LinuxSecurity.com - Latest NewsThe central voice for Linux and Open Source security news.Openwall-Announce: John the Ripper Pro 1.7.3+ for Linux- July 18, 2008 LinuxSecurity.com: This is likely the last announcement posting for today, and maybe for this month. It is to announce availability of John the Ripper 1.7.3 Pro for Linux (stable release) and 1.7.3.1 Pro for Mac OS X (currently in public beta).I'd like to thank Alain Espinosa for the optimized NTLM code, and for kindly placing it in the public domain. This release of JtR Pro includes Alain's code with slight modifications, as well as replacement code for the password file loader; I am going..http://www.linuxsecurity.com/content/view/140046?rdf Openwall-Announce: Mod_auth_mysql with Support for phpass- July 18, 2008 LinuxSecurity.com: This is to announce several assorted items at once. I intend to post another announcement shortly, focusing on new JtR releases, so I have left those out of this one. A patched version of mod_auth_mysql with support for our PHP password hashing framework's (phpass) portable hashes has been added to the contributed resources list on the phpass homepage: http:www.openwall.comphpass Do you use mod_auth_mysql The openwall project released a interesting patch that adds support..http://www.linuxsecurity.com/content/view/140045?rdf Security Bugs and Full Disclosure- July 17, 2008 LinuxSecurity.com: In an announcement for the 2.6.25.10 stable kernel, Greg KH noted, "it contains a number of assorted bugfixes all over the tree. And once again, any users of the 2.6.25 kernel series are STRONGLY encouraged to upgrade to this release." The emphasis on the word strongly led to a lengthy discussion about how security fixes are handled in the Linux Kernel. Linus Torvalds replied, "I personally consider security bugs to be just 'normal bugs'. I don't cover them up, but I also...http://www.linuxsecurity.com/content/view/139940?rdf Principle of Least Privilege Prevails, Says Red Hat Security Expert- July 16, 2008 LinuxSecurity.com: Linux security may seem daunting, but there are a host of best practices to simplify the maze. Recently, Steve Grubb of Red Hat Inc. outlined some important security principles, including minimizing admin access, the increasing sophistication of SELinux and the importance of auditing systems. Like many when I think about least privileges, I think about SELinux. What do you think about This article is a interview with a Red Hat expert that answers questions about SELinux and.http://www.linuxsecurity.com/content/view/139931?rdf Lynis - Security & System Auditing Tool for UNIXLinux- July 16, 2008 LinuxSecurity.com: Lynis is an auditing tool for Unix (specialists). It scans the system and available software, to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes.This is a tool that might be useful for both penetration testers performing white box tests and system admins trying to secure their own systems. Have you ever heard about the Linux security program called Lynis. This was the.http://www.linuxsecurity.com/content/view/139930?rdf Fedora's FreeIPA Offers Identity, Security Services- July 15, 2008 LinuxSecurity.com: Fedora 9, released last month, included the first release of FreeIPA, a new freeopen source project that comes out of Red Hat with the goal of becoming a complete and integrated security information management solution. In this article we take a look at exactly what FreeIPA is, both what it can do now and what its developers hope it will be capable of in the future. It seems destined to become a key feature of Red Hat Enterprise Linux 6, and with Fedora 9 released and...http://www.linuxsecurity.com/content/view/139778?rdf |