----- Original Message ----- From: "Jim Doherty" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, July 15, 2003 9:12 PM Subject: Re: I've been hacked!! (was Re: [mhvlug] One more question.....(yeah, sure))
> > > Okay, time for me to jump on my soapbox :-). Most Linux > distributions, and most UNIX systems for that matter seem to ship > system configurations out the door that are easy for people to get > working on because they start alot of services. Each tcp/udp port that > you have listening is a potential buffer overflow waiting to happen > (read remote root exploit). Some UNIX applications (mySql ships > without a passwd) are even stupid enough to ship with default > userids/passwords, some routers and network switches have pulled this as > well. The default configuration out the door should be that > everything is turned off by default, and if a password needs to be set, > it should be forced to be set at 1st boot by the user/administrator. > > If you are going to run a server, ideally the only ports left open > should be for the service you are making available, and you should be > subscribed to the development mailing lists for the 'server' to know > when you are vulnerable. The only port I leave open is ssh, but them > I am paranoid and use both a router/firewall and iptables :-). Taking > a step beyond this, a server which has multiple people accessing it > shouldn't have a complete install image on it, in particular setuid > programs should be limited. I once examined all security alerts for > RedHat Linux announced in a year, and came to the conclusion that I > could have ignored half of them if I was picky about what I installed. > > I agree totally, when I set up samba servers the first thing I do is configure "Deny All" and then allow specific hosts to access. Unfortunatly I know little about firewalls or NAT and less about IP Tables and Chains. I made an asumption and listened to some advise about Firestarter that I realize I wasn't qualified to make. Now it's back to firewall school for WayneC. > _______________________________________________ > mhvlug mailing list - http://mhvlug.org > [EMAIL PROTECTED] > http://lists.dague.net/mailman/listinfo/mhvlug > _______________________________________________ mhvlug mailing list - http://mhvlug.org [EMAIL PROTECTED] http://lists.dague.net/mailman/listinfo/mhvlug
