Re: Secure Linux From Scratch
Miguel Bazdresch <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
* Archaic <[email protected]> [03-1212 11:52]: > Okay, if it's going to become a reality we need to start formulating a > plan of attack. The first one I would consider is book goals and > format/layout. My own suggestions follow. I see two big slices in the security pie: 1. Packages stuff - patches, compilation options, etc. 2. Practices - how to do things. Furthermore, these can be subdivided according to the use of the system: server, workstation, firewall, etc. For illustration let me show you a hypothetical "Package" chapter: Title: Patching the kernel against stack attacks Explanation: stack attack means such and such and are exploited like this. Priority: this patch is especially crucial for servers because this and that. WS are vulnerable but you lose x and y functionality, so you have to compromise. And a "Practice" chapter: Title: networking clients (chat, irc) Explanation: any app that listens to the net is vulnerable to attack etc etc. Priority: all WS should follow this practices. What to do: create unprivileged users like this etc etc. Alternative: run net apps in an isolated machine and use X forwarding which in turn has the following risks: etc. I think covering both aspects in necessary and gives maximum security. What good is it to lock down the kernel if then you go and run xmule as root? (an extreme example to illustrate my point). This is the kind of book I'd like to read - and this is the kind of book that I don't think exists today. -- Miguel Bazdresch http://thewizardstower.org/ -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page