Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-17-2008, 04:15 PM
Tom Forsmo
Guest
 
Posts: n/a
Default question about hardened linux

Hi

I am setting up a small private server which will run services like
smtp, imap, webserver, news and webmail on Debian. I have been reading,
among other things, the Gentoo hardening documentation and it explains
different hardening techniques, such as PaX, GrSecurity and hardened
toolchain and sources. I am a little bit confused now and are looking
for some help to clarify some questions I have.

My main question is, what of all that is relevant for me to do to harden
my server? Since my server is only going to run a few security minded
services, my thinking is that a lot of what the gentoo hardening
doucmentation describes does not apply as much to my scenario.

- As I see it, MAC is mostly of interest if users has login access to
the server.
- hardened toolchains and sources (i.e. use of ASLR and SSP) are mostly
of interest to servers/programs which do not care that much about
security, i.e. they have lots of buffer overrun problems

On the contrary, Bastille is important, so is probably parts of GrSecurity.

The way I see it is that if I run a server, the most important things I
have to focus on is:
- only use servers that are designed for security, such as dovecot,
postfix, apache2, ssh, openvpn
- configure them properly and securely, including applying chroot and
only accepting ssl connections with certificates.
- only start the services I actually use
- setup a proper firewall
- perform environment security setup, including things such as
- using bastille,
- basic linux security setup, such as hosts.deny etc
- read-only partitions
- tripwire
- secure system logs
- regularily perform security maintenance and updates.

Is this enough to fend of 99% of the security issues, or am I entirely
mistaken? My aim here is to keep away even the seasoned hackers, but
probably not the best of them. DDOS is not an issue yet, its more about
making sure things stored on the server are kept private.

regards

tom

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Repair Windows XP travolta011@gmail.com alt.comp.hardware 89 08-12-2007 10:19 PM
Windows XP optimization tricks travolta006@gmail.com alt.comp.hardware 93 07-30-2007 09:37 PM
Reading files from linux when you use linux (No partition but 2nd HDD) just_me alt.comp.hardware 2 02-19-2007 08:58 PM
Problem with Cisco wireless card under Suse Linux 10.1 starl8gazer@yahoo.com alt.internet.wireless 18 12-07-2006 09:29 PM
Modem setup question Linux evodawg alt.internet.wireless 2 11-08-2005 03:26 PM


All times are GMT. The time now is 08:10 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45