LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-23-2003, 09:55 AM   #1
scorpatron
Member
 
Registered: Nov 2003
Location: New Zealand
Distribution: Redhat 9 2.4.20-8 Athlon, Windows 2000 Professional, FreeBSD
Posts: 122

Rep: Reputation: 15
Talking semi-newb security questions? (and a stupid poll if you're bored)


I know a bit about networking, I also know a little about hacking/exploiting

/*
For the sake of people who don't know what hacking and/or explioting is

- Hacking : A general term refering to the act of breaking and entering (in electronic terms)
- Explioting : A method in which a vulnerability is taken advantage of (refering to the exploitation of programming errors to steal a root password)
*/

Basically what I know is that when it comes to securing your computers on the internet there are 2 types of leaks... connections which go out from your 'location', and connections which are being accepted from the internet (or 'listening sockets")

2 examples:

- an apache server running on port 80 (listening)
- a trojan application trying to connect to the outside world (resolving host)





So let me start my two questions:

// Question One

My router blocks all incoming connections apart from one to an apache server, is the router guarenteed to block all other traffic? if the router is only accessable to the internal network does that mean its brute force safe? do routers have vulnerabilities? Is my apache web server safe?, I'm using PHP and trying to be very secure.. should I be trying alot harder? Should I protect SSH?

// Question Two

For a connection to establish from within my network all a station must do is ask the dns server for a location (is that right?) could I log all non http requests? I want full control, where should I start?


Thanks.. like I said I'm semi noob, but I do know what's at stake.

(Red hat 9, newest kernal, fully upgraded? i run red carpet.. im pecimistic.. redhat wants me to pay for a subcription)
 
Old 11-23-2003, 09:57 AM   #2
scorpatron
Member
 
Registered: Nov 2003
Location: New Zealand
Distribution: Redhat 9 2.4.20-8 Athlon, Windows 2000 Professional, FreeBSD
Posts: 122

Original Poster
Rep: Reputation: 15
damn forgot the poll! damn if a moderator reads this can you add this poll?

? Are you concerned about the security (or lack of ) in your system/network ?

1. Yeah, but every day I deal with it properly and effectively
2. Yeah, I think I'm doing enough but I don't know
3. Yeah, we definately lack security
4. Nah, I am not concerned about security and I have reasons
5. Nah.
 
Old 11-23-2003, 03:48 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Best you could do is set up a separate thread for your poll.
I'll then graft this thread onto the new one.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Stupid newb + Knoppix + Wireless Network + ndiswrapper = PROBLEM! tomh500 Linux - Newbie 2 05-31-2005 05:45 AM
stupid debian newb qs sh4d0w13 Debian 1 03-11-2005 07:09 PM
Semi poll: Do you customise ? jalal Linux - Software 1 03-25-2004 11:17 AM
stupid stupid newb ? what to use instead of xconfigurator h00ligan Fedora 3 01-25-2004 09:51 PM
stupid newb questions xanxui Linux - Newbie 6 08-22-2003 01:26 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration