|
This is from http://www.linuxquestions.org/questions/showthread.php?t=45261 and this local copy is for my convenience. Security references <!-- / icon and title --> <!-- message --> Welcome to the LQ Security references!
Securing a Linux box is not hard, but requires a bit of reading and planning ahead to make sure you covered the important points. That's why I compiled a few lists of texts about Linux security, grouped by subject: 1: Basics, important sites, HOWTO's, handbooks, tips, advisories, mailinglists, hardening, log analysis, sites, books Some texts contain step by step directions for newbies, and some are directed at intermediate or expert users.
Have fun! A note for copying. While this information is free, there are restrictions for copying. I collected and posted these resources here for the use of the larger Linux Community. This means you are free to copy this information, but you will give credit where credit is due and reference back adding this page as the original Linuxquestions.org URI. WARNING: HTML lintcheck <!-- / message --> <!-- edit note --> Last edited by unSpawn : 02-25-2006 at 12:56 AM. Reason: // 2006/02/25 tt sync <!-- / edit note --> |
||
| <!-- controls --> <!-- / controls --> | ||
<!-- post 222573 popup menu -->
<!-- / post 222573 popup menu --><!-- / close content container --><!-- / post #222573 --><!-- post #222575 --> <!-- open content container -->
| <!-- status icon and date --> |
#2 | |
|
Moderator
Registered: May 2001
Posts: 9,574
Distribution:
|
<!-- icon and title -->
Basics etc
<!-- / icon and title --> <!-- message --> Post 1
Basics, important sites, HOWTO's, handbooks, hardening, tips Advisories, alerts, bulletins, disclosure, mailinglists, mailing archives, knowledge bases, other sites Hardening, distro-specific Log analysis tools, resources Daemons, device or application specific More Brainfood, sites, books Basics, important sites, HOWTO's, handbooks, hardening, tips Checklists Securing Compromise, breach of security, detection Advisories, alerts, bulletins, disclosure, mailinglists, mailing archives, knowledge bases, other sites Neohapsis (mailinglists/archives): http://www.neohapsis.com Linux Gazette: http://www.linuxgazette.com Mailinglists distro specific: Debian S.u.S.E. Mandriva Conectiva Linux Slackware # We need to incorporate more distro's here. Hardening, distro specific Log analysis tools, resources Daemons, device or application specific Auditing tools at: More Brainfood, sites, books <!-- / message --> <!-- edit note --> Last edited by unSpawn : 08-02-2006 at 03:59 PM. Reason: //tt sync 20060801 <!-- / edit note --> |
|
| <!-- controls --> <!-- / controls --> | ||
<!-- post 222575 popup menu -->
<!-- / post 222575 popup menu -->
<!-- / close content container --><!-- / post #222575 --><!-- post #222579 --> <!-- open content container -->
| <!-- status icon and date --> |
#3 | |
|
Moderator
Registered: May 2001
Posts: 9,574
Distribution:
|
<!-- icon and title -->
Netfilter, firewall, Iptables etc
<!-- / icon and title --> <!-- message --> Post 2
Netfilter, firewall, Iptables, Ipchains, DoS, DDoS *Please note the easiest way to troubleshoot Netfilter related problems is to add log (target) rules before any "decision" in a chain. Netfilter/Iptables Ipchains Web-browsers, mail clients, FTP clients, IM, P2P ports database for building your own rules: http://www.pcflank.com/fw_rules_db.htm Other resources/misc stuff Webbased portscan services
DoS info DDoS info <!-- / message --> <!-- edit note --> Last edited by unSpawn : 02-24-2004 at 06:29 PM. <!-- / edit note --> |
|
| <!-- controls --> <!-- / controls --> | ||
<!-- post 222579 popup menu -->
<!-- / post 222579 popup menu -->
<!-- / close content container --><!-- / post #222579 --><!-- post #222581 --> <!-- open content container -->
| <!-- status icon and date --> |
#4 | |
|
Moderator
Registered: May 2001
Posts: 9,574
Distribution:
|
<!-- icon and title -->
Intrusion detection etc
<!-- / icon and title --> <!-- message --> Post 3
Intrusion detection, integrity checks: IDS, NIDS, HIDS, Antivirus, software. Note: vulnerability checking: CIS, SATAN, COPS, Tiger FAQ: Network Intrusion Detection Systems: http://www.robertgraham.com/pubs/net...detection.html The IDS acronym game: IDS: Intrusion Detection System refers to an application able to examine traffic for attributes and properties that mark "benign", suspicious, restricted, forbidden or outright hostile activities. NIDS: Network IDS refers to Intrusion Detection, like running "sensors" on various sentry or sniffer hosts while logging and/or logprocessing and alerting is done on a central host (many-to-one topology). HIDS: Host-based IDS. The HIDS acronym itself is subject to flamewars. IPS: Intrusion Protection System. Passive or active (learning, like the heuristics stuff?) enforcement of rules at the application, system or access level. I suppose we're looking at stuff like Grsecurity, Solar Designer's Open Wall, LIDS, LOMAC, RSBAC, Linux trustees, Linux Extended Attributes, LIDS or Systrace here. Docs:
Snort basics: Dropping Packets with Snort: Snort GUI's, management, log reporting and analysis:
