category><![CDATA[arbitrary code]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[attackers]]></category> <category><![CDATA[CVE-2007-3948]]></category> <category><![CDATA[CVE-2008-0983]]></category> <category><![CDATA[CVE-2008-2927]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[internal database]]></category> <category><![CDATA[linux security]]></category> <category><![CDATA[memory footprint]]></category> <category><![CDATA[minimal memory]]></category> <category><![CDATA[msn protocol]]></category> <category><![CDATA[overflows]]></category> <category><![CDATA[protocol handlers]]></category> <category><![CDATA[security issues]]></category> <category><![CDATA[vulnerabilities]]></category> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=2463</guid> <description><![CDATA[Debian Linux project released today bug fixes for lighttpd and gaim package that allows remote attacks and DoS attacks.]]></description> <wfw:commentRss>http://www.cyberciti.biz/tips/debian-linux-security-lighttpd-dos-gaim-package-2.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>