securite informatique
Accueil > Newsgroups Archives > comp.os.linux.security > Question on keeping Fedora 7 secure while connected to Internet

Question on keeping Fedora 7 secure while connected to Internet


Newsgroup: comp.os.linux.security ( Qu'est-ce qu'un Newsgroup et comment y participer ? )
Sujet: Question on keeping Fedora 7 secure while connected to Internet
De: Eric (reply.in.group@nospam.no)
Date: 28 Juillet 2007
I have a host set up at a remote site in another state. I'm working to
make it as secure as I can, so if you guys don't mind I'd like to run a
brief description of the system by you and ask for your opinion of where I
stand.

Here's a description of the system.

> Fedora 7 with all updates on Pentium 4
> Connected to the Internet
> Services available: httpd, sshd, pop3d, sendmail
> No rsh or rlogin (disabled in /etc/xinetd.d)
> No FTP; only SFTP (FTP over SSH) allowed, and no anonymous access.

This host has only three remote users, all trusted (myself and two
others). None are allowed to run any executable programs or scripts
(that's not enforced by anything on the host, but I trust them
sufficiently to not do it that I'm not concerned about it).

Any time anyone logs in, I get an email alert on my cell phone telling me
who it is and from what IP.

sshd is restricted to certain IPs in hosts.allow... big pain in the ass,
because the other two users have dynamic IPs and every time their IP
changes they can't get in anymore... :-(

pop3d and sendmail are available in hosts.allow (sendmail is configured to
disable relaying from untrusted hosts).

httpd is available to all (but, it's usually shut down unless we need it).

hosts.deny says ALL: ALL so if it's not listed in hosts.allow, it's not
allowed in.

Telnet is available to two specific hosts only, and is used only for
emergencies (sshd seems to shut itself down occasionally... been an issue
with Linux for many of the distros I've used... so every few months or so
I have to telnet in from one of the two trusted hosts and restart sshd).

Myself and the other two meed to be able to remotely access this thing, no
way around it, so we have to keep it connected to the net.

What else can I do to keep this thing secure?
Liens connexes
 Les réponses au message de Eric (reply.in.group@nospam.no)
Vulnerabilite.com ne peut être tenu responsable des propos tenus dans le Newsgroup comp.os.linux.security

 
 
Stopping Spam (en anglais)
Par Schwartz (O'Reilly)
 
Malicious Mobile Code (en anglais)
Par Grimes (O'Reilly)
Business Place
© 2000-2006 Vulnerabilite.com - Le portail des professionnels de la sécurité informatique
Edité par la société  ISECURELABS | Notice légale | Contact | Sitemap
Liens Promo : Disque dur - optimisation windows xp - Astuces Vista - Meilleurs prix