Check List For Linux Security

Check List for Linux Security

Linux is an amazing operating system considering how it was originally created. It was a modest program written for one person as a hobby – Linus Torvald of Finland. It has grown into a full-fledge 32-bit operating system. It is solid, stable and provides support for an incredible number of applications. It has very powerful capabilities and runs very fast and rarely crashes.

Unfortunately Linux machines are broken almost every day. This happens not because it is an insecure operating system. It contains all the necessary tools to make it very secure. But the truth is. It hasn’t become significantly more secure with the increase in popularity. On the other hand, our understanding of the hackers methods and the wide variety of tools and techniques available contributed to help system administrators to secure their Linux computers.

Our goal in this article is to list the most critical situations, and how to prevent an invasion with simple measures.

1- Weak passwords – By far the first and most used method used by hackers to try penetrating a Linux system is cracking a password, preferently of the user root. Usually they will target a common user first, and then, using his/her access to the operating system, try to get a privileged access cracking the root password. Good password policy, and good passwords are absolutely critical to the security on any computer. Some common mistakes when selecting a password:
A- use “password” as password.
B- use the name of the computer.
C- a well-know name from science, sports or politics.
D- reference to movies.
E- anything that is part of the user web site.
F– references associated with the account.

The latest version of Linux offer shadowed passwords. If a cracker can see an encrypted password, crack it would a simple task. So, instead of storing the password in the passwd file, they are now stored in the shadow file which is readable only for root. Before a hacker can crack a password he needs to figure out an account name. So, simple accounts names must be avoided as well. Another security measure is to apply a “no login” to the account in the passwd file. This must be done to all the accounts that don’t need to log in to the system. Examples are: apache, mysql, ftp and other.

Limit which terminals root may log in from. If the root account is allowed to log in only in certain terminals that are considered secure, it will be almost impossible for a hacker to penetrate the system. This can be done listing the allowed terminals on /etc/security. The login program will consider insecure any terminal that is not listed on this file, which is readable, only by root.

2- Open Network Ports

Any Linux default installation will provide the Operating System with tons of software and services. Several of them are not necessary or even wanted by the administrator. Removing these software and services will close the path to several attacks and improve security. The /sbin/chkconfig program can be used to stop services from automatically starting at run levels 3, 4 and 5. Log in as root and type /sbin/chkconfig --list to view all the services set to start automatically. Select the ones you don’t need and type /sbin/chkconfig 345 name_of_service off. You must do that to all services you don’t want to keep running. Also, the xinetd server can be used to disable other services as well.

3- Old Software Versions

Everyday vulnerabilities are found in programs, and most of them are fixed constantly. It is important, and sometimes critical, to keep up with the changes. There are mailing lists for every Linux distribution where one can have security related information’s, and the latest vulnerabilities found.
Some place to watch for security holes are:
· http://www.redhat.com/mailman/listinfo/redhat-announce-list
· http://www.debian.org/MailingLists/
· http://www.mandrakesecure.net/en/mlist.php
· http://www.suse.com/us/private/support/security/index.html
· http://www.freebsd.org/security/index.html
· http://www.linuxtoday.com/
· http://www.lwn.net/
It is crucial to insure that the security released patches are applied to the programs as soon as they area available. The hacker community will be aware of the discovered holes and will try to explore them before the fixes are applied.

4- Insecure and Badly Configured Programs

There are some programs that have a history of security problems. To name a few IMAP, POP, FTP, port map and NFS, are the most known. The good thing is that most of these programs can be replaced by a secure version like spop, sftp or scp.

It is important that, before deploying any service, the administrator investigate its security history. Sometimes simple configuration measures can prevent serious headaches in the future.

Some advices regarding a web server configuration are well worth to mention:

- Never run the web server as a privileged user;
- Do not keep clients’ confidential data on the web server – Credit card numbers, phone numbers, mailing addresses, must be recorded on a different machine.
- Make sure the privileged data that a user supplies on a form does not show up as a default for the next person to use the form; - Establish acceptable values for data that is supplied by web clients. - Check vulnerabilities on CGI programs.

