Server Security - Page 49
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.
We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.
Here's an article that talks about keeping your site safe. It is a discussion of some commercial security products, some of which run on Linux. "Still, there's a more insidious threat that such technologies don't guard against: actions . . .
"Establishing a Web presence can be crucial to a company's success, but the wrong moves can tarnish your image." This article "... gives tips on how to safely develop and deploy websites and how a comprehensive information technology policy . . .
A pair of House lawmakers on Wednesday introduced legislation that would exempt private companies from liability for sharing information with the federal government and each other on ways to beef up computer security. . . .
This new version of bind (not for production use yet) includes support for IPv6, many security improvements, protocol and operational improvements and especially support for DNSSEC. The quicklist of security improvements include: Support for DNSSEC, Support for TSIG, Auditability . . .
The provider of the Sendmail Internet Mail platform, which drives most of the Internet's mail servers, last week debuted the Sendmail Secure Switch, routing software that provides server-level encryption for E-mail transmissions. The software automatically encrypts the Simple Mail Transfer . . .
Updated. This is an analysis of the "Shaft" distributed denial of service (DDoS) tool. Denial of service is a technique to deny access to a resource by overloading it, such as packet flooding in the network context. Denial of service . . .
A company that makes popular software to block children from Internet pornography is suing two computer experts for distributing a method for children to deduce their parents' password and access those forbidden Web sites. . . .
System backups are the oft-forgotten step of system security. This Linux Journal article discusses using your CD-RW drive to make a backup of your system. . . .
Secure Switch provides state of the art server-to-server encryption technology so businesses can now safely use the Internet for transmitting sensitive information to partners, suppliers and employees. By automatically encrypting the SMTP connection between trusted servers, end users are freed . . .
Trustix Secure Linux is developed specifically for server applications such as e-business servers, web servers, mail servers, DNS servers and Internet access servers, with demand for the highest security and reliability. . . .
The general link above points to the new features in "the most powerful open source sendmail release ever". This link talks about the new general security features, and this one talks about the new anti-spam features. . . .
"In a move to shore up security, the Department of Defense (DOD) will require that by July 1, 2002, DOD agencies buy only information assurance products that have been evaluated by accredited national laboratories, according to a directive issued this . . .
This article shows how a web-server behind a firewall can be accessed without compromising security. It discusses configuring the Apache ProxyPass option to allow external hosts to an internal network. . . .
Microsoft has been unable to douse allegations that one of the hotly anticipated technologies in Windows 2000 Server has a security hole. "If this had been a legitimate security bug, Microsoft would have admitted that," said Peter Houston, Microsoft's group . . .
Part 1 of this LJ series discusses "backup strategies, tools, and ways to make the whole process a bit less unpleasant." [Found on linuxtoday] . . .
"Somebody's going to get sued; that's clear," said David J. Loundy, of Chicago's D'Ancona & Pflaum LLC. "Somebody's going to want a test case. The issue [is] whether there's going to be one or two of these suits, or whether . . .
The Apache Software Foundation and The Apache Server Project are pleased to announce the release of version 1.3.12 of the Apache HTTP server. The primary changes in this version of Apache are those related to the ``cross site scripting'' . . .
Here's a pretty well-written introduction to utilizing the access control mechanisms built into Apache. This includes the Apache security modules, controlling access by IP and username, using htaccess/htpasswd, among others. . . .
John Viega posted the following message to bugtraq announcing a new security auditing tool. "I've put together a command-line tool for statically scanning C and C++ source code for security vulnerabilities. The tool is . . .
The E-Commerce Times writes, "The rash of hacker attacks against Web sites continued this week, directed mainly against e-commerce sites, and the FBI reportedly is now investigating a total of 17 distributed denial-of-service (DDoS) intrusions." . . .