LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 09-20-2009, 09:15 PM   #1
egregor
Member
 
Registered: Sep 2009
Distribution: slackware, Salix, bsd's
Posts: 35

Rep: Reputation: 17
Beyond basic security tuning


OK, I got past configuring servers (even disabled inetd, ident, yp... all that I could), iptables, root suid programs, options in fstab, login.defs, hosts.deny... I could I do now? I'm looking at Tripwire and Snort. But what do you know works well on slack you would recommend? I know about a plethora of patchs like grsecurity, bastille, apparmor, selinux... But the majority of them seems to be discontinued. Or these new kernel versions don't need them?

Is the stock slackware kernel already very well secured or can I improve it?

And what about PAM?
Stock Shadow encryption in Slack is good?
There is some other good logging tool?

This machine is used only as a desktop, thus I don't need network servers running.


Sorry If I missed some thread about this, because all I could find were dated posts.

So lets discuss about security on someone who's paranoid's desktop slack. :^)
 
Old 09-21-2009, 07:20 AM   #2
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
My experience running my personal server is that Slackware is pretty secure out of the box. That said, I have done a few things:

1) Lock down ssh to only accept key-based logins, no username/password
2) Running AIDE to check for changed files
3) Using mod-security to lock down Apache a bit more.
4) Turn off all unused services

My personal opinion is that for desktop use, there isn't a lot that is needed. I use Firefox plus Adblock and Noscript to keep browsing threats down. In fact, I don't have my desktop machines locked down as tightly as my server is.
 
Old 09-21-2009, 09:53 AM   #3
digitalboy74
Member
 
Registered: Aug 2004
Location: Matrix
Distribution: slack currrent
Posts: 61

Rep: Reputation: 16
#1 on my list is to maintain your security patches.
 
Old 09-24-2009, 10:01 AM   #4
egregor
Member
 
Registered: Sep 2009
Distribution: slackware, Salix, bsd's
Posts: 35

Original Poster
Rep: Reputation: 17
Thanks for the replies.
Do you have experience with security patches for the kernel? Like those that difficult buffer overflow. What do you think about?
 
Old 09-24-2009, 06:08 PM   #5
mRgOBLIN
Slackware Contributor
 
Registered: Jun 2002
Location: New Zealand
Distribution: Slackware
Posts: 999

Rep: Reputation: 231Reputation: 231Reputation: 231
Personally I think that since it's a desktop machine that has no services running that you really just need to be sure you have decent passwords and that your system is up-to-date with security patches. A local firewall will add some security but make it too tight and you begin to loose functionality.

Realistically the weakest point of any system is the user/administrator.

There are many penetration testing live cd's out there that you can run against your system to verify the security.

OSSEC might be interesting to you also.

If you are downloading/compiling/installing software, make sure it is from a reputable source and that you verify all signatures (preferably gpg signed) before doing anything with them.

Many years ago my friends and I created a set of hardening scripts for Slackware http://www.sastk.org/. These are well and truly out of date now and should only be used on the versions they were written for but may give you some ideas if you want to harden your system further.

P.S I see you have J Denton's hardening doc in your sig... that's a pretty comprehensive list. Jeffery was also one of the SAStk authors.

Last edited by mRgOBLIN; 09-24-2009 at 06:09 PM.
 
Old 09-24-2009, 07:14 PM   #6
Josh000
Member
 
Registered: Aug 2009
Distribution: Slackware 13 64bit
Posts: 534

Rep: Reputation: 35
As others have pointed out, a first priority should be to always stay uptodate. Most attacks still occur on unpatched systems. For a desktop system, you won't be running so many services that you will have to worry about it, but a simple firewall will provide protection ifyou are still worried about it.

If you are interested in kernel patches, then I would suggest RSBAC. SELinux is definitely kept uptodate, and was accepted into the kernel sometime ago, although it is quite dependent on PAM, and so can be a nightmare to setup on slack. GRSecurity is still in development, and is quite simple, and will stop many of the attacks that would probably be used against a home user.

RSBAC is more similar to SELinux in scope, and has several advances security models. It is extremely stable and still in development, and works perfectly with slackware. I run it at the moment without an issue.
 
Old 09-24-2009, 07:48 PM   #7
egregor
Member
 
Registered: Sep 2009
Distribution: slackware, Salix, bsd's
Posts: 35

Original Poster
Rep: Reputation: 17
Thank you very much. I will look at these.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Security - seriously tuning Ubuntu problems deadlinx Ubuntu 0 06-02-2007 12:15 PM
Basic Security matchgirl Linux - Newbie 4 03-23-2006 01:21 AM
basic security?? wrat Linux - Security 5 05-15-2004 02:55 AM
Security Basic vcheah Linux - Security 2 01-08-2002 04:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 02:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration