Re: Secure Linux From Scratch

Miguel Bazdresch <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
* Archaic <[email protected]> [03-1212 11:52]:
> Okay, if it's going to become a reality we need to start formulating a
> plan of attack. The first one I would consider is book goals and
> format/layout.

My own suggestions follow. I see two big slices in the security pie:

1. Packages stuff - patches, compilation options, etc.

2. Practices - how to do things.

Furthermore, these can be subdivided according to the use of the
system: server, workstation, firewall, etc.

For illustration let me show you a hypothetical "Package" chapter:

  Title: Patching the kernel against stack attacks

    Explanation: stack attack means such and such and are exploited
    like this.

   Priority: this patch is especially crucial for servers because this
   and that. WS are vulnerable but you lose x and y functionality, so
   you have to compromise.

And a "Practice" chapter:

  Title: networking clients (chat, irc)

  Explanation: any app that listens to the net is vulnerable to
  attack etc etc.

  Priority: all WS should follow this practices.

  What to do: create unprivileged users like this etc etc.

  Alternative: run net apps in an isolated machine and use X
  forwarding which in turn has the following risks: etc.

I think covering both aspects in necessary and gives maximum
security. What good is it to lock down the kernel if then you go and
run xmule as root? (an extreme example to illustrate my point).

This is the kind of book I'd like to read - and this is the kind of
book that I don't think exists today.

-- 
Miguel Bazdresch
http://thewizardstower.org/
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.