LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-03-2004, 01:05 PM   #1
webazoid
Member
 
Registered: Jun 2004
Posts: 224

Rep: Reputation: 30
securing system for newbie?


i'm running mdk 10. just use it for docs, email, browsing, etc. i've turned on the firewall in the control center. anything else i can do to secure the system? how do i find out if other people have logged onto the system? thanks.
 
Old 07-03-2004, 02:16 PM   #2
gensis
LQ Newbie
 
Registered: Jun 2004
Distribution: Slackware, Suse, Red Hat, Fedora
Posts: 28

Rep: Reputation: 15
Bastille linux is your friend ^_^
http://www.bastille-linux.org/

Dunno if mandrake got lokkit, i think mandrake does have the GUI firewall editor, turn on only neccssary ports like SSH if and samba ports if your gona fileshare, buti i think SCP is a better way to go. if i am not mistaken firewalker is a good personal firewall http://sourceforge.net/projects/firewalker/

Complex passwords, disable services that are ONLY required, dont be running apache as a default service that is asking the script kiddies <ooohhh looky looky i got a big security hole, please pwn me>

This should you started ^^
Good luck and Google is your other best friend ^^
 
Old 07-03-2004, 02:39 PM   #3
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Mandrake has Shorewall, which by all accounts is a pretty good firewall editor. lokkit is absolutely the worst firewall policy editor I've ever seen, and the Red Hat people should be ashamed of shipping it in a commercial product.

By the way, one of the best resources would be to simply click on the sticky post at the top of this forum. unSpawn spent a lot of time putting together a huuuuuuuuge list of security references.
 
Old 07-03-2004, 04:22 PM   #4
gensis
LQ Newbie
 
Registered: Jun 2004
Distribution: Slackware, Suse, Red Hat, Fedora
Posts: 28

Rep: Reputation: 15
i agree with you, but personally i think lokkit is never really ment to be a policy editor, it just thought of it as a quick and dirty way of editing some basic rules. Did not know about being a "in a commercial product." Learn new things everyday.

Thx
 
Old 07-03-2004, 06:56 PM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
No, lokkit is not fit for anything at all--period. It completely violates security principles of "everything not explicitly allowed is denied", because lokkit implements it's rules as "everything not explicitly denied is allowed". That means you have to think of every possible way to abuse your firewall, and then write a rule to block it. If you miss just one case, you can be compromised. Essentially, you have to be the world's most perfect security admin in order to not leave holes in a lokkit firewall. That is setting up for failure and probably will fail 99.9% of the time when seriously attacked.

As for the commercial product, so far as I know that is the default firewall shipped with RHEL, which is just terrible. At least the Windows firewall blocks everything by default (when you turn it on).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
newbie: securing 9.2 viniosity SUSE / openSUSE 3 03-07-2005 11:10 PM
Newbie needs help securing his Slack Mr. Hill Linux - Security 2 02-28-2005 03:56 AM
Need some guidlines on securing a system BajaNick Linux - Security 5 10-15-2004 02:48 PM
[SOLVED] securing corporate system g_arun22 Linux - Security 14 06-03-2003 03:10 AM
securing system g_arun22 Linux - Security 2 06-02-2003 04:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration