Re: Common Unix Security Risks - Your help please!

From: Gandalf Parker (gandalf_at_most.of.my.favorite.sites)
Date: 06/11/04


Date: Fri, 11 Jun 2004 16:55:04 GMT

b.u.watkins@gmx.co.uk (Ben Watkins) wrote in
news:f2b78b04.0406080956.21732a19@posting.google.com:

> I am currently writing a university assignment on Unix Security.
>
> I would be grateful if you guys could help me out...
>
> What, in your minds, are the most common (top five) and potentially
> most exploitable security risks that you see in Unix/Linux
> deployments?

IMHO

1) using defaults
2) getting secure, then adding an "easy administration" package
3) no internal policies to block social engineering attempts
4) considering security to be locking-out only with no watchdogs on the
system for spotting unusual changes
5) considering "secure" to be something you do once and thats adequate

If I were to add two more it would be
6) relying on any popular well-known package for security
7) relying only on ONE security package to make you secure

Gandalf Parker
-- alt.hacker newsgroup
(white-hats only need apply)
www.alt-hacker.org



Relevant Pages

  • Re: Visual Basic 6 OLEAUT32.DLL Security Update
    ... It still has a 'security' ... issue - but Win98 isn't exactly that secure to begin with. ... This is obviously only an issue if you are creating a package on a ...
    (microsoft.public.vb.general.discussion)
  • Re: Ten least secure programs
    ... it's probably better you leave the topic alone ... I said I do not have security issues with the programs I code. ... I didn't realize you were a Linux user, ... > the most widely used and secure UNIX flavors? ...
    (Security-Basics)
  • "An Asp.Net accident waiting to happen" - Draft article
    ... In a time where Security ... in shared hosting environments. ... technologies that allow the creation and deployment of secure ... IIS 6 web server and windows 2003 also provide some tools to deploy ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: Why Easy To Use Software Is Putting You At Risk
    ... I do agree that the additions and changes to Solarius will make it more secure and that this is good. ... Why Easy To Use Software Is Putting You At Risk ... instead I would say that the view that security is ... Four Construction Workers Died after Crane Collapse in Toledo, ...
    (Security-Basics)
  • TSLSA-2006-0024 - multi
    ... Trustix Secure Linux Security Advisory #2006-0024 ... Affected versions: Trustix Secure Linux 2.2 ... Package description: ... Mu Security has reported a vulnerability in Cyrus SASL ...
    (Bugtraq)