What I won't discuss User security issue $IFS hacks, $PATH problems, password/account sharing, authentication methods (shadow, one time passwords, LDAP, SSH keys, PAM, kerberos, biometrics, two factor authentication, etc) Common user programming mistakes strcpy, strcat, gets, sprintf, vsprintf, trusting user input, using csh User-space security issues buffer overflows, format string attacks, viruses, trojans, TCP Wrappers, restricted shells, LD_PRELOAD Administration/configuration issues Running unnecessary services, poor file permissions, Audit / Log analysis / Scanning tools Tripwire, AIDE, Tiger, SATAN's offspring, NSAT, swatch, Nessus, etc.