Re: Linux Hardening
Liran Cohen <[email protected]> Sun, 21 Oct 2007 13:32:18 +0200
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <[email protected]> |
I completely agree providing you have the time and dont have a couple of dozens of Linux machines to maintain daily, in many cases you have to make a sensible choice what would be worth more or in other words asses where the risk is higher and invest most of your efforts there. Ajai Khattri wrote: > On Wed, 17 Oct 2007, Liran Cohen wrote: > > >> what is the machine's location on your network (LAN\DMZ etc...) what is >> the machine role, you should ask yourself some questions before >> approaching hardening, I would not put the same effort on a machine >> which is located on my LAN as much as I would make sure that DMZ >> machines are protected >> > > I believe even machines on internal networks should all run local > firewalls at the very least. There's always some Windoze user using > Outlook and clicking on an email attachment they shouldn't click on... > > > -- Liran Cohen http://www.rct.co.il http://www.dir.rct.co.il