LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-25-2002, 06:36 PM   #1
hubergeek
Member
 
Registered: Mar 2002
Location: Hackensack, NJ.
Distribution: RedHat 7.0
Posts: 75

Rep: Reputation: 15
Hot to protect your router from attack


This may sound funny for some but I just learned crackers can hack your router and get all kinds of privileges.

How can I protect my routers from being hacked?
 
Old 07-29-2002, 07:36 AM   #2
grubjo
LQ Newbie
 
Registered: Jul 2002
Posts: 19

Rep: Reputation: 0
Use the latest Security-Patches, long passwords, disable all unused functions, install as less as possible software on your router.
 
Old 07-30-2002, 11:31 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
First it depends on what type of router you have. In it cleanest form and for max performance it just will do the routing part leaving filtering to a firewall, and serving to servers.
Second it depends on what you're attacked with. If a TCP/UDP/ICMP DoS is directed at your router there isn't match you can do beyond filtering obvious spoofs like protocols that aren't allowed from the outside, private range/broad/multicast addresses and rate limiting before calling your upstream provider to setup some filters or close the pipe.
If OTOH your router is attacked using routing protocols you'll have to get into docs on those. I've included a Router security reference list below.
Also NSA and Cisco laid out some basic guidelines for router configuration, and even tho it's geared towards Cisco's much on hardening the system and routing protocols applies to Linux as well.

*Btw, the "all that isn't specifically allowed is denied"
mantra should be on your mind while hardening the router.

Elaborating on what Grubjo said I'll try and specify:
- harden your system (GRsecurity/LIDS kernel patches, monolithic, obscure /proc/sys flags)
- remove default passes (like SNMP strings, if used)
- remove non-system user accounts and restrict logins by host, (virtual) terminal and user.
- chattr +iu configs and system binaries
- remove unused software (look at what LRP provides)
- a router is not a server: remove services to a (DMZ) server

- if remotely managed do it tru OpenSSH, not telnet.
- if remotely managed and it's got a web interface, make it use SSL using https
- where possible set up trusted hosts that connections are allowed from, if managed with SNMP, only allow from the local net cuz of cleartext passwords.

- review what you're routing it with (gated, routed, zebra, bird, netfilter/iptables, routing protocols like RIP/OSPF)
- review what you're routing (routed protocols like for instance TCP/UDP/ICMP)
- review who you're routing it to (private range/broad/multicast filters, rate limiting)

- install SIV like Aide, Tripwire, backup databases off site and check weekly.

- remote logging if possible
- backup cd for easy restoring after failure/break in

Some generic info:
CERT UNIX Security Checklist v2.0
Router specific:
NSA Security Recommendation Guides zipped pdf's,
Site Security Handbook rfc,
*also check its companion rfc 2350.
Routing security references.

Last edited by unSpawn; 07-30-2002 at 11:33 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
What attack could this be??? darrel Linux - Security 10 02-26-2005 10:10 PM
How Do You Protect Yourself? nuka_t Linux - Security 5 08-18-2004 11:35 PM
password-protect wireless router sugar Linux - Wireless Networking 5 07-27-2004 09:54 PM
What to do during an attack? revenant Linux - Security 9 04-02-2004 12:18 AM
Help I am UNDER ATTACK... needamiracle Linux - Security 28 04-22-2003 12:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration