[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

Opioids More Likely To Kill Than Car Crashes Or Suicide

The association between COVID-19 “vaccines” and cognitive decline

Democrats Sink to Near Zero in New Gallup Poll, Theyre Just Not Satisfied

She Couldn't Read Her Own Diploma: Why Public Schools Pass Students but Fail Society

Peter Schiff: Gold To $6,000 Next Year, Dollar Index To 70

Russia Just Admitted Exactly What Everyone – But Trump – Already Knew About Putin's Ukraine Plans

Sex Offenses in London by Nationality

Greater Israel Collapses: Iran the Next Target

Before Jeffrey Epstein: The FINDERS

Cyprus: The Israeli Flood Has Become A Deluge

Israel Actually Slaughtered Their Own People On Oct 7th Says Israeli Newspaper w/ Max Blumenthal

UK Council Offers Emotional Support To Staff "Discomforted" By Seeing The National Flag

Inside the Underground City Where 700 Trucks Come and Go Every Day

Fentanyl Involved In 70% Of US Drug Overdose Deaths

Iran's New Missiles. Short Version

Obama Can't Bear This. Kash Patel Exposes Dead Chef Revelation. Obama’s Legacy DESTROYED!

Triple-Digit Silver Imminent? Critical Mineral, Backwardation & Remonetization | Mike Maloney

Israel Sees Sykes-Picot Borders As 'Meaningless' & 'Will Go Where They Want': Trump Envoy

Bring Back Asylums: It's Time To Talk About Transgender Fatigue In America

German Political Parties (Ex-AfD) Sign 'Fairness Pact' That Prevents Criticizing Immigration

CARVING .45 CALIBER AUTOMATICS OUT OF STEEL WWII UNION SWITCH AND SIGNAL MOVIE

This surprising diabetes link could protect your brain

Putin and Xi to lay foundations for a new world order in Beijing

Cancer Natural Solutions Q&R

Is ANYONE buying this anymore? (Netanyahu)

Mt Etna in Sicily Eupting

These Soviet 4x4 Sedans Are Cooler Than You Think!

SSRIs and School Shootings, FDA Corruption, and Why Everyone on Anti-Depressants Is Totally Unhappy

St. Louis Man Who Gunned Down Police Officer Demond Taylor Is Released on $5,000 Bond

How Israeli spy veterans are shaping US big tech


Science/Tech
See other Science/Tech Articles

Title: Linux vulnerability leaves top sites wide open to attackers
Source: [None]
URL Source: https://www.rt.com/usa/355558-linux-vulnerability-websites-attacks/
Published: Aug 12, 2016
Author: © Beck Diefenbach / Reuters
Post Date: 2016-08-12 02:50:46 by Tatarewicz
Keywords: None
Views: 1524
Comments: 1

RT... A flaw in the Linux operating system lets hackers inject malware into downloads and expose the identities of people using anonymizing software such as Tor – even for those who aren’t using Linux directly.

In a Wednesday presentation at the USENIX Security Symposium in Austin, Texas, researchers with the University of California, Riverside showed that the flaw lies in the Transmission Control Protocol (TCP) used by Linux since late 2012.

READ MORE: US officials covered up China hack of FDIC computers – House report

The networking blunder is present in the Linux kernel, the core of its operating system, and can be exploited by malicious actors to determine whether two systems are communicating with each other, and even inject malicious data into or break their connection.

At the symposium, the researchers demonstrated the exploit by injecting code into a live USA Today page that asks visitors to enter their emails and passwords, which was possible because pages on USA Today aren’t encrypted.

Perhaps most importantly, the intercepting of data doesn’t require a man-in-the-middle attack, where a connection will covertly intercept, collect and pass forward information between two parties. Instead, attackers can just send packets of data to the two targets with spoofed credentials.

“Through extensive experimentation, we demonstrate that the attack is extremely effective and reliable. Given any two arbitrary hosts, it takes only 10 seconds to successfully infer whether they are communicating,” the team wrote in a white paper. “If there is a connection, subsequently, it takes also only tens of seconds to infer the TCP sequence numbers used on the connection. To demonstrate the impact, we perform case studies on a wide range of applications.”

Linux flaw puts millions of PCs, Android smart devices at riskt.co/AiOHutMjfYpic.twitter.com/8Zv92p9OYD — RT America (@RT_America) January 20, 2016

Because Linux runs in the backend on a majority of servers as well as on Android devices, an enormous number of users might be left vulnerable. Even those using the much-vaunted anonymizing software Tor could have their privacy compromised 90 percent of the time in an average time of about 50 seconds.

"In general, we believe that a [denial-of-service or] DoS attack against Tor connections can have a devastating impact on both the availability of the service as a whole and the privacy guarantees that it can provide," the researchers said.

The team notes that because only version 3.6 or later of the Linux kernel has the flaw, systems running older software are not affected. They distributed a patch to fix the vulnerability, but they note a large number of individuals and networks will still be left exposed to miscreants, since the exploit only requires one unpatched party for the attack to work.

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: Tatarewicz (#0)

I won't say this makes me feel great about never having switched to Linux, but it makes me feel kinda great about it....... How vicious people are.

This is just a case of human error, right -- they're not saying anybody's sabotaging the program?

_____________________________________________________________

“We build but to tear down. Most of our work and resource is squandered. Our onward march is marked by devastation. Everywhere there is an appalling loss of time, effort and life. A cheerless view, but true.” - Tesla per FP

NeoconsNailed  posted on  2016-08-12   6:25:56 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]