Re: Linux hardening
Norwich University - Information Security <[email protected]>
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Organization | Norwich University |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Since we're talking about Linux hardening...
What do folks suggest as far as files that should be monitored with
integrity checking tools? Obviously, tmp files and other frequently
changed files are out of the question, and it is also impractical to do
checking on all other files. Does anyone have a best practices list or
suggestions of what files are critical to monitor with integrity checking?
/etc/passwd
/etc/shadow
/etc/group
/etc/pam.d/*
/var/www/<static web pages>
/etc/ssh/sshd_config
???
- --
@XXXXXX{========================>
Jason Wallace
Chief Information Security Officer
Norwich University
http://www.norwich.edu
"If you spend more on coffee than on information security,
then you will be hacked. What's more, you deserve to be hacked."
-Richard Clarke
Special Advisor to the President on Cybersecurity
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
iD8DBQFDC1clpmEqH5sLlmsRAhfcAJ9CLSqy5z+8c1EwCY0ZynQ5bpHkhACdGGiC
kBHohXrHJSQ/W23vXyV5R/o=
=B43u
-----END PGP SIGNATURE-----