LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-13-2009, 03:35 PM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Which is more secure Ubuntu or CentOS?


Which is more secure Ubuntu or CentOS?

TIA
 
Old 10-13-2009, 03:51 PM   #2
forrestt
Senior Member
 
Registered: Mar 2004
Location: Cary, NC, USA
Distribution: Fedora, Kubuntu, RedHat, CentOS, SuSe
Posts: 1,288

Rep: Reputation: 99
Yes.

Forrest
 
Old 10-13-2009, 03:58 PM   #3
brianL
LQ 5k Club
 
Registered: Jan 2006
Location: Oldham, Lancs, England
Distribution: Slackware & Slackware64 15.0
Posts: 8,233
Blog Entries: 61

Rep: Reputation: Disabled
Depends on who's using them.
 
Old 10-13-2009, 08:35 PM   #4
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,308

Rep: Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744
Depends on how you've set them up.
 
Old 10-13-2009, 08:43 PM   #5
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
How about assuming both are reasonably hardened after installation.
 
Old 10-14-2009, 05:54 AM   #6
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by abefroman View Post
How about assuming both are reasonably hardened after installation.
Are they both administered by the same person?
 
Old 10-14-2009, 07:39 AM   #7
avijitp
Member
 
Registered: May 2005
Location: India
Distribution: FC11, Debian/Ubuntu, RHEL, Solaris, AIX, HP-UX
Posts: 161

Rep: Reputation: 32
All depends on the users skill to harden it. Basic idea remains same, implementation is different.
 
Old 10-14-2009, 08:54 AM   #8
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Quote:
Originally Posted by win32sux View Post
Are they both administered by the same person?
Yes.

From the bugtrac, I seem to get more reports for Ubuntu over CentOS, so I would assume CentOS might be a little more secure, is that correct?
 
Old 10-14-2009, 09:02 AM   #9
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by abefroman View Post
From the bugtrac, I seem to get more reports for Ubuntu over CentOS, so I would assume CentOS might be a little more secure, is that correct?
Since the packages included in distros vary, I'm not sure that would be a good metric. That is, unless you're talking about distro-specific security vulnerabilities, which aren't very common. Maybe you could use other metrics, such as the time it takes for the distributor to release security patches. That way you could get a random sample of vulnerabilities which affected both distros and compare their response times.

Another thing you could do is set two test boxes up with those distros (fully updated), and hire someone to run a penetration test on them. Of course, as has been hinted above, the results of a penetration test wouldn't necessarily be good indicators for security problems with the distributions themselves, since they could easily be the result of poor implementation.

Last edited by win32sux; 10-14-2009 at 09:07 AM.
 
Old 10-14-2009, 09:36 AM   #10
forrestt
Senior Member
 
Registered: Mar 2004
Location: Cary, NC, USA
Distribution: Fedora, Kubuntu, RedHat, CentOS, SuSe
Posts: 1,288

Rep: Reputation: 99
Quote:
From the bugtrac, I seem to get more reports for Ubuntu over CentOS, so I would assume CentOS might be a little more secure, is that correct?
This may also be due to Red Hat bugs being fixed and CentOS acquiring the fixes when they get the newest version of whatever source RPM fixes the bug. Or it may be that more people are using Ubuntu and reporting problems. As win32sux says, it isn't really a good metric.

Forrest
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Apache (CentOS 5) multiple secure sites deadeyes Linux - Server 3 10-11-2009 07:00 AM
Running centos 5, and i want a secure ftp (ssl or ssl2) Anauj0101 Linux - Server 1 03-04-2008 01:27 PM
Centos 5 vsftpd /var/log/secure question johnvoisey Linux - Security 3 09-06-2007 06:45 AM
LXer: How To Secure Your CentOS Server Against Attackers LXer Syndicated Linux News 0 08-23-2006 02:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration