LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-13-2009, 06:35 PM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Webmin, secure enough or leave it off?


For an email/web server is it a good idea to put webmin on? Or for security would it be wise to leave webmin off?

TIA
 
Old 10-13-2009, 06:44 PM   #2
pljvaldez
LQ Guru
 
Registered: Dec 2005
Location: Somewhere on the String
Distribution: Debian Wheezy (x86)
Posts: 6,094

Rep: Reputation: 281Reputation: 281Reputation: 281
My security stance is anything that isn't needed is an extra risk. So if you feel capable of doing everything from the command line, I would leave it off. If you're still learning your way around, it might be a useful crutch for a while.
 
Old 10-13-2009, 06:54 PM   #3
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Quote:
Originally Posted by pljvaldez View Post
My security stance is anything that isn't needed is an extra risk. So if you feel capable of doing everything from the command line, I would leave it off. If you're still learning your way around, it might be a useful crutch for a while.
Thanks!
 
Old 10-13-2009, 08:02 PM   #4
FragInHell
Member
 
Registered: Sep 2003
Location: Sydney Australia
Distribution: Redhat, Centos, Solaris, Ubuntu, SUSE
Posts: 282

Rep: Reputation: 45
If you really have to use it, then set it up to listen on localhost only and then use SSH port fowarding to access the webmin page.
 
Old 10-14-2009, 11:19 AM   #5
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Anything that you can justify using, you can use.

Webmin does have ACLs, so you can lock it down to only certain IPs that can access it. In tandem with that, you can also add a FW ACL to block access from anything you don't specifically allow.

SSH tunneling may not work if you're in a corporate environment, but HTTP/S traffic is almost always allowed (not that I'm telling you to duck corporate security posture). When I'm at work, the only way for me to access my server is Webmin. I've been flagged before by the security office for tunneling or directly shelling into the server, so, for me at least, HTTP/S is the only option (unless its via my iPhone...not a pretty solution, tho).
 
Old 10-14-2009, 12:58 PM   #6
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Right - webmin w/ strong passwords + sane ACLs should be fine.

If you really don't need it, then of course don't use it. (But I'm unsure about why you would be asking this if you didn't need it.)
 
Old 12-20-2009, 02:39 AM   #7
Jun87
LQ Newbie
 
Registered: Aug 2007
Posts: 6

Rep: Reputation: 0
Quote:
Originally Posted by FragInHell View Post
If you really have to use it, then set it up to listen on localhost only and then use SSH port fowarding to access the webmin page.
Can you briefly explain how to do that? Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
slackware 11.0 -- to leave or not to leave out the 2.4 kernel? aquilolumen Slackware - Installation 7 06-30-2007 07:12 PM
how can I secure my nis server ?can I use openSSL to secure it form sniffing ? abhi_raj Linux - Networking 1 07-10-2006 06:19 AM
LXer: University of Michigan Selects SSH Tectia for Secure System Administration and Secure File Transfers LXer Syndicated Linux News 0 04-25-2006 12:54 AM
webmin troubles - Failed to write to /etc/webmin/module.infos.cache : No space left o coal-fire-ice Linux - Software 1 07-28-2005 10:08 AM
How Secure is Webmin? macnut Linux - Security 6 09-13-2004 09:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:36 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration