LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-05-2003, 03:44 PM   #1
dai
Member
 
Registered: May 2002
Location: Wales
Distribution: Slack 8.1, Gentoo 1.3a, Red Hat 7.3, Red Hat 7.2, Manrake 8.2
Posts: 328

Rep: Reputation: 30
Reccomended Security books to read


As Im currently forced to look thru loads of security related books for my MSc dissertation I just thought that I would offer a list of books that come in handy with many topics especially Linux Security.

General Security books
====================

Hacking Exposed 4th ed ------ excellent book can read as a whole or use as a reference.

Hacking Exposed Web Applications --- very informative and helps with developing secure code and secure setup of web servers.

Linux Focused Security
====================

Maximum Linux Security 2nd ed --Excellent reference and very easy to digest

Hacking Linux Exposed 2nd ed -- Again superb reference and identifies via case study etc particular areas of interest.

Linux Security (craig Hunt series) -- Again well balanced, a little dated but very informative.

Apache Security
====================

Proffesional Apache Security --- Fairly thin but its quality not quantity that counts this book is absolutely superb and has an excellent section on Apache Jailing. A must for all interested in APache Security.

Apache the Definitive guide ----- Not strictly security oriented but an excellent reference

Linux reference
======================

Linux in a Nutshell ----need I say anything, brilliant reference



All of the above are excellent books for the relative security newbie and/or intermediate/advanced user. Im not advocating everybody rush out and buy these books as much info is available on-line (See Unspawn's sticky). But for those who like to read info from a book while working or just for a focused approach all of these are excellent in bringing together pertinent security issues and/or supplementary information usefull for all Linux administrators.

Hope this helps some of you

Last edited by dai; 07-05-2003 at 03:46 PM.
 
Old 07-06-2003, 03:09 AM   #2
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Also Building Internet Firewalls is truely an excellent book for security awareness and hardening systems.
 
Old 07-09-2003, 04:07 PM   #3
dogn00dles
Member
 
Registered: Feb 2003
Distribution: Slack 9.0/NetBSD
Posts: 101

Rep: Reputation: 15
Wink

Nice list. "Real World Linux Security" is also a good 'un as far as security is concerned (I'm too poor to buy computer books- but you can jot down a heck of a lot at the bookstore ).
 
Old 07-09-2003, 05:12 PM   #4
dai
Member
 
Registered: May 2002
Location: Wales
Distribution: Slack 8.1, Gentoo 1.3a, Red Hat 7.3, Red Hat 7.2, Manrake 8.2
Posts: 328

Original Poster
Rep: Reputation: 30
glad it helps, hope anybody else who can reccomend some Security books will let us now.

Perhaps this list could be made a sticky or added to UnSpawns FAQ as a list of sources of information???
 
Old 07-10-2003, 12:29 PM   #5
Dagon
LQ Newbie
 
Registered: Jul 2003
Posts: 5

Rep: Reputation: 0
Haven't read it myself but every review I've read for Maximum Security 4th Ed. has been excellent.
 
Old 07-15-2003, 05:20 PM   #6
dai
Member
 
Registered: May 2002
Location: Wales
Distribution: Slack 8.1, Gentoo 1.3a, Red Hat 7.3, Red Hat 7.2, Manrake 8.2
Posts: 328

Original Poster
Rep: Reputation: 30
Also having recently purchased and read the books Id like to recommend


Professional Apache 2.0 Wrox press

Practical Unix and Internet Security 3rd ed. O'Reilly

Both are excellent reads and Practical Unix is an excellent resource for Security allthough a great deal of the security discussions take place at a more theoretical level it does assit in identifying what is needed and isnt before you go about removing/disabling things.
 
Old 07-15-2003, 05:31 PM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Perhaps this list could be made a sticky or added to UnSpawns FAQ(..)
LOL, it ain't my FAQ, it's a LQ FAQ.
And, yes, I'll add those books. Hows your 'lil project coming on?
 
Old 07-15-2003, 05:45 PM   #8
dai
Member
 
Registered: May 2002
Location: Wales
Distribution: Slack 8.1, Gentoo 1.3a, Red Hat 7.3, Red Hat 7.2, Manrake 8.2
Posts: 328

Original Poster
Rep: Reputation: 30
Quote:
Originally posted by unSpawn
Perhaps this list could be made a sticky or added to UnSpawns FAQ(..)
LOL, it ain't my FAQ, it's a LQ FAQ.
And, yes, I'll add those books. Hows your 'lil project coming on?
Hehe well the FAQ looks like a UnSpawn whats what of Security at the moment so excuse the mistake

With regards my wonderful MSc Project Ive written up about 12000 words of research so far.

Practical element wise, Ive configured Apache 2.0 for SSL, PHP and etc. Along with MySQl yahda, yahda

Installed Sara, Tara, Crack, Jack and run Jack for 3 days before cracking a password so quite happy there.

And the pinnacle is that Ive managed to chroot Apache, ssl and PhP while getting the MySQL db to recognise the /chroot/temp/mysql.sock rather than normal /tmp/ so very happy there.

Now Im going to look into using Port Sentry for on demand Port Scanning and blocking and not sure what else yet. If I get time I may try and stick Guarddog or something on another machine I got and set Apache up as a proxy on it also. But time is short and allthough id like to work on setting up an Ip-tables firewall i dont think i will have time to.

Also Ive not forgotten about the Apache 2.0 chroot discussion/FAQ I said id knock together for you to check out just a bit busy at the moment, when I get a chance I'll e-mail it to you.

Dai

Last edited by dai; 07-15-2003 at 05:47 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
What books do you all read? vharishankar General 54 10-24-2004 05:56 AM
Star Wars books fans plz read this kamransoomro84 General 3 08-31-2004 04:04 PM
Books to read?? mayash Linux - Newbie 8 04-05-2004 11:50 AM
Linux Admin/Security/LAMPS/Develop Books jonconley Linux - Newbie 1 04-29-2003 02:28 PM
Security Books Palitha Linux - Security 4 07-12-2001 09:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration