LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-16-2002, 01:57 PM   #1
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
Are you armed?


Guys, I believe script_kiddies era is falling down, but I don't believe the crackers era is falling down as well, I just came across this article
http://zdnet.com.com/2100-1105-943879.html
Are you prepared to deffend yourself?
 
Old 07-16-2002, 03:30 PM   #2
akohlsmith
Member
 
Registered: Apr 2002
Distribution: Slackware
Posts: 114

Rep: Reputation: 15
It's easy to defend yourself if you take some time and lock down your firewall. You don't have one? Find a geek to help you out. I make good money selling slackware-based firewalls to corporations.

Don't think that just because you've disabled tcp/137-139, turned on rp_filter and turned off ICMP echo replies that you're safe. You need to think like a paranoid jackrabbit about network security, and then realize that being *that* paranoid solves nothing. Coming at it hte other way just doesn't work.
 
Old 07-16-2002, 08:19 PM   #3
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Original Poster
Rep: Reputation: 56
Yeah, that's true, I've blocked everything I could think of, turned off ICMP echo to just find out that somebody was playing jack and hide with me, see my post about promiscous mode on my ppp0 interface, I guess there's no a single solution to all your security needs. But the point of the article is that cracker's "community" is no longer interested in playing with MS Windows different flavors OS's, it is switching to more advanced "techniques" to target *NIX based platforms, I am not saying that *NIX's have never been a target for crackers, I am saying that *NIX's, espacially Linux had gained enough power to acquire network and net market such that malicious users are following the wind. I guess, *NIX vs MS war in network/net market won by *NIX, and now it must carry the burden of MS in the war against crackers - I really don't like call them hackers because they bring bad name for programming enthusiasts.
Will see who wins - obviously MS lost big time in both - MS vs *NIX and MS vs. crackers

Last edited by neo77777; 07-16-2002 at 08:22 PM.
 
Old 07-16-2002, 08:31 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Their sites/article doesn't show details like SOHO boxen vs servers and hardened/updated vs out of the box setups and for example. IMNSHO FUD spread by a company that makes its money securing systems doesn't make me run faster.

I do think the Linux community as a whole should put more effort into educating each other getting knowledge of good administration and security practices, I hope you agree security is more than just a firewall...
 
Old 07-16-2002, 09:23 PM   #5
akohlsmith
Member
 
Registered: Apr 2002
Distribution: Slackware
Posts: 114

Rep: Reputation: 15
It's not even that it's more than a firewall.

Many people think that NAT protects them. It doesn't. Having a default DENY policy is pretty damned effective but it's also a pain in the ass unless it's properly set up.
 
Old 07-16-2002, 11:52 PM   #6
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Original Poster
Rep: Reputation: 56
I am totaly agree with you guys, that's why I said there is no a single solution to your security needs. Like again in my case, I have tripwire laying around collecting dust and I didn't bother to install it, now I am puzzled if any files were modified. I just hope my system wasn't a part of a DDoS and my ISP wouldn't call me about it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration