Re: Security on debian

2001-09-30 Thread Blars Blarson
In article <[EMAIL PROTECTED]> 
[EMAIL PROTECTED] writes:
>debian security howto
>   http://www.debian.org/doc/manuals/securing-debian-howto/
>   ( url seemed slow to me too...gave up after 10 sec of waiting )

www.debian.org was/is having problems -- I wound up getting the document
off of www.uk.debian.org.

I'll have comments on the document in a while, it obviously is still
under contstruction. 
-- 
Blars Blarson   [EMAIL PROTECTED]
http://www.blars.org/blars.html
"Text is a way we cheat time." -- Patrick Nielsen Hayden



Re: Security on debian

2001-09-30 Thread Alvin Oga

hi ya scoot..

hoping you mean "really secure" as good enough for protecting
against most script kiddies ...

you can dig thru all those hundreds of urls... fun reading if you have
the time ...

debian security howto
http://www.debian.org/doc/manuals/securing-debian-howto/
( url seemed slow to me too...gave up after 10 sec of waiting )

simplified "hardening"
- turn off daemons you dont need/use ( printer, samba, etc
- turn off services yu dont need/use ( telnet, ftp, ppp, etc
- file system changes ( look for setuid bits, do you need it?
passwd files, "special accounts" dont need bash shells
- backup of your important data
- audit your sytem - ( nmap, nessus, etc
- tighten your kernel ( do you need modules
try to protect against buffer overflow
- lots to do... ( endless list of stuff... )

have fun
alvin
http://www.Linux-Sec.net/Harden -- more detailed hardening stuff to do(later)


On Sun, 30 Sep 2001, Scott Henson wrote:

> Can any one point me to the best books, how-to's, articles, scripts, etc. on
> hardening debian and making it really secure, but still easy to use?  I was
> looking on the debian site and I saw a security how-to, but for some reason
> it would not let me access it.  It said i didnt have permision to view it.
> 
> 



Re: Security on debian

2001-09-30 Thread Blars Blarson

In article <[EMAIL PROTECTED]> 
[EMAIL PROTECTED] writes:
>debian security howto
>   http://www.debian.org/doc/manuals/securing-debian-howto/
>   ( url seemed slow to me too...gave up after 10 sec of waiting )

www.debian.org was/is having problems -- I wound up getting the document
off of www.uk.debian.org.

I'll have comments on the document in a while, it obviously is still
under contstruction. 
-- 
Blars Blarson   [EMAIL PROTECTED]
http://www.blars.org/blars.html
"Text is a way we cheat time." -- Patrick Nielsen Hayden


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: Security on debian

2001-09-30 Thread Alvin Oga


hi ya scoot..

hoping you mean "really secure" as good enough for protecting
against most script kiddies ...

you can dig thru all those hundreds of urls... fun reading if you have
the time ...

debian security howto
http://www.debian.org/doc/manuals/securing-debian-howto/
( url seemed slow to me too...gave up after 10 sec of waiting )

simplified "hardening"
- turn off daemons you dont need/use ( printer, samba, etc
- turn off services yu dont need/use ( telnet, ftp, ppp, etc
- file system changes ( look for setuid bits, do you need it?
passwd files, "special accounts" dont need bash shells
- backup of your important data
- audit your sytem - ( nmap, nessus, etc
- tighten your kernel ( do you need modules
try to protect against buffer overflow
- lots to do... ( endless list of stuff... )

have fun
alvin
http://www.Linux-Sec.net/Harden -- more detailed hardening stuff to do(later)


On Sun, 30 Sep 2001, Scott Henson wrote:

> Can any one point me to the best books, how-to's, articles, scripts, etc. on
> hardening debian and making it really secure, but still easy to use?  I was
> looking on the debian site and I saw a security how-to, but for some reason
> it would not let me access it.  It said i didnt have permision to view it.
> 
> 


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: Security on debian

2001-09-30 Thread Alexander Reelsen
Hiya

On Sun, Sep 30, 2001 at 12:17:00AM -0600, Stefan Srdic wrote:
> This is the link that I have for the Securing Debian HOW-TO, it appears 
> to be down too
> 
> http://joker.rhwd.de/doc/Securing-Debian-HOWTO/Securing-Debian-HOWTO.htm
First it does not seem down (to me at least), second you should change
.htm to .html and third this document is completely obsoleted as Javier
Fernandez has incorporated it into an official Debian Document Project
Paper on www.debian.org/doc, which should be used as reference. :)


MfG/Regards, Alexander

-- 
Alexander Reelsen   http://joker.rhwd.de
[EMAIL PROTECTED]   GnuPG: pub 1024D/F0D7313C  sub 2048g/6AA2EDDB
[EMAIL PROTECTED]7D44 F4E3 1993 FDDF 552E  7C88 EE9C CBD1 F0D7 313C
Securing Debian:http://joker.rhwd.de/doc/Securing-Debian-HOWTO



Re: Security on debian

2001-09-30 Thread Alexander Reelsen

Hiya

On Sun, Sep 30, 2001 at 12:17:00AM -0600, Stefan Srdic wrote:
> This is the link that I have for the Securing Debian HOW-TO, it appears 
> to be down too
> 
> http://joker.rhwd.de/doc/Securing-Debian-HOWTO/Securing-Debian-HOWTO.htm
First it does not seem down (to me at least), second you should change
.htm to .html and third this document is completely obsoleted as Javier
Fernandez has incorporated it into an official Debian Document Project
Paper on www.debian.org/doc, which should be used as reference. :)


MfG/Regards, Alexander

-- 
Alexander Reelsen   http://joker.rhwd.de
[EMAIL PROTECTED]   GnuPG: pub 1024D/F0D7313C  sub 2048g/6AA2EDDB
[EMAIL PROTECTED]7D44 F4E3 1993 FDDF 552E  7C88 EE9C CBD1 F0D7 313C
Securing Debian:http://joker.rhwd.de/doc/Securing-Debian-HOWTO


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: Security on debian

2001-09-30 Thread Matteo Sisa
debian-security@lists.debian.org writes:
> I saw a security how-to, but for some reason
>it would not let me access it.  It said i didnt have permision to view it.

The link I know is: 

http://www.debian.org/doc/manuals/securing-debian-howto/

and it is working perfectly! As Nicole just said, look in the "Accepted
languages" preferences of your browser, and set [en] (NOT [en-US]!) if it
is not present.

Matteo



Re: Security on debian

2001-09-30 Thread Nicole Zimmerman

We just went through this on this list, actually. If you are getting this
error, go into your browser settings and make sure you have the [en]
language in your accepted languages list. 

-nicole

At 13:19 on Sep 30, Scott Henson combined all the right letters to say:

> looking on the debian site and I saw a security how-to, but for some reason
> it would not let me access it.  It said i didnt have permision to view it.



Re: Security on debian

2001-09-30 Thread Stefan Srdic

Scott Henson wrote:http


Can any one point me to the best books, how-to's, articles, scripts, etc. on
hardening debian and making it really secure, but still easy to use?  I was
looking on the debian site and I saw a security how-to, but for some reason
it would not let me access it.  It said i didnt have permision to view it.


-Scott Henson



A few good tips on this site:

http://wwwcmc.pharm.uu.nl/gillies/debian/

A few more security tips:

http://tinyplanet.ca/pubs/debian/html/c206.html

This is a good security site, I think some guy on this lists manages it.

http://www.linux-sec.net/

This is the link that I have for the Securing Debian HOW-TO, it appears 
to be down too


http://joker.rhwd.de/doc/Securing-Debian-HOWTO/Securing-Debian-HOWTO.htm

You can also download an exaple Debian IPtables script from:

http://www.debiandiary.f2s.com/files/iptables.sh

Stef





Security on debian

2001-09-30 Thread Scott Henson
Can any one point me to the best books, how-to's, articles, scripts, etc. on
hardening debian and making it really secure, but still easy to use?  I was
looking on the debian site and I saw a security how-to, but for some reason
it would not let me access it.  It said i didnt have permision to view it.


-Scott Henson



Re: Security on debian

2001-09-30 Thread Matteo Sisa

[EMAIL PROTECTED] writes:
> I saw a security how-to, but for some reason
>it would not let me access it.  It said i didnt have permision to view it.

The link I know is: 

http://www.debian.org/doc/manuals/securing-debian-howto/

and it is working perfectly! As Nicole just said, look in the "Accepted
languages" preferences of your browser, and set [en] (NOT [en-US]!) if it
is not present.

Matteo


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: Security on debian

2001-09-30 Thread Nicole Zimmerman


We just went through this on this list, actually. If you are getting this
error, go into your browser settings and make sure you have the [en]
language in your accepted languages list. 

-nicole

At 13:19 on Sep 30, Scott Henson combined all the right letters to say:

> looking on the debian site and I saw a security how-to, but for some reason
> it would not let me access it.  It said i didnt have permision to view it.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: Security on debian

2001-09-30 Thread Stefan Srdic

Scott Henson wrote:http

>Can any one point me to the best books, how-to's, articles, scripts, etc. on
>hardening debian and making it really secure, but still easy to use?  I was
>looking on the debian site and I saw a security how-to, but for some reason
>it would not let me access it.  It said i didnt have permision to view it.
>
>
>-Scott Henson
>
>
A few good tips on this site:

http://wwwcmc.pharm.uu.nl/gillies/debian/

A few more security tips:

http://tinyplanet.ca/pubs/debian/html/c206.html

This is a good security site, I think some guy on this lists manages it.

http://www.linux-sec.net/

This is the link that I have for the Securing Debian HOW-TO, it appears 
to be down too

http://joker.rhwd.de/doc/Securing-Debian-HOWTO/Securing-Debian-HOWTO.htm

You can also download an exaple Debian IPtables script from:

http://www.debiandiary.f2s.com/files/iptables.sh

Stef




-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Security on debian

2001-09-30 Thread Scott Henson

Can any one point me to the best books, how-to's, articles, scripts, etc. on
hardening debian and making it really secure, but still easy to use?  I was
looking on the debian site and I saw a security how-to, but for some reason
it would not let me access it.  It said i didnt have permision to view it.


-Scott Henson


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]