Title: Re: I've been hacked!! (was Re: [mhvlug] One more ques
Well, On the sys I was running I needed smb for print server as well. I was getting a bunch of firewall hits that I was just finding out was due to rwho (?). I was starting to learn that what I needed to do was keep smb from talking to eth0. Like I said before, I'd like to start with a "Deny All" firewall and then open connections as needed (and as was pointed out, deny connections to needed services to any but localhost (I believe webmin is configured this way by default is it not?). My problem is I don't know enough to do this yet.
 
I had updated all my installed packages for at least security fixes. It's one of the reasons I was using Mandrake vs RH because I've had a harder time updating RH with their demo account then with Mandrake.
 
I think I had smb, cups and ssh running but not 100% certain.
----- Original Message -----
From: Porkchop
Sent: Wednesday, July 16, 2003 1:38 AM
Subject: Re: I've been hacked!! (was Re: [mhvlug] One more question.....(yeah, sure))

Also, think really hard about what you need running, and what ports you
enable.  In most cases, all you need is ssh.  After that you should
configure ssh to not allow root logins, and even better, not allow passwords
(only use keys).

This gives some good food for thought...Jim touched on it too.
Fact of the matter is that you can have the best firewall software in the world running restrictive rules and still get hacked if you allow connections to and run a vunerable server. And it looks like RedHat 9 has plenty of security updates for holes discovered after the RH9 release...looks like about 35:
https://rhn.redhat.com/errata/rh9-errata-security.html

Cablemodem, DSL, and other always-on broadband subnets are constantly scanned for new vaunerable machines and then automatically attacked en masse by scripts that often continue the hunt once they infect new hosts. Its not all that uncommon to see large collections of machines under the control of one 13 year old kid in his/her basement.

This is the downside to Linux. Gotta lock it up solid or keep on top of all the updates. The only way to really run a firewall perfectly securely is to halt the system after it boots. It'll keep passing traffic and following the firewall rules, but there won't be enough of an active system to really hack.
Pkcp

Reply via email to