5- Stale and Unnecessary Accounts

When a user no longer uses his /her account, make sure it is removed from the system. This stale account won’t have this password changed periodically leaving a hole. Publicly readable or writable files owned by that account must be removed. When you remove an unnecessary service make sure you remove or disable the correspondent account.

Security Resources in the web

Bugtraq – Includes detailed discussions of Unix security holes
http://www.securityfocus.com/

Firewalls – Discuss the design, construction, operation, and maintenance of firewall systems.

http://www.isc.org/services/public/lists/firewalls.html

RISKS Discuss risks to society from computers

http://www.risks.org/

Insecure.org

http://www.insecure.org/

By: Jair

Related Products

GRI 289-1, Recessed Door Alert/Pool Alarm, 7-Second Delay, ETL Listed

(more details)
The GRI 289-1 is a recessed door alert/pool alarm with 7 second delay - closed loop (Home Security, Total Computing Life Safety Systems)

GRI 289-3, Recessed Door Alert/Pool Alarm, Instant On, ETL Listed

(more details)
The GRI 289-3 is a recessed door alert/pool alarm with instant on - closed loop (Home Security, Total Computing Life Safety Systems)

GRI 289-4, Surface Mount Door Alert/Pool Alarm, Instant On, ETL Listed

(more details)
The GRI 289-4 is a surface mount door alert/pool alarm with instant on - closed loop (Home Security, Total Computing Life Safety Systems)

Honeywell HP300ULX, UL Listed Power Supply, 12 VDC/24 VDC, 2.5A

(more details)
The Honeywell HP300ULX is a UL Listed Power Supply, 12 VDC/24 VDC, 2.5A (Security, Total Computing Life Safety Systems)

Honeywell HP400ULX, UL Listed Power Supply, 12 VDC/24 VDC, 4.0A

(more details)
The Honeywell HP400ULX is a UL Listed Power Supply, 12 VDC/24 VDC, 4.0A (Security, Total Computing Life Safety Systems)

Linear UL Listed Wireless 2-Channel Receiver/CO Detector

(more details)
The DX-COKIT Supervised Carbon Monoxide Detector Transmitter and Receiver Kit contains a single station DXS-80 carbon monoxide alarm with a built-in supervised transmitter and DXR-702 2-Channel Receiver (Security, Total Computing Life Safety Systems)

Honeywell HP600ULX, UL Listed Power Supply, 12 VDC/24 VDC, 6.0A

(more details)
The Honeywell HP600ULX is a UL Listed Power Supply, 12 VDC/24 VDC, 6.0A (Security, Total Computing Life Safety Systems)

SBR Javascripting Module - Linux Single 1 appliance

(more details)
SBR Javascripting Module - Linux Single 1 appliance (Home Security, SecureHQ)

Musical Checking His List Water Globe

(more details)
FREE Shipping when you spend $50 on selected items! Plays santa Claus Is Coming To Town Melody. Add A Musical Accent To Your Home With This Water Globe. Christmas. Hand-painted Details. (christmas decor, decor, home decor, Target.com)

Musical Checking His List Water Globe

(more details)
FREE Shipping when you spend $50 on selected items! Plays santa Claus Is Coming To Town Melody. Add A Musical Accent To Your Home With This Water Globe. Christmas. Hand-painted Details. (christmas decor, decor, home decor, Target.com)

Musical Checking His List Water Globe

(more details)
FREE Shipping when you spend $50 on selected items! Plays santa Claus Is Coming To Town Melody. Add A Musical Accent To Your Home With This Water Globe. Christmas. Hand-painted Details. (christmas decor, decor, home decor, Target.com)

Checking His List Stocking

(more details)
Bring smiles to children of any age with the Holiday Reflections II Christmas Stockings. These handmade stockings display colorful, acrylic needlepoint faces with velveteen backs and hanging loops. Specify one name up to 11 letters. Each stocking is... (Accessories, fireplace accessories, home decor, Touch of Class)

Samsung TAD137JSEB Premium OEM Travel Charger for Samsung Cell Phone (check compatibility list)

(more details)
Compatible with Samsung MM-A900 Blade,SCH-A530,A570,A610,A630,A650,A670,A890,A930,A970,N330...SGH A300,C207,D307,D347,D357,D407, D415, D500, 508,D600,E105,E315, E316,E317,E330,E335,E600,E630,E635,E700,E705,E715,E770,E800,N625,P100 ,P107,P207,P777,S300,S307,T309,T319,T609,V205,V206,X105,X426 ,X427,X427M...SGH-X475,X507,X660 ,ZX10...SPH-A580,A790,A900,A920 mobile phones. (Amazon.com, none)

DOOR ANCHOR STRAP by FIT CORD for Resistance Band and Exercise Tube Workouts (PLEASE CHECK OUR OTHER LISTINGS FOR SAFETY SLEEVE FIT CORDS THAT INCLUDE DOOR ANCHOR.)

(more details)
THIS LISTING IS FOR ONE FIT CORD DOOR ANCHOR. (PLEASE CHECK OUR OTHER LISTINGS FOR SAFETY SLEEVE FIT CORDS THAT INCLUDE DOOR ANCHOR.) This high quality tightly woven nylon Door Anchor accommodates most brands of resistance toners with standard handles. Our Fit Cord toners have padded handles and a nylon safety sleeve covering the entire tube and they are easily secured with this door anchor. FIT CORD DOOR ANCHORS CAN BE USED WITH ALL RESISTANCE BAND WORKOUTS, FITNESS PROGRAMS AND EXERCISE VIDEOS (Amazon.com, none)

Check ME Notepad - Grocery List Planner

(more details)
{Sanity-inducing shopping list} Objective: To get you in and out of the store with healthy foods and your mind in tact. 5.5 x 8.5 note pad, 50 sheets, printed on white recycled paper with colored text, chip board backing, shrink wrapped. (Amazon.com, none)

Check List and Record Book of United States and Canadian Coins (Official Red Books)

(more details)
Complete Inventory Check List and all United States and Canadian Coins! (Amazon.com, none)

Hewlett Packard Commercial PCs HP SmartBuy dc5850 SFF Phenom X3 8600B 2.3GHz/1.5MBL2/3GB/320GB/SuperMulti/GigNIC/Linux

(more details)
The HP Compaq dc5850 Desktop PC offers high-end capabilities and power-efficient performance for uncompromising results. Featuring a powerful processor, chipset, and integrated graphics technologies from AMD, the HP dc5850 is equipped to exceed your... (desktop computers, HP, PC Connection)

Hewlett Packard Commercial PCs HP SmartBuy dc5850 SFF Phenom X3 8600B 2.3GHz/1.5MBL2/3GB/320GB/SuperMulti/GigNIC/Linux

(more details)
The HP Compaq dc5850 Desktop PC offers high-end capabilities and power-efficient performance for uncompromising results. Featuring a powerful processor, chipset, and integrated graphics technologies from AMD, the HP dc5850 is equipped to exceed your... (desktop computers, HP, PC Connection)

Iomega StorCenter Pro NAS 200rL Server 2TB Linux (Open Box Product, Limited Availability, No Back Orders)

(more details)
This 2TB server is a cost-effective way to add reliable, secure rack-mount storage to your network. It provides advanced RAID and print capabilities to store, share, protect and backup your data. (desktop computer accessories, MacMall)

Linux Proc Celeron 450r 1g Hd 80g

(more details)
30-Day Money-Back Satisfaction Guarantee! (computer processor upgrades, Tech for Less)

HP/Compaq nc6120 Pentium M 750 1.86GHz 512MB 40GB CDRW/DVD 15'' Ubuntu Linux

(more details)
HP Compaq nc6120 Pentium M 1.86 GHz 15-inch Notebook General Features: Black color Ubuntu Linux 8.04 Hardy Heron pre-installed Intel Pentium M 750 1.86 GHz processor 512 MB RAM 40 GB hard drive CDRW/DVD drive Mobile Intel 915GM graphics Integrated... (Geeks.com, laptop computers)

Related Articles

Related Questions

Comments