LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-20-2012, 08:11 AM   #16
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422

Quote:
Originally Posted by Linux_Kidd View Post
Perhaps the idea of "not needed not there" concept has vanished from the world of security?

So what's your stance when there's a zeroday for the telnet client that allows uid's to do things as uid =0 ??? Would you then say "OH, only if it wasn't installed"???

Not needed here certainly hasn't vanished, and is prudent in many instances . However, the scenario you're raising applies to ANY piece of software on the machine. Are you sure your text editors don't have a zero-day exploit just waiting to jump out? How about your shell environments?

If having a telnet client makes you uncomfortable, then by all means remove it. But also think about overall ways to monitor the health of the system (regular patching, file integrity checks, log monitoring). Those are much more likely to catch a problem than worrying about individual software installs.
 
Old 10-22-2012, 12:02 PM   #17
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 737

Original Poster
Rep: Reputation: 78
I am not talking about per app here, i am talkjng about security best practices. And yes, my systems have every item installed on the system and what its functions and needs are. If not needed its gone, if its function can be done via another tool, like using ssh instaed of telent to check open ports, then i evaluate that and remove he one that is not needed.

This is my practice for locking a system down.
 
Old 10-22-2012, 12:42 PM   #18
Reuti
Senior Member
 
Registered: Dec 2004
Location: Marburg, Germany
Distribution: openSUSE 15.2
Posts: 1,339

Rep: Reputation: 260Reputation: 260Reputation: 260
You also removed unnecessary kernel modules or compiled a static one?
 
Old 10-23-2012, 01:48 PM   #19
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 737

Original Poster
Rep: Reputation: 78
Yes, I advocate monolithic kernel for specific systems. Out of the box is no longer acceptable in this day and age of hacking.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to setup thin client just for telnet or ssh client use using boot diskless PXE. hocheetiong Linux - Newbie 3 05-21-2008 07:02 PM
slackware 11.0 -- to leave or not to leave out the 2.4 kernel? aquilolumen Slackware - Installation 7 06-30-2007 07:12 PM
Best Telnet Client? Haggis Linux - Newbie 1 12-29-2004 01:05 PM
What telnet client? rivethead Linux - Software 3 03-25-2004 02:10 PM
What telnet client ? rivethead Linux - Software 5 02-27-2003 12:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration