LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-30-2002, 03:42 PM   #1
StamfordRob
Member
 
Registered: Jan 2002
Location: Stamford CT
Posts: 97

Rep: Reputation: 15
Question Locking down Linus and Snort


All.. I posted the following thread in Newbie but I hope that I can ask here as well. This being a more advanced request.

Thanks in advance..

rob


http://www.linuxquestions.org/questi...threadid=13109
 
Old 02-01-2002, 01:11 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Ill answer it here, cuz this is the appropriate place. Quite cool, you posting this "advert" for your post elsewhere borders on cross-posting, but IMO can't be marked as that :-]

Basically security comes in basically 3 levels:
- box integrity: setting (shell/pam/access/quota) limits on accounts or disabling unnecessary ones, perhaps use kernel patches like Open Wall (2.2x) or Grsecurity (2.4x) for stack and process protection, disable users permissions to run system tasks or run em tru sudo, finer grained logging, protecting your libraries and binaries by either running em off a read-only mounted partition or else chattr +iu em, and adding (and using) a system integrity detector like Aide, Tripwire, Samhain, chkrootkit. If thats settled check up on system application vulnerabilities, and register for the rhnetwork to be able to run up2date if you don't like manual upgrading. IMO manual upgrading has the pro you can tweak the source, turn features on or off and compile static binaries if necessary. *Some vulnerabilities youve got to live with, like svgalib, for instance.
* If this is a firewall, router or server: strip off X, gcc, user shell accounts, any unnecessary services and server apps.

- network security: if you run remote sytem maintenance, run OpenSSH instead of telnet, and limit account access to a few trusted hosts if possible and *dont* log in as root. Use sysctl to change TCP/IP behaviour (/proc/sys/net/ipv*) like forwarding, fragmenting, router discovery etc.
Make sure your firewall rules mirror/are in sync with the TCP Wrapper files, and add detection tru Snort, possibly complemented with an "active" part like Guardian to add firewall rules OTF, and set up cron to do regular reporting, cleaning out "dead" rules, etc. If you use X, make sure it's using Xauth, Xhost and the serverarg "-nolisten tcp" if you're not using it for connection to/from other hosts. Set up remote logging so if shit happens no one will be able to zap em logs.

- network application security: Don't run services you don't need, comment em out in (x)inetd.conf, and stop em in your runlevels (SYSV stuff in /etc/rc.d). If you have services that are only used by a few privileged users, limit account access to those. Check your network binaries' configs for possible loopholes. Limit where possible, like if you don't want sendmail to handle incoming attachments of 500Mb or be used as a relay, BIND version queries, etc. Limit daemon accounts, chroot apps if necessary. Play safe, run "stable" binaries.

Here's three things to give a bit more overview/make Linux security easier: Bastille Linux, The Linux Administrator's Security Guide and the CERT tech tips on improving security[/url].

The rest of my security reference list is in the second reply here: possibly a dumb(..).

*Btw, Im sorry this one of my prefab posts, but then again this way I dont have to worry Im forgetting something.
**Don't forget to patch Snort-1.8.3 for the small ICMP packet bug, or get the new one from CVS/snort.org
 
Old 02-02-2002, 05:08 PM   #3
StamfordRob
Member
 
Registered: Jan 2002
Location: Stamford CT
Posts: 97

Original Poster
Rep: Reputation: 15
unSpawn.. dude.. thanks for the help.. that helps a ton and gives me plenty to look into .. r
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
What does Linus use? John5788 Linux - General 8 06-19-2004 10:23 AM
snort snort.conf help crealkiller175 Linux - Software 1 03-08-2003 05:58 PM
Locking down Linux and SNORT StamfordRob Linux - Newbie 1 02-01-2002 01:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration