Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)
From: Fabrice Bacchella (fabrice.bacchella@synaptique.com)Date: 11/03/01
- Previous message: Trevor Fiatal: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- In reply to: Trevor Fiatal: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Next in thread: Trevor Fiatal: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Reply: Trevor Fiatal: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Reply: Vladimir Ivanov: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Reply: John Rowan Littell: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Reply: John Rowan Littell: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Message-ID: <3BE421FB.27C4EA7A@synaptique.com> Date: Sat, 03 Nov 2001 17:57:31 +0100 From: Fabrice Bacchella <fabrice.bacchella@synaptique.com> To: Trevor Fiatal <trevor@fiatal.net> Subject: Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)
> * Compile and install the tcpwrappers package. Set up policies in hosts.allow
> for in.telnetd, in.ftpd, in.rshd, and sshd. Pay especially close attention to the
> private cluster networks for in.rshd access. Make sure hosts.deny is set
> up to deny everything else by default.
I always had a bad feeling about tcpwrappers, it can only protect a few
daemons, those running with inetd and those willing to do so. That's
little user against a hackers, how will just try something else. Try
something like ipf instead, you can protect every service running on
your machine.
And there is no interest in running at the same time telnet, ftp, rsh
and ssh. Are you sure someone in your organisation will not one day use
telnet instead of ssh, just because he doesn't have ssh on his computer.
Just cut all those and dtlogin too. Ssh should be the only remote access
on your computer if you want it to be useful.
- Previous message: Trevor Fiatal: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- In reply to: Trevor Fiatal: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Next in thread: Trevor Fiatal: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Reply: Trevor Fiatal: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Reply: Vladimir Ivanov: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Reply: John Rowan Littell: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Reply: John Rowan Littell: "Re: Security for SUN-Cluster 3.0/2.2 with OPS (8.1.7)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|