Re: My way of securing my server... Any ideas?

From: Alan J. Wylie (alan_at_wylie.me.uk)
Date: 10/23/04


Date: 23 Oct 2004 20:19:36 +0100

On 23 Oct 2004 11:38:16 -0700, f_gunnar@hotmail.com (Frank Gunnar) said:

> Hi, I want to secure my server. I made a list of things I have to
> do. Is this good or did I miss something important? Any ideas or
> improvements?

> 7) read-only root directory and only allow to write to /tmp /var /home

And mount those directories noexec,nosuid,nodev

> B) log collection and evaluate tool

If possible, send the syslog to another box.

-- 
Alan J. Wylie                                          http://www.wylie.me.uk/
"Perfection [in design] is achieved not when there is nothing left to add,
but rather when there is nothing left to take away."
  -- Antoine de Saint-Exupery


Relevant Pages

  • Re: NFS trouble
    ... >> Look for mountd log messages on the server ... >> and see what gets into syslog. ... /mnt is usually a mount point, ... Mail has the best spam protection around ...
    (freebsd-questions)
  • Re: Mount fat32 partition
    ... message: "mount: you must specify the filesystem type". ... I have four syslog files: ... > but I am still stuck with the same message when Fedora is lauched. ...
    (Fedora)
  • CD oddities with VIA PATA
    ... On this box I can't mount it - ... In some cases useful info is found in syslog - try ... das eine Mal als Tragödie, ...
    (Linux-Kernel)
  • Re: mounting a dvdrw
    ... mount: wrong fs type, bad option, bad superblock on /dev/hdd, ... missing codepage or other error ... In some cases useful info is found in syslog - try ... Everyone is raving about the all-new Yahoo! ...
    (Debian-User)
  • Re: cannot mount cdrom!
    ... mount: block device /dev/hdc is write-protected, ... In some cases useful info is found in syslog - try ... And the messages put into syslog are the same, char for char, with or ...
    (Debian-User)