LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions
User Name
Password
Linux - Distributions This forum is for Distribution specific questions.
Red Hat, Slackware, Debian, Novell, LFS, Mandriva, Ubuntu, Fedora - the list goes on and on... Note: An (*) indicates there is no official participation from that distribution here at LQ.

Notices


Reply
  Search this Thread
Old 12-01-2011, 10:33 PM   #1
ArTranc3
LQ Newbie
 
Registered: Dec 2011
Posts: 3

Rep: Reputation: Disabled
Smile Choosing the right distro, Locked down from within.


I'm looking to put a box at a client site which will be connected to the client's home router for internet.

That box will have remote access software on it and will have untrustworthy contractors logging in and using the browser. So, I'm looking for a distro that would be LOCKED DOWN to the max from the user side.

Regardless of the distro I'm planning on blocking all possible applications, (especially the terminal) leaving only the browser accessible. Blocking all the ports and all the domains aside from the 2 that the user/contractor should access. The user will have non-admin privileges of course.

So, taking all that into consideration, is there a distro that somehow facilitates being locked down from within, to minimize the possible attack surface?

That's a home network we're talking about, so I'm considering security VERY seriously.
Can the security even be guaranteed to a certain extent with this setup, should I even go ahead with this project?

Any and all other possible security tweaks are definitely welcome, I'm a newbie so everything and all is new to me.

Guys, your thoughts are greatly appreciated!

Thank you beforehand!

Last edited by ArTranc3; 12-01-2011 at 10:35 PM.
 
Old 12-01-2011, 10:56 PM   #2
fukawi1
Member
 
Registered: Apr 2009
Location: Melbourne
Distribution: Fedora & CentOS
Posts: 854

Rep: Reputation: 193Reputation: 193
All distro's should be capable of doing what you want..

Keep in mind though, with physical access to the computer, things become a lot harder to protect.
Some things to think about
-> booting to a live cd will give full access to the HDD
-> disable alternate boot devices in the BIOS and password the BIOS
-> single user mode
-> password protect the boot menu
-> Removal of the disk and putting it into a external caddy/spare computer
-> disk encryption
-> if the machine stays on, the encryption key can possibly be recovered from RAM with a "cold boot attack", although, this is somewhat unlikely..
It all depends on your definition of "LOCKED DOWN to the max", and "VERY seriously".
 
Old 12-01-2011, 11:02 PM   #3
ArTranc3
LQ Newbie
 
Registered: Dec 2011
Posts: 3

Original Poster
Rep: Reputation: Disabled
I'm not as worried about the actual client being able to get in.

My main concern are the contractors. Those contractors will not have any access to the box except for that which is given by the TeamViewer.

The box will not have a CD/DVD-ROM.

The main concern should be the contractors hacking their way out of the locked down box and messing up the client's system thats on the same local network. Thats my main concern.
 
Old 12-01-2011, 11:18 PM   #4
fukawi1
Member
 
Registered: Apr 2009
Location: Melbourne
Distribution: Fedora & CentOS
Posts: 854

Rep: Reputation: 193Reputation: 193
Apologies, I misread your OP in that i thought the untrusted folk had physical access..

As i said, pretty much any distro is going to do what you want.

You can create firewall (iptables) rules to only allow certain ports to certain IP's.
Proxy (squid) rules to only allow certain websites.
User groups, permissions, ACL's etc, to restrict particular programs.

So, I would pick the distro you are most comfortable with.
 
Old 12-01-2011, 11:29 PM   #5
vharishankar
Senior Member
 
Registered: Dec 2003
Distribution: Debian
Posts: 3,178
Blog Entries: 4

Rep: Reputation: 139Reputation: 139
Have you considered an OS like OpenBSD? It's not Linux, but it is a "secure by default" kind of Operating System with maximum security features built right into the OS that would require a lot of tweaking/work in other *nix systems.

Last edited by vharishankar; 12-01-2011 at 11:30 PM.
 
Old 12-01-2011, 11:44 PM   #6
ArTranc3
LQ Newbie
 
Registered: Dec 2011
Posts: 3

Original Poster
Rep: Reputation: Disabled
Thank you fukawi1!

vharishankar, I already settled with CentOS.

Any specific guides or suggestions on how to bring forth the security configurations I mentioned. I only tentatively know how it should work in theory but will need massive research to bring it into fruition.

If guys have any specific guides that would be greatly appreciated.
 
Old 12-01-2011, 11:46 PM   #7
vharishankar
Senior Member
 
Registered: Dec 2003
Distribution: Debian
Posts: 3,178
Blog Entries: 4

Rep: Reputation: 139Reputation: 139
OK, since you've settled down to a distro, you could mark this thread "solved".

Last edited by vharishankar; 12-01-2011 at 11:47 PM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Choosing the right distro bob--r Linux - Newbie 4 03-23-2008 07:45 AM
need help choosing a distro Homer69 Linux - Newbie 17 11-11-2005 02:52 PM
Need help choosing distro redfedora88 Linux - Distributions 7 08-30-2005 10:24 PM
Choosing a Distro raspera Linux - Newbie 5 08-02-2005 04:16 PM
choosing a Distro SabaumLinux Linux - Distributions 8 02-13-2005 02:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions

All times are GMT -5. The time now is 11:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration