Check List For Linux Security
Check List for Linux Security
Linux is an amazing operating system considering how it was originally created. It was a modest program written for one person as a hobby – Linus Torvald of Finland. It has grown into a full-fledge 32-bit operating system. It is solid, stable and provides support for an incredible number of applications. It has very powerful capabilities and runs very fast and rarely crashes.
Unfortunately Linux machines are broken almost every day. This happens not because it is an insecure operating system. It contains all the necessary tools to make it very secure. But the truth is. It hasn’t become significantly more secure with the increase in popularity. On the other hand, our understanding of the hackers methods and the wide variety of tools and techniques available contributed to help system administrators to secure their Linux computers.
Our goal in this article is to list the most critical situations, and how to prevent an invasion with simple measures.
1- Weak passwords – By far the first and most used method used by hackers to try penetrating a Linux system is cracking a password, preferently of the user root. Usually they will target a common user first, and then, using his/her access to the operating system, try to get a privileged access cracking the root password. Good password policy, and good passwords are absolutely critical to the security on any computer. Some common mistakes when selecting a password:
A- use “password” as password.
B- use the name of the computer.
C- a well-know name from science, sports or politics.
D- reference to movies.
E- anything that is part of the user web site.
F– references associated with the account.
The latest version of Linux offer shadowed passwords. If a cracker can see an encrypted password, crack it would a simple task. So, instead of storing the password in the passwd file, they are now stored in the shadow file which is readable only for root. Before a hacker can crack a password he needs to figure out an account name. So, simple accounts names must be avoided as well. Another security measure is to apply a “no login” to the account in the passwd file. This must be done to all the accounts that don’t need to log in to the system. Examples are: apache, mysql, ftp and other.
Limit which terminals root may log in from. If the root account is allowed to log in only in certain terminals that are considered secure, it will be almost impossible for a hacker to penetrate the system. This can be done listing the allowed terminals on /etc/security. The login program will consider insecure any terminal that is not listed on this file, which is readable, only by root.
2- Open Network Ports
Any Linux default installation will provide the Operating System with tons of software and services. Several of them are not necessary or even wanted by the administrator. Removing these software and services will close the path to several attacks and improve security. The /sbin/chkconfig program can be used to stop services from automatically starting at run levels 3, 4 and 5. Log in as root and type /sbin/chkconfig --list to view all the services set to start automatically. Select the ones you don’t need and type /sbin/chkconfig 345 name_of_service off. You must do that to all services you don’t want to keep running. Also, the xinetd server can be used to disable other services as well.
3- Old Software Versions
Everyday vulnerabilities are found in programs, and most of them are fixed constantly. It is important, and sometimes critical, to keep up with the changes. There are mailing lists for every Linux distribution where one can have security related information’s, and the latest vulnerabilities found.
Some place to watch for security holes are:
· http://www.redhat.com/mailman/listinfo/redhat-announce-list
· http://www.debian.org/MailingLists/
· http://www.mandrakesecure.net/en/mlist.php
· http://www.suse.com/us/private/support/security/index.html
· http://www.freebsd.org/security/index.html
· http://www.linuxtoday.com/
· http://www.lwn.net/
It is crucial to insure that the security released patches are applied to the programs as soon as they area available. The hacker community will be aware of the discovered holes and will try to explore them before the fixes are applied.
4- Insecure and Badly Configured Programs
There are some programs that have a history of security problems. To name a few IMAP, POP, FTP, port map and NFS, are the most known. The good thing is that most of these programs can be replaced by a secure version like spop, sftp or scp.
It is important that, before deploying any service, the administrator investigate its security history. Sometimes simple configuration measures can prevent serious headaches in the future.
Some advices regarding a web server configuration are well worth to mention:
- Never run the web server as a privileged user;
- Do not keep clients’ confidential data on the web server – Credit card numbers, phone numbers, mailing addresses, must be recorded on a different machine.
- Make sure the privileged data that a user supplies on a form does not show up as a default for the next person to use the form; - Establish acceptable values for data that is supplied by web clients. - Check vulnerabilities on CGI programs.
5- Stale and Unnecessary Accounts
When a user no longer uses his /her account, make sure it is removed from the system. This stale account won’t have this password changed periodically leaving a hole. Publicly readable or writable files owned by that account must be removed. When you remove an unnecessary service make sure you remove or disable the correspondent account.
