----- Original Message ----- 
From: "Jim Doherty" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, July 15, 2003 9:12 PM
Subject: Re: I've been hacked!! (was Re: [mhvlug] One more
question.....(yeah, sure))



> >
> Okay, time for me to jump on my soapbox :-).    Most Linux
> distributions,  and most UNIX systems for that matter seem to ship
> system configurations out the door that are easy for people to get
> working on because they start alot of services.   Each tcp/udp port that
> you have listening is a potential buffer overflow waiting to happen
> (read remote root exploit).    Some UNIX applications (mySql ships
> without a passwd) are even stupid enough to ship with default
> userids/passwords, some routers and network switches have pulled this as
> well.      The default configuration out the door should be that
> everything is turned off by default,  and if a password needs to be set,
>  it should be forced to be set at 1st boot by the user/administrator.
>
> If you are going to run a server,  ideally the only ports left open
> should be for the service you are making available,  and you should be
> subscribed to the development mailing lists  for the 'server'  to know
> when you are vulnerable.    The only port I leave open is ssh,  but them
> I am paranoid and use both a router/firewall and iptables :-).    Taking
> a step beyond this,   a server which has multiple people accessing it
> shouldn't have a complete install image on it,   in particular setuid
> programs should be limited.    I once examined all security alerts for
> RedHat Linux announced in a year,  and came to the conclusion that I
> could have ignored half of them if I was picky about what I installed.
>
>

I agree totally, when I set up samba servers the first thing I do is
configure "Deny All" and then allow specific hosts to access. Unfortunatly I
know little about firewalls or NAT and less about IP Tables and Chains. I
made an asumption and listened to some advise about Firestarter that I
realize I wasn't qualified to make. Now it's back to firewall school for
WayneC.



> _______________________________________________
> mhvlug mailing list - http://mhvlug.org
> [EMAIL PROTECTED]
> http://lists.dague.net/mailman/listinfo/mhvlug
>


_______________________________________________
mhvlug mailing list - http://mhvlug.org
[EMAIL PROTECTED]
http://lists.dague.net/mailman/listinfo/mhvlug

Reply via email to