LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 06-26-2004, 07:27 PM   #1
moger
Member
 
Registered: Sep 2002
Distribution: Fedora Core 3
Posts: 247

Rep: Reputation: 30
Tweaking Slack security


I am looking through a linuxsecurity.com quick reference guide and in it, it recommends some kernel configuration options through the /proc pseudo-filesystem. In particular, there are in /proc/sys/net/ipv4 (such things as icmp_echo_ignore_all and tcp_syncookies). However, I don't see that directory on Slackware. Is there an equivalent proc directory that would have those settings?
 
Old 06-27-2004, 01:52 AM   #2
Cerbere
Member
 
Registered: Dec 2002
Location: California
Distribution: Slackware & LFS
Posts: 799

Rep: Reputation: 33
I've got that directory in Slack 9.0. I think whether or not it exists depends on the configuration of your kernel.

Enjoy!
--- Cerbere

[edit] Oh, BTW I'm still running 2.4.22 [/edit]

Last edited by Cerbere; 06-27-2004 at 01:53 AM.
 
Old 06-27-2004, 02:01 AM   #3
moger
Member
 
Registered: Sep 2002
Distribution: Fedora Core 3
Posts: 247

Original Poster
Rep: Reputation: 30
Happen to know where in slack 10.0 / latest 2.6.x kernel this may be?
 
Old 06-27-2004, 05:30 AM   #4
gargamel
Senior Member
 
Registered: May 2003
Distribution: Slackware, OpenSuSE
Posts: 1,839

Rep: Reputation: 242Reputation: 242Reputation: 242
Can't tell where the option is buried, but you have to add proc file system support to your kernel.

BTW, you can then add support for procfs config info, meaning that you can ask the proc pseudo file system for information on the configuration of your currently running kernel. Which is nice, at times, especially, if you are experimenting with multiple kernels, and don't remember what exactly you have booted with... ;-)

gargamel
 
Old 06-27-2004, 05:39 AM   #5
keefaz
LQ Guru
 
Registered: Mar 2004
Distribution: Slackware
Posts: 6,552

Rep: Reputation: 872Reputation: 872Reputation: 872Reputation: 872Reputation: 872Reputation: 872Reputation: 872
Yes you should configure your kernel with CONFIG_SYSCTL=y and CONFIG_PROC_FS=y at the minimum but maybe some other options for netfilter are missing too.
 
Old 06-27-2004, 09:31 AM   #6
moger
Member
 
Registered: Sep 2002
Distribution: Fedora Core 3
Posts: 247

Original Poster
Rep: Reputation: 30
I have procfs support but not sysctl support in my kernel. I still don't have a /proc/sys/net/ipv4 directory, though.
 
Old 06-27-2004, 09:35 AM   #7
moger
Member
 
Registered: Sep 2002
Distribution: Fedora Core 3
Posts: 247

Original Poster
Rep: Reputation: 30
Ah nevermind, this explains why...

" Setting kernel parameters in the /proc/sys directory need not be a manual process or one that required echoing values into a virtual file, hoping they are correct. The sysctl command can make viewing, setting, and automating special kernel settings very easy.

To get a quick overview of all settings configurable in the /proc/sys directory, type the sysctl -a command as root. This will create a large, comprehensive list, a small portion of which looks something like this:

net.ipv4.route.min_delay = 2
kernel.sysrq = 0
kernel.sem = 250 32000 32 128

This is the same basic information you would see if you viewed each of the files individually. The only difference is the file location. The /proc/sys/net/ipv4/route/min_delay is signified by net.ipv4.route.min_delay, with the directory slashes replaced by dots and the proc.sys portion assumed. "

That is for redhat but I assume it's similar in Slackware.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to set security options in Slack 9.1 Nappa Slackware 1 01-15-2004 06:18 AM
This is an security concern? Then why is it defualt in Slack 8.1? Tarts Slackware 2 08-20-2003 11:06 PM
um, Tweaking Thom_Redhat Linux - Software 13 06-17-2003 03:10 AM
Slack 9 firewall/security? Manx_UK Slackware 10 06-06-2003 04:14 PM
some X tweaking zeky Linux - Software 3 12-23-2002 02:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 06:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration