LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-12-2003, 03:04 AM   #1
budhusa
LQ Newbie
 
Registered: Dec 2003
Location: Austin, TX and Budapest, Hungary
Distribution: Mandrake 9.2
Posts: 27

Rep: Reputation: 15
Newbie about webmin...


i would like to enable remote access to my home pc's webmin, but im kinda wondering if anyone has any good security tips... just cause im a little bit worried, since someone could really fuck things up with webmin access...

so, would it help to have it on a non-standard port? and are there any specific modules that should be disabled for remote access, or is it safe to allow evthing? any other tips help too...

or...should i just not worry about this, and assume webmin's safe...

thanks...

bud
 
Old 12-12-2003, 07:25 AM   #2
irish_rover
Member
 
Registered: Sep 2002
Location: IN, USA
Distribution: Debian, Endian FW
Posts: 368

Rep: Reputation: 30
Anytime you open ports outside your lan you are taking a risk. Non-standard ports don't work so well, that is security-through-obscurity.
 
Old 12-12-2003, 10:08 AM   #3
phoeniXflame
Member
 
Registered: Feb 2003
Location: Somewhere, UK
Distribution: Slack, OpenBSD, Debian, SuSE
Posts: 189

Rep: Reputation: 30
anyone who is even remotely motivated to attack you WILL find your open ports no matter what you change them to, if your that worried about security, learn to do the things you do via webmin in a console, you'll learn more that way and its considerably more secure (imo)
 
Old 12-12-2003, 10:22 AM   #4
bureado
Member
 
Registered: Oct 2003
Location: Caracas
Distribution: Knoppix 3.3 (Debian sarge/sid)
Posts: 72

Rep: Reputation: 15
Using Debian?
http://www.debian.org/doc/manuals/se....html#contents
 
Old 12-12-2003, 11:10 AM   #5
budhusa
LQ Newbie
 
Registered: Dec 2003
Location: Austin, TX and Budapest, Hungary
Distribution: Mandrake 9.2
Posts: 27

Original Poster
Rep: Reputation: 15
okay...thanks for all your info.

im actually running mandrake, and i would say that security for me is not essential (it is just my home pc), but it cant hurt. anyway, ill rethink whether or not i should use webmin, and look into all the command line stuff...peace,
 
Old 12-12-2003, 11:25 AM   #6
mac_phil
Member
 
Registered: Sep 2003
Distribution: Mandrake 10.0
Posts: 200

Rep: Reputation: 30
You need to at least use SSL when you use Webmin remotely.

Another thing you could do is restrict access to Webmin. If you have an account on another computer, only let that computer connect to webmin. Then, when on the road, connect to that intermediate computer, then webmin.

If you don't have an account to facilitate this, you could set up webmin to only listen to requests from a proxy server, then connect through that proxy server.

However, if you have good passwords (long, alphanumeric, gibberish) and you use SSL (https) then it should be OK to just open Webmin up to the world.

Changing the port is probably pointless, since any attacker is going to scan you anyway.

Last edited by mac_phil; 12-12-2003 at 11:27 AM.
 
Old 12-15-2003, 04:36 PM   #7
frogman
Member
 
Registered: Sep 2003
Distribution: Mandrake, Slack, Debian and PicoBSD
Posts: 181

Rep: Reputation: 31
In addition to the above:

On boxes where I need webmin (read: am too lazy to fix by command line), I login via ssh and start the webmin service, then do what I need from the browser and when I'm finished I turn the service off again.

It can be a hassle that way, but I prefer to turn it on only when I need it.

ymmv.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
webmin FedoraUsr Linux - Networking 3 08-18-2005 06:43 PM
webmin troubles - Failed to write to /etc/webmin/module.infos.cache : No space left o coal-fire-ice Linux - Software 1 07-28-2005 10:08 AM
Webmin Pezboy *BSD 2 09-14-2003 04:28 AM
Webmin ckone Linux - General 2 05-11-2003 12:49 PM
webmin Chijtska Linux - Networking 3 02-08-2002 11:09 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration