February 13th, 2003 -
IBM announces commitment to Common Criteria Security Certification of Linux across eServer
IBM today announced that it will work with the Linux community to enter the
Common Criteria certification process for the Linux operating system early
this year and proceed with a progressive plan for certifying Linux at
increasing security levels through 2003 and 2004.
[Read the Full Story]
February 4th, 2003 -
Net firms face constant attack
A report produced by Symantec, Inc. shows that, on average, every
net-connected company is being attacked 30 times per week. Read how Guardian Digital can protect your company
from the constant onslaught of Internet attacks.
[Read the Full Story]
January 6th, 2003 -
Net users want law to can spam
Rising angst over junk e-mail has the majority of the Internet
population in favor of outlawing it, a new study shows. Ask how Guardian
Digital and EnGarde can improve productivity and eliminate Internet
threats including spam.
[Read the Full Story]
January 4th, 2003 -
Jabber 1.4.2 Now Available for EnGarde
The latest version of the XML-based, open-source system and protocol for
real-time messaging and presence notification is now available. Build
your own AOL Instant Messager server using EnGarde.
[Package Information]
[Download Package]
November 19th, 2002 -
Spam headaches bring more pain
In the days before Christmas the amount of spam e-mail being sent and
received looks set to soar as marketing machines and e-greetings firms
go into seasonal overdrive.
[Read the Full Story]
November 19th, 2002 -
Open-Source Security Is Opening Eyes
Wreski says Guardian Digital turned profitable eight months ago and is
growing by 10% each quarter, much faster than the low single-digit
growth for the overall security sector, according to tech consultancy
Gartner. "I think there was some apprehension about [the software] being
free. But that has changed," says [Guardian Digital CEO] Wreski...
[Read the Full Story]
November 14th, 2002 -
Patch Availability for BIND Flaws in Question
Patches exist for three potentially devastating vulnerabilities in the
most commonly used Domain Name Server (DNS) software, Berkeley Internet
Name Domain (BIND). However, security lists are humming with postings
from BIND users who have been unable to get the patches for their
systems. EnGarde users were among the first protected.
[Read the Full Story]
[Download Advisories]
November 12th, 2002 -
Hackers could be planning major attack, says White House
A new computer worm infecting a popular World Wide Web technology is
proof that computer hackers have grown more sophisticated and could be
preparing a significant attack, according to a senior White House
official. What is your vendor doing to protect you?
[Read the Full Story]
September 25th, 2002 -
Open Source: A False Sense of Security?
Guardian Digital Inc., of Allendale, N.J., recently released EnGarde Secure Linux Professional, which features a litany of added
security functionality, such as a network gateway firewall, a network IDS (intrusion detection system) and a host IDS, and a security
control center.
[Read the Full Story]
September 25th, 2002 -
New Linux OS billed as secure and user friendly
EnGarde jettisons elements of traditional Linux versions that were a frequent source of security vulnerabilities. For example,
the company does not distribute SNMP (Simple Network Management Protocol) with EnGarde, opting for its own management protocol and does
not
distribute a Telnet client with EnGarde because of its frequent role as a vehicle for carrying out attacks on remote systems.
[Read the Full Story]
September 25th, 2002 -
Guardian digital ships Linux OS
"Our entire goal was to abstract the process of security because it was so difficult, you couldn't expect the average Linux
administrator to have the level of understanding to keep their server secure and also run his or her business. Instead, [Guardian] took
on the responsibility of keeping the environment secure," said Guardian Ditigal CEO Dave Wreski.
EnGarde consolidates management functions in a graphical Web interface called the "Guardian Web Tool" that administrators can use to
manage DNS (Domain Name System), e-mail, and database services, in addition to security features such as public keys, SSL (Secure
Sockets Layer) and SSH (Secure Shell) certificates.
[Read the Full Story]
September 24th, 2002 -
Start-up banks on hack-proof Linux
Start-up Guardian Digital has launched an effort to sell a version of Linux that's less vulnerable to attack, a niche the company hopes
will gain it a foothold in the market for the Unix-like operating system.
[Read the Full Story]
September 24th, 2002 - Guardian Digital Launches EnGarde to Provide Enterprises with Linux Security Solutions
Guardian Digital, Inc., the leading open source security company, has today formerly launched the EnGarde Secure Linux server operating system, EnGarde Secure Professional. EnGarde Secure Professional is a comprehensive enterprise software solution that provides all the tools necessary to build a complete, secure online presence. This provides organizations with a cost-effective and proven platform capable of supporting thousands of Web sites and e-mail domains. Designed with security and ease of management as its primary focus, EnGarde Secure Professional allows organizations to increase productivity while reducing support and infrastructure costs.
[Read the Full Release]
August 30th, 2002 -
Spam hits 36 percent of e-mail traffic
Corporate networks are becoming increasingly clogged by e-mail pitches
for pornography, money-making schemes and health products, and there's
little relief on the horizon.
[Read the Full Story]
August 13th, 2002 -
White-Hat Hate Crimes on the Rise
The Black-hat hackers are playing for keeps these days. Choose the
distribution that considers the security of your assets. "You've got to
realize that these people are walking around with exploits that vendors
haven't even heard of yet. They're pissed and they've got this almost
God-like power that enables them to break into any network that they
want," Hines said. He reported that FateLabs.com was knocked
offline last week by a denial-of-service attack immediately after the
security firm published an advisory about a security bug.
Why so much venom against white hats, the hackers who ostensibly break
software in order to help make the Internet safer? The el8 zines don't
clearly spell out the group's motivations, but Project Mayhem appears to
be a violent incarnation of the "anti-sec" movement, a campaign to
persuade hackers not to publish information about the security bugs they
uncover.
[Read the Full Story]
July 30th, 2002 -
Customers shun MS licensing plan
The majority of Microsoft's customers won't be signing up for a controversial licensing plan set to go into effect on Thursday,
according to analysts' estimates.
Signing onto the plan, which would commit business customers to a two- or three-year annually paid contract guaranteeing the right to
upgrade, will be the only way to continue buying Microsoft software at deep discounts.
The holdouts have until the end of their business day on Wednesday to sign up for the plan or risk paying full price the next time they
buy software from Microsoft. They won't get a reprieve, either. Microsoft has twice extended the deadline for the new program, but a
representative said Monday that there would be no more extensions.
[Read Full Story]
Learn how Guardian Digital can enable your organization with
license-free secure Internet connectivity software. "The majority of
Microsoft's customers won't be signing up for a controversial licensing
plan set to go into effect on Thursday, according to analysts' estimates."
[Want more info?]
July 15th, 2002 -
Gartner Study: CRM Demands Sound Customer Privacy Practices
What is your Linux vendor doing about your security? Customer
privacy best practices recently revealed by Gartner. "To leverage
customer relationship management insights effectively, respect customer
demands regarding the collection and use of personal information.
Failure to do so risks damaging your most precious asset -- customer trust."
[Read the full
report]
July 10th, 2002 -
Guardian Digital Combats Proprietary Software Licensing Deadline
Guardian Digital, Inc., the first full-service open source Internet server security company, has today announced a special incentive
program designed to provide companies with an alternative to Windows-based servers and applications as the July 31st deadline for
Microsoft's new licensing program approaches.
[Read
the full press release]
June 22nd, 2002 -
Beware of .Net sticker shock
Companies planning on moving their old programs to Microsoft's new .Net
software plan had better prepare for sticker shock: Making the
conversion could cost roughly half of the original development cost,
Gartner says.
[Read the full report]
June 17th, 2002 -
Guardian Digital offers new Secure Linux server OS
Writes Todd Weiss, ComputerWorld, "Instead of having system administrators go through the program and disable services,
as occurs with many server operating systems, all services are turned off in the default installation."
http://www.computerworld.com/softwaretopics/os/linux/story/0,10801,72073,00.html
June 10th, 2002 -
Guardian Digital Delivers Next Generation Enterprise Internet Server Solution
Guardian Digital, Inc., the open source security company, has today released the next generation of its highly successful EnGarde Secure
Linux server operating system. EnGarde Secure Professional Release v1.2 is a comprehensive enterprise software solution that provides
all of tools necessary to build a complete online presence.
http://www.guardiandigital.com/company/press/EnGarde-v1.2-Release.pdf
June 10th, 2002 -
EnGarde Secure Linux walks away with Editor's Choice
EnGarde walked away with our Editor's Choice award thanks to the depth of its security strategy, which covers nearly all the bases.
Everything from the low-level mechanisms (binary integrity checking and stack protection) to high-level usability issues (including an
excellent patching interface) demonstrate the serious effort the Guardian Digital crew has invested in EnGarde.
ESL's Guardian Digital Secure Network provides a textbook example of an ideal patching interface--automatic notification, simplified
downloading and straightforward descriptions are all included. We were up to current patch levels in a matter of minutes.
http://www.networkcomputing.com/1312/1312f32.html
June 6th, 2002 -
EnGarde Secure Linux Review Wins Perfect Score
Guardian Digital's Engarde Secure Linux Professional offers a lightweight, robust, and secure Linux Distribution for small and large
networks. This distribution is really great for small to large business. Ease of administration and added security means less man hours.
The home business user would appreciate its completeness, ease of use, and its low cost.
One feature I really liked was the web based administration. You can easily administer most of the system directly from this secure
interface.
As I said before Engarde Secure Linux is an extremely lightweight. Packaging a minimal amount of services accomplishes this. Most major
Linux distributions tend to bundle tons of junk you really don't need. That approach is great for the average user who wants to pick and
choose what they want to run but not too good for just a server. Those added services also tend to compromise security. Guardian Digital
has packaged only the services you need to get the job done. Also, instead of enabling every single service packaged Engarde makes you
turn on only those you wish to run.
http://www.linuxlookup.com/modules.php?op=modload&name=Reviews&file=index&req=showcontent&id=27
May 21st, 2002 -
MS licensing: Pay now or lose
Let Guardian Digital and EnGarde Secure Linux show you the way out of
the vicious Microsoft license circle. Learn how MS is cashing in early
and forcing you to pay now. Registered users of EnGarde Secure
Professional receive a free upgrade to the next version when its
released shortly!
"Market researcher Gartner on Tuesday again warned corporate technology
managers that they could pay more for their next Microsoft software
upgrades if they fail to sign up."
http://zdnet.com.com/2100-1104-919128.html
May 15th, 2002 -
Why hackers are a step ahead of the law
Does your organization have the resources necessary to provide the
assurance necessary to be on the Internet today, and maintain that
security? The six organizations outlined in this article, including
Western Union, apparently do not.
"Law enforcement officials say many online merchants may be partly to
blame for the lack of arrests because they do not devote enough
resources to prevent intrusion or facilitate investigations in the event
of a crime."
April 24th, 2002 -
Users Turn to Guardian Digital for Expertise
Responding to the rising demand for authoritative documentation on email configuration and security, resident Guardian
Digital network guru Pete O'Hara authored the most comprehensive and definitive guides on the Postfix mail server
program to date.
Exclaims Jared Raddigan in a post to the public EnGarde community, "I just read your entire
Postfix doc (Configuring Postfix) and I wanted
to
say good job. I actually have the only Postfix book that is currently out and I used both it and your HOWTO, and I found
your document was very competitive (on the comparable chapters) if not better. You have to admit it's a good sign when I
am using ESL HOWTO's for both my ESL box and other non ESL boxes."
Configuring Postfix - This document outlines running Postfix on EnGarde. Wietse Venema, author of Postfix and several other
staple
Internet security products, describes Postfix as an "attempt to provide an alternative to the widely-used Sendmail program. Postfix
attempts to be fast, easy to administer, and hopefully secure, while at the same time being sendmail compatible enough to not upset your
users."
http://www.linuxsecurity.com/feature_stories/feature_story-91.html
April 9th, 2002 -
Survey: Many Microsoft customers lack funds for new licensing
The study of 1,400 IT executives worldwide conducted by Information Technology Intelligence Corp. (ITIC) and Sunbelt
Software found that 41% of respondents said they did not have the funds to convert to Microsoft’s new License 6.0 volume
licensing plan by the July 31 deadline.
March 24th, 2002 - Which
Linux Vendor?
Is your Linux vendor
watching out for your best interests? Are they providing you with the
level of security and support you demand? At least one Linux vendor
has switched their focus to the largest of companies, dropping support
for others, according to this ZDNet
article
"Red Hat,
... has restructured to focus on big customers while cutting jobs elsewhere,
executives said Tuesday. Red Hat eliminated its network consulting group,
which the company acquired for $47 million in February 2001.
The company is paring
down to focus on selling its operating system products and services
to large corporate customers." There are many things to consider
when choosing the right Internet solution for your business. How many
servers do you have? If you don't have at least five, Red Hat won't
support you. Concerned about security? Then doesn't it make sense to
choose the one designed to withstand the hostile nature of the Internet?
Guardian Digital, primary sponsors of EnGarde Secure Linux, provides
support and services for organizations with one to one hundred servers.
March 14th, 2002
-
Significant Vulnerability Afflicts Linux Systems
The vulnerability
is rooted in the free() function and how it used. Quoting from the EnGarde
Secure Linux advisory, "The zlib shared library may attempt to free()
a memory region more then once, potentially yielding a system exploitable
by certain programs that use it for decompression. Because certain packages
include their own zlib implementation or statically link against the
system zlib, several packages need to be updated to properly fix this
bug."
