Re: Securing Fedora Core 4
Scott Rippee <[email protected]>
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <[email protected]> |
I agree with this completely and after a few years of not taking this approach have had to many headaches to count. Within a few weeks I will have my web services moved to a dedicated computer with no internal privileges and be able to sleep a little better at night. :) On Sun, Sep 25, 2005 at 01:44:16AM +0100, Glynn Clements wrote: > > AragonX wrote: > > > Well, the offices that I will be setting up are rather small and I can't > > convince them to separate the services to multiple machines. > > > > So basically, the servers will have to do everything. Email, web, > > firewall, gateway, file & print. Those are the tasks it will have to > > perform. > > > Email and web are the services that will be available to the Internet. > > The public web server should definitely be a separate box, especially > if it has any kind of CGI or scripting capability (i.e. mod_cgi, > mod_perl, mod_php etc), and it shouldn't be given any trust (i.e. any > firewall rules or access lists which distinguish between "internal" > and "external" systems should treat the web server as external). > > Rule #1 of running a web server: assume that it is going to get > compromised occasionally. Obviously, you try to prevent that, but > don't assume that you will be entirely successful. > > -- > Glynn Clements <[email protected]> -- Scott Rippee [email protected] http://www.hypexr.org