Re: General Security Issues

From: db (db_at_traceroute.dk)
Date: 03/01/04

  • Next message: Jacques A. Vidrine: "Re: mbuf vulnerability"
    Date: Mon, 1 Mar 2004 19:34:57 +0100
    To: bookman@oteglobe.net, security@freebsd.org
    
    

    On Mon, 1 Mar 2004 16:48:07 +0200
    "Konstantinos Fotiadis" <bookman@oteglobe.net> wrote:

    > The box has no services running expect apache and we telnet to it via
    > SSH. Main function of this box will be graphing various interfaces via
    > rrdtool. So, I would like to ask if there is any other precautions
    > that I must take in order to sleep safe at night. Should I check for
    > any other opened ports ?

    sockstat -l -4

    >Should I do something with the kernel to be
    > more secure ? I know this ain't so easy, but let's say my main scope
    > is to get a least a decent sleep :-)

    Try these ports (all under "security"):
    lockdown
    chkrootkit
    portaudit
    tripwire
    snort
    freebsd-update
    just to name a few. Of course you should read about OpenSSH and Apache
    security and keep them up to date. Maybe even run sshd at some high port
    like 56789?

    br
    db
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Jacques A. Vidrine: "Re: mbuf vulnerability"

    Relevant Pages

    • Re: Building and configuring reliable linux routers?
      ... Curently one linux box with two ethernet interfaces is routing between ... what I'm proposing to do is enable vlan tagging on both ... two physical ports and use STP so only one is active at a time. ... the other students who are working in the lab don't have a clue. ...
      (comp.os.linux.networking)
    • Re: routed interfaces
      ... For clarity sake I was speaking about a 36xx with a NM-16ESW. ... With that setup you can have either L2 ports (with a VLAN interfaces if you ...
      (comp.dcom.sys.cisco)
    • Re: Redundant 6500 sup module behavior
      ... I've read that the interfaces on the standby unit are active. ... implies the ports are actually active in spanning-tree, ... full physical/logical redundancy, I don't see how the ports would be ...
      (comp.dcom.sys.cisco)
    • Re: Stock DHCP on Solaris 8/07
      ... I finally got around to putting in a support call with Sun and what they ... that sets LAN interfaces to use a local (not the same for all ports) MAC ... and doesn't configuring the zone as an exclusive-IP zone do ...
      (comp.unix.solaris)
    • Re: Help for designing MIL-STD 1553 boards.
      ... > ten serial communication ports of RS-232 and also 4 USB interfaces. ...
      (comp.arch.embedded)