- Mastering Linux Security and Hardening
- Donald A. Tevault
- 235字
- 2021-07-02 19:19:17
The threat landscape
If you've kept up with IT technology news over the past few years, you'll likely have seen at least a few articles about how attackers have compromised Linux servers. For example, while it's true that Linux isn't really susceptible to virus infections, there have been several cases where attackers have planted other types of malware on Linux servers. These cases have included:
- Botnet malware: It causes a server to join a botnet that is controlled by a remote attacker. One of the more famous cases involved joining Linux servers to a botnet that launched denial-of-service attacks against other networks.
- Ransomware: It is designed to encrypt user data until the server owner pays a ransom fee. But, even after paying the fee, there's no guarantee that the data can be recovered.
- Cryptocoin mining software: It causes the CPUs of the server on which it's planted to work extra hard and consume more energy. Cryptocoins that get mined go to the accounts of the attackers who planted the software.
And, of course, there have been plenty of breaches that don't involve malware, such as where attackers have found a way to steal user credentials, credit card data, or other sensitive information.
Some security breaches come about because of plain carelessness. Here's an example of where a careless Adobe administrator placed the company's private security key on a public security blog: https://www.theinquirer.net/inquirer/news/3018010/adobe-stupidly-posts-private-pgp-key-on-its-security-blog.
- INSTANT Netcat Starter
- API安全實(shí)戰(zhàn)
- Kali Linux Wireless Penetration Testing Cookbook
- Applied Network Security
- CTF競賽權(quán)威指南(Pwn篇)
- 物聯(lián)網(wǎng)安全滲透測試技術(shù)
- 電腦安全與攻防入門很輕松(實(shí)戰(zhàn)超值版)
- 無線傳感器網(wǎng)絡(luò)安全與加權(quán)復(fù)雜網(wǎng)絡(luò)抗毀性建模分析
- 構(gòu)建新型網(wǎng)絡(luò)形態(tài)下的網(wǎng)絡(luò)空間安全體系
- Android Application Security Essentials
- 聯(lián)邦學(xué)習(xí)原理與算法
- 黑客攻防與電腦安全從新手到高手(超值版)
- Hands-On Bug Hunting for Penetration Testers
- 網(wǎng)絡(luò)空間安全實(shí)踐能力分級培養(yǎng)(I)
- 數(shù)據(jù)安全實(shí)踐:能力體系、產(chǎn)品實(shí)現(xiàn)與解決方案