March 4th, 2002 -
Latest
EnGarde Linux Updates: mod_ssl and mod_php
Ensuring
that your systems are updated is an integral part of maintaining a secure
Internet presence. Two security updates were released today for EnGarde,
one for PHP and another for mod_ssl.
mod_php
- There is a vulnerability in PHP's MIME data parsing code which may
allow an attacker to execute arbitrary code as the web server user.
Click
for Advisory
mod_ssl
- There is a buffer overflow in mod_ssl, part of EnGarde's apache package,
which an attacker may potentially trigger by sending a very long client
certificate. Click
for Advisory
February 20th, 2002
- Secure by Design
Proves Most Effective .
EnGarde implements the "Secure by Design" methodology, and this article
in CIO describes how it dramatically increases your ROI. "Security has
been an add-on at the last minute, and detecting security problems has
been left to users." And, of course, hackers.
Overall, the average company catches only a quarter of software security
holes. On average, enterprise software has seven significant bugs, four
of which the software designer might choose to fix. Armed with such
data, the researchers concluded that fixing those four defects during
the testing phase cost $24,000. Fixing the same defects after deployment
cost $160,000, nearly seven times as much.
The ROSI breakdown: Building security into software engineering at the
design stage nets a 21 percent ROSI. Waiting until the implementation
stage reduces that to 15 percent. At the testing stage, the ROSI falls
to 12 percent.
November 21st 2001
- Guardian Digital Signs Major
UK Distributor for Internet Software
Guardian Digital, Inc., the open source security company, has today
announced a key partnership with iTS-LiNUX, the premier Linux distributor
in the United Kingdom. Terms of the partnership include exclusive rights
to distribute Guardian Digital Internet server software, including EnGarde
Secure Professional.
November 19th 2001 - Guardian Digital Unveils Corporate
Support and Services
Guardian Digital, the first full-service Open Source Security company,
today unveiled Guardian Digital Secure Network, a central location for
receiving product information, support, and system software services.
November 19th 2001
- Guardian Digital Delivers Enterprise
Internet Server Solution .
Guardian Digital, Inc., the open source security company, has today
released the enterprise edition of its highly successfully EnGarde Secure
Linux server operating system. EnGarde Secure Professional is a comprehensive
software solution that provides all the tools necessary to build a complete
online presence.
November 4th 2001 - Time
to stop defending Microsoft security
Further
information on why open source leads to a more secure environment. Bruce
Schneier comments in this article why he thinks Microsoft wants a closed-door
policy on security vulnerability disclosure. "Security firms, [ScottCulp]
says, can just whisper the problems to Microsoft, which will promptly
patch the hole.
Bruce
Schneier, chief technology officer of Counterpane Internet Security,
says that won't happen. Microsoft has always treated security threats
as a public relations problem, so it would do anything it could not
to publicize its susceptibility, Schneier says. "Companies like
Microsoft would ignore security researchers who quietly informed them
of security vulnerabilities," he explains. "They would lie
to the public and say
that the vulnerabilities were 'theoretical only' or 'impractical.' "
October
4th 2001
- Survey:
MS licensing rankles customers.
Most corporate customers are unhappy with looming changes in Microsoft
software-licensing programs, and many would consider switching to competitors'
products, according to a survey released recently.
October
1st 2001
- Security industry set to Soar.
The worldwide information security services market will grow by more
than a quarter a year until 2005, reaching a value of $21bn (£14.3bn),
according to market research firm IDC.
September
24th 2001
- Gartner Group Recommends
Alternatives to Microsoft.
The
Gartner Group is recommending organizations using Microsoft's Web server
to replace it with more secure servers such as Apache. They continue
by saying that organizations can't always patch fast enough against
worms such as Nimda and other security vulnerabilities.
Gartner recommends that enterprises hit by both Code Red and Nimda immediately
investigate alternatives to IIS, including moving Web applications to
Web server software from other vendors, such as iPlanet and Apache.
August
23rd 2001
- EnGarde Secure Newswire
- Aug/Sept.
Welcome to the EnGarde Secure Newswire! This monthly newsletter contains
details on EnGarde development, usage tips, news & reviews pertaining
to EnGarde, and information on the latest software released by Guardian
Digital for EnGarde.
English:
http://www.engardelinux.org/docs/newswire-09-en.html
Español: [Cortesía de Nispernet.com]
http://www.engardelinux.org/docs/newswire-09-es.html
Portuges do Brasil: [ Courtesia da www.linuxsecurity.com.br
]
http://www.engardelinux.org/docs/newswire-09-pg.html
August
23rd 2001
-
No slump for security biz!.
