Re: securing single debian box against internet attacks

From: Ryan R. Frederick (bob_at_nospam.k7hosting.com)
Date: 06/23/03


Date: Mon, 23 Jun 2003 15:44:20 GMT

User wrote:
> I am on broadband and I wish to secure my debian box before putting it
> on the internet. I have a LinkSys G54 broadband router and 'firewall'
> but as a firewall it is limited (spoofed tcp ACK packets get by, etc.)
> Hence, I need to protect my desktop debian box against attacks. It's
> used just a simple desktop machine, it doesn't need to route or bridge
> or any of that. What is the easiest way to harden it against network
> attacks? I've read the firewall HOW-TO etc. but I was wondering if
> there is a more convenient way than having to recompile the kernel?
> For instance, is there a debian package that would aid me?
>
> thanks

Mostly... just disable unneeded services... and make sure the needed
ones are configured properly... I've never enabled a firewall solution
on my home networks... and i've never really been attacked either...

Good Luck,

Bob



Relevant Pages

  • RE: Need help from a group of experts. I am not a network expert but I play one on tv.
    ... preventing file attachments alone won't stop all email attacks. ... Sonicwall is a good firewall...but any firewall depends on how well you ... I am not a network expert ... - Precisely Define and Implement Network Security ...
    (Security-Basics)
  • Re: Advice for setting up a file server
    ... > I would very much appreciate any advice concerning the set-up of a Debian ... > based file server. ... image back over the network. ... lab (thankfully behind the university firewall) before ...
    (Debian-User)
  • Re: A poor mans activity check :)
    ... Is a firewall worth the memory it occupies? ... If you are on a closed network and trust all other users not to abuse ... To balance cost against benefit, you need to know something about cost, ... Can a firewall prevent attacks? ...
    (comp.security.firewalls)
  • Re: Ask EU - firewalls
    ... The addresses to use in a "private network" ("your side of the ... but that is a different subject, and this is not how a software firewall ... Yes, routers could be hacked potentially, wireless routers have already ... an important and often weak target for attacks is partly due to its near ...
    (uk.media.radio.archers)
  • Re: IDS on Switched Networks
    ... connecting a network IDS to it would be fine. ... Higher state of alert you know what attacks you are ... If your firewall has NAT turned on, ...
    (Focus-IDS)