Snort vs Abacus Portsentry: Comparison of IDSs ( NFR NID, Snort, INBOUNDS, SHADOW, Dragon, Tripwire): http://zen.ece.ohiou.edu/~nagendra/compids.html Snort help, mailinglist (archives), honeypots: Snort + 802.11 aka Wireless: http://www.loud-fat-bloke.co.uk/w80211.html Sniffing (network wiretap, sniffer) FAQ: http://www.robertgraham.com/pubs/sniffing-faq.html An Analysis of a Compromised Honeypot (Snort+Ethereal): http://www.securityfocus.com/infocus/1676 Snort on two interfaces, solution one: "-i bond0". Snort on two interfaces, solution two: "-i any"
File Integrity Detection Systems Commercial/non OSS examples: Versioner, GFI LANguard System Integrity Monitor, Ionx's Data Sentinel, Tripwire for Servers and Pedestal Software Intact. Viruses on Linux/GNU, Antivirus software Sendmail, Tcpdump, OpenSSH, TCP Wrappers, Aide and some other projects have suffered from people succeeding to inject malicious code, and of those only Sendmail and OpenSSH where at main servers, the rest where mirrors AFAIK. Even though all the apps mentioned are safe to use, and the differences where noted soon, the real problem is you I. have to have the knowledge to read code, and II. the discipline to read the code each time and question any diffs or III. have minimal "protection" in place to cope with like rogue compiled apps "phoning home". Which in essence means to end users any SW provided w/o means to verify integrity of the code and the package should be treated with care, instead of accepting it w/o questioning. As for the "virus" thingie I wish we, as a Linux community, try to "convert" people away from the typical troubles of Pitiful Operating Systems (abbrev.: POS, aka the MICROS~1 Game Platform) and direct them towards what's important to know wrt Linux: user/filesystem permissions, b0rken/suid/sgid software, worms, trojans and rootkits. Basic measures should be: *If you're still not satisfied you've covered it all you could arm yourself with knowledge on forensics stuff like UML, chrooting, disassembly and honeypots. If you want to find Antivirus software, Google the net for Central Command, Sophos, Mcafee, Kaspersky, H+BEDV, Trend Micro, Frisk, RAV, Clam, Amavis, Spam Assassin, Renattach, Ripmime, Milter or Inflex. Links to check out: <!-- / message --> <!-- edit note --> Last edited by unSpawn : 10-04-2006 at 02:52 PM. <!-- / edit note --> |
|
| <!-- controls --> <!-- / controls --> | ||
<!-- post 222581 popup menu -->
<!-- / post 222581 popup menu -->
<!-- / close content container --><!-- / post #222581 --><!-- post #222598 --> <!-- open content container -->
<!-- post 222598 popup menu -->
<!-- / post 222598 popup menu -->
<!-- / close content container --><!-- / post #222598 --><!-- post #222600 --> <!-- open content container -->
| <!-- status icon and date --> |
#6 | |
|
Moderator
Registered: May 2001
Posts: 9,574
Distribution:
|
<!-- icon and title -->
Forensics, recovery, undelete
<!-- / icon and title --> <!-- message --> Post 5
Forensics, recovery, undelete Forensics HOWTO's, docs Forensics CDR's Forensics tools Undelete HOWTO's Rescue tools for partition table/ext2fs Rescue tools from dd image Rescue tools for FAT/VFAT/FAT32 from Linux Partition imaging II. Runefs: The first inode that can allocate block resources on a ext2 file system is in fact the bad blocks inode (inode 1) -- *not* the root inode (inode 2). Because of this mis-implementation of the ext2fs it is possible to store data on blocks allocated to the bad blocks inode and have it hidden from an analyst using TCT or TASK. To illustrate the severity of this attack the following examples demonstrate using the accompanying runefs toolkit to: create hidden storage space; copy data to and from this area, and show how this area remains secure from a forensic analyst.: http://www.phrack.org/show.php?p=59&a=6 //If you've read this far and you aren't a professional system administrator: congrats. LQ doesn't ask you nothing in return but to spread around whatever good security practices you know. If you want to add a section or a link: please email me. License information: see top of thread. <!-- / message --> <!-- edit note --> Last edited by unSpawn : 02-24-2004 at 06:37 PM. <!-- / edit note --> |
|
| <!-- controls --> <!-- / controls --> | ||
<!-- post 222600 popup menu -->
<!-- / post 222600 popup menu -->
<!-- / close content container --><!-- / post #222600 --><!-- post #2122954 --> <!-- open content container -->
| <!-- status icon and date --> |
#7 | |
|
Moderator
Registered: May 2001
Posts: 9,574
Distribution:
|
<!-- icon and title -->
Securing networked services
<!-- / icon and title --> <!-- message --> Post 6
Securing networked services Apache Suexec Apache modules MySQL PHP Checking PHP Exploiting Common Vulnerabilities in PHP Applications Security network testing Application security testing Oracle Samba BIND SSH <!-- / message --> <!-- edit note --> Last edited by unSpawn : 08-17-2006 at 06:12 AM. Reason: //tt sync 20060817 |
|

price of Fioricet Klonopin vs losartan 881
Happy New Year!
Great post
buy viagra cialis
sample free milf college booty movies VS enjoying sex with wife
Post new comment