"
Open Source is proving to be a valuable alternative to proprietary security
solution for companies trying to avoid the current economic belt-tightening
experienced by many.
By 2005, IDC predicts the Internet security market will tally more than
$14 billion a year in revenue, up from $5.1 billion last year.
"For security software
vendors, the current economic instability is a double-edged sword,"
Brian Burke, senior research analyst at IDC, said in a statement.
"On the one hand,
it's forcing companies to reduce spending. On the other hand, it's forcing
companies to look for ways to cut costs, become more security-proficient
and build trusted relationships with customers, partners, suppliers,
and channels--which are areas security software can help."
The report breaks the Internet security industry into four markets:
firewalls, encryption, antivirus and the AAA (authentication, authorization
and administration) market, each of which is expected to grow 23 percent
per year, on average. The AAA market will lead the way, said the report,
growing annually by 28 percent on average to amass $9.5 billion in revenue
in 2005. "
August
11th 2001
- EnGardeLinux.com
Named Site of the Week! .
"
PacketStorm Security named EnGardeLinux.com, the Official Site for the
Engarde Secure Linux distribution, "Site of The Week". PacketStorm Security
is known as one of the largest and highly regarded security sites on
the Internet, offering the latest security exploits, articles and tools.
We would like to thank our friends at PacketStorm for the prestigious
honor.
EnGarde is a secure distribution of Linux engineered from the ground-up
to provide organizations with the level of security required to create
a corporate Web presence or even conduct e-business on the Web. It can
be used as a Web, DNS, e-mail, database, e-commerce, and general Internet
server where security is a primary concern. "
July
16th 2001
- Guardian Digital Announces
Corporate Partnership Program
"The
Guardian Digital Partnership Program provides cost-effective tools to
participating vendors for profitably deploying secure network solutions
utilizing EnGarde Secure Linux and the Guardian Digital Linux Lockbox
secure turnkey server appliance."
July 16th 2001
- The
Duke of URL reviews Engarde Secure Linux
"The
security security features are intrusion detection (what system doesn't
need this?), extensive system logging, and security policy enforcement.
The intrusion detection is fine-grained and easy to setup. If a service
is accessed by unauthorized means the administrator is notified immediately.
Logging can be configured to be general or specific and is event-based.
You can also configure your logs to be stored on the server in one,
or several, locations on the network. Security policies such as password
length and password expiration are easily enforced and automated. It's
just a matter of clicking a few options and things are completely set
up. You can also restrict the commands that a user may access. "
July 12th 2001
- EnGarde
Newsletter!
"Welcome to the first issue of the EnGarde Secure NewsBrief. This
monthly newsletter contains details on EnGarde development, usage tips,
news & reviews pertaining to EnGarde, and information on the latest
software released by Guardian Digital for EnGarde."
July
10th 2001 - Join our Official Mirrors
Group! We're curretly
accepting requests for access to our official rsync server.
July 5th 2001 -
EnGarde
FAQ
"What is EnGarde
Secure Linux? Who is Guardian Digital, Inc? How do I install EnGarde?
Is there a supported version available? What does EnGarde provide to
ensure security? Why did we design it? What platform does it run on?
How do you set up a secure Web server using it? How do I use the intrusion
detection? What is the license for Guardian Digital EnGarde Secure Linux?"
June 2001 - UnixReview.com
Rave review for EnGarde in the June 2001 issue!
The EnGarde
Linux distribution is probably the most secure Linux distribution I've
seen. EnGarde enforces physical, host, and network security to protect
your machine from attacks inside and out. In addition to tightening security
policies and adding features like a LILO password to prevent someone with
physical access getting root, EnGarde also includes intrusion detection
to alert you to break-in attempts. Some distributions I've looked at seem
to concentrate too heavily on one aspect of security or another, but EnGarde
seems pretty well rounded. "
June 18th 2001
- Newsforge
reviews EnGarde!
"With minimal
system access allowed and every precaution taken, Engarde Secure Linux
just might be the best distribution for Web/mail servers yet. It doesn't
have all the bells and whistles of other distributions or operating systems,
but it would seem that, unlike other companies that market server OSes,
Guardian Digital does not think Pinball is an appropriate application
for a server. With tight security and everything you need to configure
a server out of the box built into it, Engarde Linux is something you
should consider if building a secure Web site for commerce or any other
purpose, or just needing a reliable mail server. "
|