Security Resources in the web
Bugtraq – Includes detailed discussions of Unix security holes
http://www.securityfocus.com/
Firewalls – Discuss the design, construction, operation, and maintenance of firewall systems.
http://www.isc.org/services/public/lists/firewalls.html
RISKS Discuss risks to society from computers
http://www.risks.org/
Insecure.org
http://www.insecure.org/
By: Jair
Related Products
GRI 289-1, Recessed Door Alert/Pool Alarm, 7-Second Delay, ETL Listed
(more details)GRI 289-3, Recessed Door Alert/Pool Alarm, Instant On, ETL Listed
(more details)GRI 289-4, Surface Mount Door Alert/Pool Alarm, Instant On, ETL Listed
(more details)Honeywell HP300ULX, UL Listed Power Supply, 12 VDC/24 VDC, 2.5A
(more details)Honeywell HP400ULX, UL Listed Power Supply, 12 VDC/24 VDC, 4.0A
(more details)Linear UL Listed Wireless 2-Channel Receiver/CO Detector
(more details)Honeywell HP600ULX, UL Listed Power Supply, 12 VDC/24 VDC, 6.0A
(more details)SBR Javascripting Module - Linux Single 1 appliance
(more details)Musical Checking His List Water Globe
(more details)Musical Checking His List Water Globe
(more details)Musical Checking His List Water Globe
(more details)Checking His List Stocking
(more details)Samsung TAD137JSEB Premium OEM Travel Charger for Samsung Cell Phone (check compatibility list)
(more details)DOOR ANCHOR STRAP by FIT CORD for Resistance Band and Exercise Tube Workouts (PLEASE CHECK OUR OTHER LISTINGS FOR SAFETY SLEEVE FIT CORDS THAT INCLUDE DOOR ANCHOR.)
(more details)1981 Fleer Star Baseball Complete Set of 125 Sticker Cards Plus Check Lists Includes Many Stars - Garvey, Schmidt, Yastrzemski, Stargell, Winfield, Niekro, Rivers, Bench, Yount, Carew Rose, Foster, Seaver Rice Fisk, Griffey and Many Others
(more details)Check ME Notepad - Grocery List Planner
(more details)Check List and Record Book of United States and Canadian Coins (Official Red Books)
(more details)Dick's Farm Toy Price Guide and Check List 1/32 & 1/16 Tractors and Machinery 1886-1992
(more details)Hewlett Packard Commercial PCs HP SmartBuy dc5850 SFF Phenom X3 8600B 2.3GHz/1.5MBL2/3GB/320GB/SuperMulti/GigNIC/Linux
(more details)REFURBISHED - HP Compaq FW905UP t5735 Thin Client - AMD 2100+ Sempron 1 GHz Processor - 1 GB Flash Memory/512 GB RAM - 0 GB Hard Drive - Debian Linux 4.0
(more details)Hewlett Packard Commercial PCs HP SmartBuy dc5850 SFF Phenom X3 8600B 2.3GHz/1.5MBL2/3GB/320GB/SuperMulti/GigNIC/Linux
(more details)Iomega StorCenter Pro NAS 200rL Server 2TB Linux (Open Box Product, Limited Availability, No Back Orders)
(more details)Linux Proc Celeron 450r 1g Hd 80g
(more details)OPEN BOX - HP Compaq Thin Client t5735 - Tower - 1 x Sempron 2100+ / 1 GHz - RAM 1 GB - no HDD - Radeon X1250 - Gigabit Ethernet - Debian Linux 4.0 - Monitor : none
(more details)HP/Compaq nc6120 Pentium M 750 1.86GHz 512MB 40GB CDRW/DVD 15'' Ubuntu Linux
(more details)Related Articles
- Linux Freely Available ?linux Free ? Confused Enough ?
Many new Linux users are confused by the terms bantered around – Free, Freely Available, Commercial Distributions and Shareware. The confusion comes primarily from the description and terms - “think You Might Need A Doctor’s Appointment? Make A List, Check It Twice!”
No, we’re not talking about Santa Claus, we’re talking about you and your doctor’s appointment. Making lists is the most important activity you can perform BEFORE you go to your appointment. - Camping Guide, A Full Camping Trip Check List
When people take a camping trip the number one thing that causes things to go wrong is the lack of planning that people put in before their trip. This is the number one reason for a lot of people's - Bathroom Remodeling Check List
Bathroom remodeling is the best way, after kitchen remodeling, to increase the sales value of your home. It can be a small bathroom remodel or a large one, but either one done correctly can garner a - 12 Essential Tips To Add To Your Moving Check List
Moving means umpteen things to be done –it is not about just putting things into boxes, taking them to another place, and unpacking there. The more complicated our lives get the more the things to - Check Your Hunting And Camping Supply List Carefully Before You Head Out
Once you arrive at your destination for your hunting or camping trip you will be pretty much cut off from civilization, so it is very wise to make a list of everything that you will need before you - Double Check Your Hunting and Fishing Supply List Before You Head Out
If you are preparing for an excursion into the great outdoors to do some hunting or fishing then one wise move would be to make a check list of everything that you will be needing before you leave. - Driving School Check List: Are You Getting Ripped Off?
