Hey Everyone,

Sorry I haven't put out a new update in a while but I've been pretty
 busy.  Anyway.. lots of changes, a few critical patches added, etc..

159 users and counting..

--David


--
C*      5/05/99 There is a new exploit out on Bugtraq for Wu-FTPd.  Since Redhat
hasn't
        * Sent  updated their RPMs, you need to do it yourself.
        Update *        [Section 100]

------------------


I       5/03/99 Noted a /etc/shadow fix for Caldera users
                        [Section 100]

------------------

I       5/02/99 Updated the IPFWADM ruleset to v2.94
                        # v2A.94 - Added explict INPUT filters for NFS and OUTPUT 
filters for Mountd
and RPC
                        [Section 10]

I                       Disabled VRFY and EXPN in sendmail to secure Sendmail up a bit 
better.
                        [Section 25]

------------------

I       4/26/99 Added a little blurb on what Samba is all about
                        [Section 33]

                        Doh!  Updated the /etc/smb.conf file to use ENCRYPTED 
passwords!  
                        I use encrypted passwords now and the section already 
documented
                        how to set them up but the smb.conf file wasn't configured to
                        use it.   Thanks to [EMAIL PROTECTED] for this observation!
                        [Section 33]

------------------

N       4/25/99 Added the RFC URLs for DHCP
                        [Section 5]

                        Added a little blurb on what BOOTP/DHCP is.
                        [Section 27]

------------------

C*      4/19/99 Installed (3) new RPMs for security stuff
                        [Section 50]

------------------

G       4/14/99 Updated the APCUPSD URL
                        [Section 5]

G                       Updated the Samba URLs and added URLs for the Abacus, Network 
Flight
                        Recorder (NFR), and SHADOW network monitoring tools.
                        [Section 5]

G                       Changed to a a recurisive chmod 700 to the /etc/rc.d/init.d dir
                        [Section 7]

G                       Added the note that root and user passwords should include 
special
                        characters [ `~!@#$%^&*()-_=+{[]}\|'";:,<.>/? ] in addition to 
the
                        normal upper and lowercase letters and numbers.
                        [Section 8]

N                       Noted that some security paranoid people DELETE all unused 
lines out
                        of /etc/services instead of #ing the lines out.
                        [Section 8]

N                       Added /etc/hosts.allow examples for more granular access 
restrictions
                        to remote hosts.
                        [Section 8]

G                       Made a big clarification that when you use Secure CRT for SSH 
port 
                        forwarding, you must re-configure the given to-be-SSHed 
client, say
                        Eudora for POP-3 email, to connection to IP 127.0.0.1 and NOT 
the 
                        normal POP-3 server.  
                        [Section 30]

I                       Added a little blurb that Brad wrote about issues when trying 
to figure
                        out if your box has been hacked.  This is a good little read.
                        [Section 46]

N                       Noted that users should be careful where they download there 
source code,
                        RPMs, etc.  I cited the example where win.tue.nl has hacked 
and had 
                        a trojaned version of TCP-wrappers, there.  Ack!
                        [Section 50]

I                       I want to thank Bradley M Alexander <[EMAIL PROTECTED]> for all of 
these great
                        editorial comments to TrinityOS and for his port of TrinityOS 
to MS Word.

------------------

N       4/12/99 [EMAIL PROTECTED] been pointed out to me that the recent 
                        sysklogd-1.3-26.i386.rpm RPM from Redhat has a little bug.  It 
seems 
                        that upon system shutdown, you will see:

                        Shutting down system loggers: klog:306(PID) syslogd:294(PID) 
no such pid

                        The previous sysklogd-1.3-25.i386.rpm doesn't exibit this 
behavior.
                        I don't think is is any big issue but I though you might like 
to know.
                        [Section 50]

G                       Brad Alexander <[EMAIL PROTECTED]> has 
ported TrinityOS
                        v.3/31/99 to Microsoft Word.  Though this isn't the newest 
version of 
                        TrinityOS, this should help a lot of people who have been 
complaining about
                        TrinityOS's formatting.  This should go a ways while I 
complete the
TrinityOS
                        port to SGML.  You can find this Word port on my main Linux 
WWW page.

------------------

N       04/07/99        Added to the Future Feature section the automation of of the
firewall
                        hits trending file.
                        [Section 3]

G                       Added Kurt Seifried's "Linux    Administrators Security Guide" 
(LASG)
                        URL
                        [Section 5]

N                       Added the option to disable floppy WRITE access and even the 
drive
                        all together for the truely paranoid
                        [Section 8]

I                       Added a little blurb on the importance of creating a little 
offline
                        firewall hits log on: who, when, and how people are either 
probing or
                        fully attacking you.  This is an important thing for sys 
admins.  I
                        later hope to automate this.
                        [Section 9]

G                       Added the password option to LILO so that unless the password 
is given
                        a hacker cannot alter its booting procedure.
                        [Section 15]

N                       A user noted that Slackware comes with "netdate" which is very 
similar
                        to my documented "Getdate" but since its only for Slackware, 
I've left
                        the NTP section as it is but I have noted this in the section.
                        [Section 26]

N                       Added a recommendation to the truely paranoid that you can 
convert DHCPd
                        to run in a CHROOT'ed way.  This is documented in Kurt 
Seifried's "Linux
                        Administrators Security Guide" (LASG).  The URL was added to 
Section 5.
                        [Sectiom 27]

------------------

N       03/31/99        Fixed a typo in the ssh2_config referencing "sshd1path" and 
not the
                        correct "ssh1path"
                        [Section 30]

------------------

G       03/30/99        Updated the security blurb to have initial connections only 
prompt
                        with "Login:" instead of also showing the Linux kernel version.
                        [Section 9]

C*                      Added (4) Security patches for Redhat.
                        [Section 50]

------------------

C*      03/28/99        There is a new Xfree86 /tmp race condition.  Apply the 
workaround 
                        until there is a new Xfree version.  I've also noted this 
sticky
                        bit recommendation at the end of Section 8.
                        [Section 50]

------------------

N       03/27/99        Doh!  Though my basic and strong firewalls use REJECT in the
                        explict deny statements, the default policies was DENY.  I've 
changed
                        it to REJECT.
                        [Section 10]

------------------

N       03/24/99        After some recent experimentation, I found that the Probe 
Multi-LUN
                        support for my SCSI CD-changer was breaking things so I pulled 
it out
                        of the kernel config
                        [Section 12 - kernel setup]

N                       Like above, I added a blurb on what the Multi-LUN option does 
in the
                        kernel and made the recommendation to try your changer with 
OUT this
                        option initially and then to try it out if needed.
                        [Section 32 - CD Changers]

------------------
.----------------------------------------------------------------------------.
|  David A. Ranch - Linux/Networking/PC hardware         [EMAIL PROTECTED]  |
!----                                                                    ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'



_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to