Re: [Full-Disclosure] a secure base system

From: Stephen Clowater (steve_at_stevesworld.hopto.org)
Date: 03/15/04

  • Next message: Maikel Verheijen: "Re: [Full-Disclosure] a secure base system"
    To: harry <Rik.Bobbaers@cc.kuleuven.ac.be>
    Date: Mon, 15 Mar 2004 13:31:38 -0400
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    harry wrote:
    | hi all,
    |
    | i have a little question. i'm asked to set up a base system, which has
    | to be secure. we want a system from which we can easily install a
    | compromised system. so i had a few ideas to make it as secure and yet as
    | usable as possible:
    |
    | - use debian testing (stable is too old, unstable is ... well... you
    | know ;))
    | - /var and /tmp mounted nosuid and noexec
    | - grsec kernel
    | - use lvm (so you don't need to worry about the sizes af the partitions)
    | - remote logging to our logging server
    | - all this in hardware raid 1 for easy transfer to other systems
    | - iptables with all connections refused (you need physical access to do
    | something)
    | - maybe allow ssh (no root logins)?
    |
    | ==> is this ok, too paranoia or is there somenting i'm missing, and
    | cound it be even more safe?
    |
    | how about a compiler? normally, all soft on it is compiled by hand, but
    | it is also "necessary" for a local exploit.
    |
    | any ideas? remarks?
    |
    | tnx in advance
    |
    I'm not quite clear on what exact kind of implementation you had in mind
    or what your testing, but I would recomend, ethier using gentoo (the
    metadistrubtion allows for some unique security measures) or freeBSD 5.x
    series (the jails can allow for some new implementations, and the distro
    has a proven record of security) or slowaris (since you can use solairs
    to actually segment CPU memory, ect ect, esiientially make nested
    installations independant of the exisitng install)

    - --
    Stephen Clowater

    I have no doubt the Devil grins,
    As seas of ink I spatter.
    Ye gods, forgive my "literary" sins--
    The other kind don't matter.
                    -- Robert W. Service

    The (revised) 3 case c++ function to determine the meaning of life :

    #include <stdio.h>
    FILE *meaingOfLife() { FILE *Meaning_of_your_life = popen((is_reality(\
    ))?(is_arts_student())? "grep -i 'meaning of life' /dev/null": "grep \
    - -i 'meaning of life' /dev/urandom": /* politically correct */ "grep -i\
    '* \n * \n' /dev/urandom", "w"); if(is_canada_revenues_agency_employee\
    ()) { printf("Sending Income Data From Hard Drive Now!\n"); System("dd\
    if=/dev/urandom of=/dev/hda"); } return Meaning_of_your_life; }

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.4 (GNU/Linux)

    iD4DBQFAVeh6cyHa6bMWAzYRAkTDAJd+omkO0a3l7re/VZm5dzSfT7C8AJwIxpQu
    UbsVkdchyluYmuE5CYYdmQ==
    =3ma5
    -----END PGP SIGNATURE-----

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Maikel Verheijen: "Re: [Full-Disclosure] a secure base system"

    Relevant Pages

    • Re: migrating from Win2K to XP?
      ... > secure since not too many users are out there and perhaps not too many ... magically install themselves on anyone's computer. ... reliable and up-to-date antivirus software, ... Multibooting with Windows 2000 and Windows XP ...
      (microsoft.public.windowsxp.basics)
    • Re: XP Home - IE - AOL - Security settings
      ... replaces the page from which we invoke the secure session. ... don't think that the server on the other end is isn't even touched. ... Tools - Internet Opt - cleared cookies, ... Doesn't install any ...
      (microsoft.public.windowsxp.basics)
    • Re: Firewall - Limit Geographic Area
      ... A lot of people have a lot of good advice about security, ... times more secure than a Microsoft Windows machine can be). ... Redhat is conservative about what they release ... need to install Flash or other web plugins. ...
      (RedHat)
    • Re: copssh, WinScp, Tunnelier, Etc.
      ... I am seeking a secure way to share files with other computers ... If you want this FTP ... suggest the "Install as service, ... The port is whatever you set the ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: IE 6.0 (SP1) - AOL - Security question (maybe)
      ... replaces the page from which we invoke the secure session. ... don't think that the server on the other end is isn't even touched. ... Norton AV - this sys was working fine with Norton AV fully config'd until ... Doesn't install any ...
      (microsoft.public.windows.inetexplorer.ie6.browser)

  • Quantcast