good linux security guide?

Red Squirrel

No Lifer
May 24, 2003
70,010
13,489
126
www.anyf.ca
Can anyone recommend a good security guide on securing a Linux server where users have ssh access? For example, how to stop that bug where people can just su as root with no password. Things of that nature, and also protecting from outside threats.

I know the basics, and I've recently been messing with iptables to be able to do basic IP/port blocks, but I want to go further.
 

drag

Elite Member
Jul 4, 2002
8,708
0
0
I donno. There is a nice book called 'Hardening Linux" that you can usually find in bigger bookstores.

Otherwise there are websites all over the place. Linuxsecurity.com is probably a handy place to start.

Here is somethings that I know:

a) Simple is better. Complexity is the enemy of security.
b) Reduce the amount of services you use to a bare minimum to reduce attack footprint. The only thing I have running on my systems most of the time is SSH (it can file transfer, remote gui, remote file systems, etc).
c) Encryption is easy, but unless used correctly is worse then useless.
d) Use long and irritating passwords that are unique. They also need to be changed periodically.
e) Periodically check your system to make sure that your not running anything unexpected. Keep your system up to date.

That's about it. Thats about 95% of the battle and probably covers most of the important stuff going.
 

Red Squirrel

No Lifer
May 24, 2003
70,010
13,489
126
www.anyf.ca
Yeah I also have iptables to block EVERYTHING then I just unblock what I need. And by everything, even ICMP, gone. I opened up the IPs to the data center's monitoring, and thats it.

And yeah I try to stay away from complex setups unless I really understand them.

Like I have a semi complex setup with the way my VMs are secured behind the virtual nat, with the actual service on another bridged nic, but I fully understand the setup and have it documented.

Things like SSH public key, I decided against due to the complexity of it. I'll want to play around with it and research it before I consider implementing it as a booboo could end up enabling no password access, or something, if I do something wrong.
 

child of wonder

Diamond Member
Aug 31, 2006
8,307
176
106
If your box allows port 22 connections from the internet I'd highly recommend disabling root SSH access and installing denyhosts.

At my last job, the geniuses at the company that bought ours decided it would be easier to simply open our internal network to the whole world than deal with a VPN so they could remotely access our systems.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |