White Papers

Cleartext Passwords in Linux Memory

Overview Upon examination, the memory of a popular Linux distribution contained many cleartext passwords, including login, SSH, Truecrypt, email, IM and root passwords. These passwords are retained by running applications and stored as plain text in memory for extended periods of time. The paper investigated the source of these passwords and presents a proof-of-concept method for recovering passwords from memory. The cold boot researchers demonstrated that memory is not as volatile as commonly expected, and that data from memory can be recovered with physical access to systems in a very short period of time. This has opened up a new class of attacks in physical IT security, and significantly raised the risk associated with cleartext passwords in memory.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
Philosecurity.org
File Format
PDF
Date Published
Feb 18, 2009
Format
White Papers
Topics
Linux - Open Source, Security Management

Similiar White Papers

Protection for Mac and Linux Computers: genuine need or nice to have?

Protection for Mac and Linux Computers: genuine need or nice to have?

The current risk to computers running non-Windows platforms is small but growing. As Macs and Linux computers become mor

Publisher: Sophos  |  Tags: computers, hackers, linux, mac, mac os, network, os

IBM Proventia Server Intrusion Prevention System for Linux

IBM Proventia Server Intrusion Prevention System for Linux

IBM Proventia Server Intrusion Prevention System (IPS) for Linux software supports compliance regulations that require s

Publisher: IBM  |  Tags: applications, data, data loss, dlp, downtime, ips, linux, real-time, server, software

How Dell Streamlined Authentication and Identity Management Using Quest's Vintela Authentication Services

How Dell Streamlined Authentication and Identity Management Using Quest's Vintela Authentication Services

Dell wanted to integrate authentication and identity management for Microsoft Windows, UNIX, and Linux platforms into Mi

Publisher: Dell  |  Tags: active directory, authentication, infrastructure, linux, management, microsoft windows

Using SELinux on an ICE-Linux CMS

Using SELinux on an ICE-Linux CMS

This white paper is intended for IT professionals interested in using ICE-Linux with Security-Enhanced Linux (SELinux) e

Publisher: Hewlett-Packard (HP)  |  Tags: cms, linux

Confining the Apache Web Server With Security-Enhanced Linux

Confining the Apache Web Server With Security-Enhanced Linux

Restricting the access of a web server to system resources limits the potential damage caused to those resources through

Publisher: MITRE  |  Tags: linux, server