I’ve got a confession to make. Sometimes, I drive to fast and I speed. I’ve done it before and I’ll probably do it again. And guess what? I’ve gotten speeding tickets. If you think that I’ - 10 Major Reasons To Switch To Linux
1. It Doesn't Crash Linux has been time-proven to be a reliable operating system. Although the desktop is not a new place for Linux, most Linux-based systems have been used as servers and embedd - Where To Learn How To Setup A Linux Email Server
Learning how to setup a linux email server is valuable. The more you can do for yourself for your business’ web presence and email abilities the more money you will save. There will be no need to - Linux Or Windows - Which Is It?
Computer users and programmers have become so accustomed to using Windows, even for the changing capabilities and the appearances of the graphical interface of the versions, therefore it has remaine - My Google Wish List
There are a number of "wishes" that I have for Google's future. While I would like number one ranking for all of my important keywords and phrases, but I would be willing to settle for Google acknow - It Marketing: Finding Prospect Lists
After you write your long sales letter, you need to know who to send it to. In this article, you'll learn where to find an advertising list and trade organization listings to help with your IT marke - Notebook Faq: Checking Out Notebook Computers
* What is a notebook? A notebook is a lightweight, compact, portable computer, a little smaller than a laptop. However, they have the same features as laptops, like battery pack, disk drives and - Checking Computer Security
Many people wonder whether or not their computer is secure. They fear that someone might be looking through their files, copying, altering, or erasing them. They are uneasy about the thought that so - Checking To See If You Have Wireless Capability
Do you know if your new computer already has wireless capability? Many new computers have the built-in software and connections in order for you to set up a wireless network. These wireless networki - What You Should Check Before Buying Wireless Equipment
When you buy wireless equipment, you want to make sure that everything you buy will work in your house with the computer(s) you already have and over the distances required. Before you spend any mon - Latest Inventions! Check Out These New Gizmos And Gadgets!
The Newest Gizmos and Gadgets on the Market: Ingenuity and technological advances are constantly resulting in new gizmos and gadgets. Gadgets can be both fun and functional and can save the owne - Save Thousands By Listing Your Home On Flat Fee Mls Listing
Selling your home on your own can save you a lot of money, and yet most people still use a realtor. One reason is that realtors actually do have access to marketing tools you don’t generally have. - Getting Your Home Listed On The Multiple Listing Service
Getting your home listed on the multiple listing service (MLS) used by realtors all over the country, you are gaining access to thousands of realtors, brokers, and thus their customers who are ready - List-building: Where The Heck Do I Start To Build My List?
Are you trying to figure out where to start getting a list, how to get going? You may be so overwhelmed with all of the training and all of the different how-to’s out there that you're wondering, - List-building: Start With Your Passion; The List Will Follow
People new to Internet Marketing often ask me, "What’s the best way to start in Internet marketing?" I’m going to tell you a story about myself as a case study. When I started, I had no - Helmet, Check - Breastplate, Check - Sword, Check - Love?
As a young kid in junior high, the behavior of one of my friend's insane uncles fascinated me. The old man visited at unexpected times, totally unconcerned with how unwelcome he was. Explaining his - Keeping Accurate Time on Linux - Running a NTP Time Server
Linux operating systems are becoming increasingly popular partly due to the many advantages they have over commercial systems like Windows or OS X. Linux offers increased security (as there are only - Check Scams - When Can You Be Sure A Check Is Actually Good?
Protecting yourself from scams is becoming increasingly harder since credit theft is on the rise in the nation. Thieves steal more than your possessions. They now steal your identity, credit cards,
Related Questions
- How do you list mountable usb devices on linux from terminal?
- Traveling Check List for residential school?
- Can you help me with wedding check list?
- Going camping and I want to make a check list.?
- Christmas Trivia-The following is a list of trivia questions. Write your answers down, and check them?
- My project hatch.... check list... good idea bad idea??
- Wedding day check list ?
- Can you list important checks before pouring, after pouring concrete in columns, beams and slab?
- I wanting to do a check list for camping?
- Camping check list!!?
- check list?
- Where can I study a comptia linux+ certification in Toronto or surrounding area ?
- How do I network a Suse installed machine with other computers, specifically Red hat Linux?
- Who is the best training provider for RHCE/RHCT (LINUX) in INDIA?
- Ebooks which are related to linux administration and RHCE ,where i find ?
- hi all I am RHCE certified. iam looking for linux base job . iam fresher. what should i do. ?
- RHCE( LINUX) ,fresher salary?
- How do I stop my computer from freezing during PCI Service Listing?
- I set up a wireless network and now it is showing up with multiple listings?
- What is security clearance in the Military and what do they check?
- Linux Guide To Linux Certification?
- To Unix-linux support engineers, if you have 2 study a certification, would you study Solaris or Linux and why
- How to invoke the Linux Terminal in LINUX when a process becomes unresponsive?
- What is the difference between Yellow Dog Linux 6 Mirror and just Yellow Dog Linux 6?
- How do I create a bootable Linux CD from a bootable magazine DVD with Linux on it and other things?






