Re: Linux Hardening



I completely agree providing you have the time and dont have a couple of dozens of Linux machines to maintain daily, in many cases you have to make a sensible choice what would be worth more or in other words asses where the risk is higher and invest most of your efforts there.

Ajai Khattri wrote:
On Wed, 17 Oct 2007, Liran Cohen wrote:

what is the machine's location on your network (LAN\DMZ etc...) what is the machine role, you should ask yourself some questions before approaching hardening, I would not put the same effort on a machine which is located on my LAN as much as I would make sure that DMZ machines are protected

I believe even machines on internal networks should all run local firewalls at the very least. There's always some Windoze user using Outlook and clicking on an email attachment they shouldn't click on...



--
Liran Cohen
http://www.rct.co.il
http://www.dir.rct.co.il



Relevant Pages

  • Re: Linux Hardening
    ... dozens of Linux machines to maintain daily, in many cases you have to ... trouble maintaining a couple of dozen Linux machines. ... of fun, and a source of huge leverage. ...
    (Focus-Linux)
  • Re: Hyperthreading/Dual core CPUs
    ... Yes, i have disabled HT on my machines too, but that is because i dont have ... > applications that can benefit from hyperthreading. ...
    (RedHat)
  • Re: Medieval Madness, orders now being taken.
    ... Wayne is not Gene Cunningham. ... pundits to have to now admit that, but these are two different gentlemen, with 2 ... Just because Gene remade some machines is not indication ... you dont like him for whatever reason but the business is legit. ...
    (rec.games.pinball)
  • Re: Recommendations wanted
    ... ive seen them trick people in to buying machines they dont need and if they arent computer savy they can end up buying a gaming rig when all they need is an office machine. ... i personally run one and i can build machines at half the cost of the major manufacturers and offer way better support options. ...
    (alt.2600)
  • Re: Fair price for a SA-200?
    ... I dont own an engine welder and i dont know so please dont jump down ... The machines are super reliable and have a very long lifespan between ... If you're looking for a good generator that is capable of welding a bit ...
    (sci.engr.joining.welding)