Server Security

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Server Security News

Database Security Proxies

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The last database activity monitoring (DAM) model I want to address is the proxy model. This is the final installment of my trends series, following the business activity monitoring, ADMP and the policy driven security model.

Whose Job Is Virtualization Security?

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

As network boundaries blur and longstanding design paradigms fall by the wayside, how do we assign accountability for security? It's a pressing question: Because virtualization gives us so much power and flexibility, we're moving ahead at a breakneck pace, often without looking closely at whether security-assurance levels remain as the services delivery model morphs.

Storing passwords in uncrackable form

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

News about intrusions into the servers of online stores, games vendors and other internet services can now be read on an almost daily basis. Often, the intruders obtain customers' login data including their passwords. As many people use the same password in multiple places, criminals can use the passwords to obtain unauthorised access to further services.

Is Linux Really More Secure than Windows?

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Common wisdom has held for years that Linux is superior to Windows when it comes to security issues. But now that open source is growing in popularity both on the consumer side (think Android phones) and the enterprise side (Linux runs the 10 fastest supercomputers in the world, for example, according to Wikipedia), it's time to push past the adage and look again at the whole "which is safer" issue.

The Linux vs. Windows Security Mystery

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

"NSA recommending Vista for home security is merely a reflection of the reality of monopoly in the retail space," said blogger Robert Pogson. "In the USA probably as few as 2 to 3 percent of users use GNU/Linux, so a recommendation is almost useless." Those who are serious about security "are already aware of SELinux, a product of the NSA. The NSA is merely recommending that folks move on from XP, a poor OS poorly supported by M$."

Security Tips For Virtualization

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Here you are, adding yet another server to your virtualized environment that went from beta to production in the data center equivalent of zero to 60 in 4.5 seconds. That speed means the security policies and processes you routinely applied to physical servers probably went out the window over the past few years.

8 Security Tips from the HBGary Hack

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Thanks to Ars Technica and H-online.com, we now have intimate details of the Anonymous attack against security research company HBGary. There are no surprises in how the attacks where carried out, but we can draw many morals from the story, even if we've heard them time and time before.