LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-01-2008, 04:34 PM   #1
Rauldinho
LQ Newbie
 
Registered: Nov 2004
Posts: 20

Rep: Reputation: 0
Internet Cafe Security


Hi, i own a internet cafe that used to have windows installed in every computer but i decided to use linux instead. So i'm using CCL for the administration and everything is ok. My question is, what kind of security measures should i use in every computer to avoid users from damaging the pc. I wnat to do what i did when i had windows installed, not allowing entering in the control panel, not running certain programs, etc. So can anyone give me an idea about a program or tutorial that could help me? Thanks for any answer i may get.
 
Old 07-01-2008, 05:22 PM   #2
jailbait
LQ Guru
 
Registered: Feb 2003
Location: Virginia, USA
Distribution: Debian 12
Posts: 8,337

Rep: Reputation: 548Reputation: 548Reputation: 548Reputation: 548Reputation: 548Reputation: 548
Your main protection will be proper use of file permissions. You set up your file permissions so that your users can only access the few programs and data files that you allow them to use. Here is a tutorial on file permissions:

http://www.zzee.com/solutions/linux-permissions.shtml

---------------------
Steve Stites
 
Old 07-01-2008, 08:20 PM   #3
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
One of my favorite examples of locked-down kiosks is at DNA Lounge in San Francisco, CA. You can see how it was setup here:
http://www.dnalounge.com/backstage/src/kiosk/
 
Old 07-02-2008, 03:24 PM   #4
resetreset
Senior Member
 
Registered: Mar 2008
Location: Cyberspace
Distribution: Dynebolic, Ubuntu 10.10
Posts: 1,340

Rep: Reputation: 62
Quote:
Originally Posted by Rauldinho View Post
Hi, i own a internet cafe that used to have windows installed in every computer but i decided to use linux instead. So i'm using CCL for the administration and everything is ok. My question is, what kind of security measures should i use in every computer to avoid users from damaging the pc. I wnat to do what i did when i had windows installed, not allowing entering in the control panel, not running certain programs, etc. So can anyone give me an idea about a program or tutorial that could help me? Thanks for any answer i may get.
Everything i want to tell you is pretty long ... 2 things - if you just let everyone get into it by using a regular nonroot name and p/w , I think it would solve a lot of problems.

2. LTSP project is something that can maybe help you. Linux terminal server project.
 
Old 07-02-2008, 03:44 PM   #5
farslayer
LQ Guru
 
Registered: Oct 2005
Location: Northeast Ohio
Distribution: linuxdebian
Posts: 7,249
Blog Entries: 5

Rep: Reputation: 191Reputation: 191
Could also use something like Pessulus to lock down the gnome desktop..

http://www.gnome.org/~vuntz/pessulus/
 
Old 07-10-2008, 03:03 PM   #6
simonapnic
Member
 
Registered: Jul 2008
Posts: 70

Rep: Reputation: 16
Post

In order to do anything serious to your boxes, they'd need root access.
You should patch your kernels with grsec/PaX to prevent the use of local root exploits and other malicious software, put them in a chroot and keep your systems updated (kernel + distribution). You have the alternative of using DeepFreeze as well. Here is their official site: http://www.faronics.com/html/dflinux.asp
It was used around here in internet cafe's, running Windows though.
 
Old 07-10-2008, 06:33 PM   #7
jamesapnic
Member
 
Registered: Jul 2008
Posts: 40

Rep: Reputation: 15
Personally, I might be inclined to use a PXE boot solution.

Or maybe LTSP. http://www.ltsp.org

You would then have thin clients which can get booted with a new OS every day or when someone logs off. Removing any damage they caused if they did. Also keeping it up to date would be easier since you just have one global image that they boot off.
 
Old 07-10-2008, 07:51 PM   #8
phantom_cyph
Senior Member
 
Registered: Feb 2007
Location: The Tropics
Distribution: Slackware & Derivatives
Posts: 2,472
Blog Entries: 1

Rep: Reputation: 128Reputation: 128
Here are 2 suggestions:

1. not only deny root access, uninstall sudo if it is installed, that could get ugly.

2. I have a friend thats a network administrator that setup a server that has virtual computers on it (i.e. VirtualBox), and the computers throughout the building are actually running VirtualComputers "projected" to their computers from the server. This would enable you to monitor their actions, as well as giving them a familiar environment. Also, you should be able to set it up so whenever you reboot the virtual machine, it restores your previous system, eliminating viruses and changes the user made. And, since your server would be running Linux, you could use a Linux firewall.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux Internet cafe ogfizzle Linux - Networking 1 04-08-2008 09:57 AM
internet cafe with debian slashams Debian 1 09-30-2006 03:55 AM
Linux Internet Cafe Elijah General 19 02-09-2005 06:06 PM
Help Im Stuck In Internet Cafe Help Please DaveyB Linux - Newbie 5 09-08-2004 03:54 PM
internet cafe server meetenshah Linux - Networking 1 08-31-2004 05:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration