RE: [fw-wiz] Custom Unix server installations -- to harden extensively ?

From: Keith A. Glass (salgak_at_speakeasy.net)
Date: 05/14/03

  • Next message: Achim Dreyer: "Re: [fw-wiz] FW-1 NG management interface on Linux"
    To: <kluivert@tm.net.my>, <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 13 May 2003 22:01:14 -0400
    

    -----Original Message-----
    From: firewall-wizards-admin@honor.icsalabs.com
    [mailto:firewall-wizards-admin@honor.icsalabs.com]On Behalf Of Julian
    Gomez
    Sent: Tuesday, May 13, 2003 10:21 AM
    To: firewall-wizards@honor.icsalabs.com
    Subject: [fw-wiz] Custom Unix server installations -- to harden
    extensively ?

    >Hi,

    >What is the relative opinion of hardening general purpose Unix servers
    >(general == mail, web, db hosts). Obviously, wherever possible, I'd like to
    >get most of the unwanted packages stripped and removed; but very frequently
    >-- this is extremely time consuming and is alot of documentation work
    >(which btw, no one ever bothers to read).

    >Alas, this usually conflicts in the future when there is a need for
    >additional software to be implemented, the whole compiling + installation
    >steps, but the relevant packages have been removed as per the hardening
    >work done in the above paragraph.

    >So, what do most of you all do :

    > a) Leave the possibly-relevant future packages, intact on the
    > system, and just perform permission tweaks ?

    Actually (in Solaris), I comment out most of /etc/inet.d, and disable
    most rc2 and rc3 scripts. . .

    > b) Remove the packages, and when the need arises, reinstall the
    > packages -- I have to note here that alot of cross-dependencies
    > make this hell. At least on RH, if there is opinion on different
    > distributions which make this somewhat painless, closest thing
    > which might be relevant, I think is FBSD's ports system (though
    > I haven't used it myself) ?

    We're starting to talk about playing with saferm

    http://www.cert.org/security-improvement/implementations/i027.02.html#saferm

    > c) Leave the server, its screwed anyway because local users have
    > access :-)

    Well, not the FIREWALLS. . .

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Achim Dreyer: "Re: [fw-wiz] FW-1 NG management interface on Linux"

    Relevant Pages

    • Re: Off topic: Oops
      ... >>> Still waiting for an apology. ... > You aren't constantly "keeping playing", now, are you? ... > I don't care about what feud or another that you have with Patterson, ... BTW, Mr Watkins, for WWI and WWII, you're welcome. ...
      (rec.music.classical.recordings)
    • Re: Another old guy joins the group...
      ... You must've started real young :-) It's been about ... and the stage fright didn't end when the playing ... If the off-topic stuff bothers ... repairguy1993 dot netfirms dot com ...
      (alt.guitar)
    • Re: a great book
      ... reviews singled out the sloppy editing but didn't give much more ... Who are the other interviewees? ... BTW, some nice playing from your recent tour. ...
      (rec.music.makers.guitar.jazz)
    • Re: Christmas music
      ... that they are trying to churn up some business. ... BTW, having overhead Christmas music in a casino starts to get slightly ... One of the FM stations here is already playing it 24/7. ...
      (alt.vacation.las-vegas)
    • Re: VILLA LOBOS on NAXOS
      ... than with his feelings about Hamelin's playing of Villa-Lobos; ... btw, I for one am not convinced is "truly great music," although ...
      (rec.music.classical.recordings)