Re: Locking Down a Linux Box

From: Kurt Seifried (bugtraq@seifried.org)
Date: 12/21/01


From: "Kurt Seifried" <bugtraq@seifried.org>
To: <focus-linux@securityfocus.com>
Date: Fri, 21 Dec 2001 14:50:03 -0700


> Any one out there know good reference for securing a
> Linux 7.2 Server OS. I'm new to using Linux and need
> to lock down a system for use as an IDS Sensor. Any
> help would be appreciated.

I assume you mean Red Hat 7.2. Simply remove everything except for OpenSSH.
I.e. a lot of rpm -e, remove all network daemons, also take a look for
setuid/setguid apps like ping/etc and remove them, and do not allow much
access to the box (i.e. only admins).

Kurt Seifried, kurt@seifried.org
A15B BEE5 B391 B9AD B0EF
AEB0 AD63 0B4E AD56 E574
http://www.seifried.org/security/



Relevant Pages

  • Re: Ubuntu (Linux); my first experience of...
    ... It should be a sign on the wall that I have a system on line 24/7 running Linux with: ... A web server, a mail server, a name server, telnet, X, ftpserver etc... ... It is so much easier to make _one_ lock on the frontdoor and some alarms on the windows, ... Having a dozen or more text editors allows one to select what one is most comnfortable ...
    (sci.electronics.design)
  • Mgetty doesnt release port
    ... I am trying to run a linux box as a dial in and dial out server. ... What is happening is that mgetty is locking the port ... lock belongs to mgetty. ...
    (comp.os.linux.networking)
  • Re: NFS server broken for -current
    ... success without checking with the server. ... I don't think kern/56461 should get committed; the bug is in the Linux ... should reject the locking request instead of simply dropping it. ... trying to lock a file on a Linux server. ...
    (freebsd-current)
  • Locking Down a Linux Box
    ... Any one out there know good reference for securing a ... Linux 7.2 Server OS. ...
    (Focus-Linux)
  • Re: Locking Down a Linux Box
    ... > Any one out there know good reference for securing a ... > Linux 7.2 Server OS. ... I'm new to using Linux and need ...
    (Focus-Linux)