Re: AW: Secure Linux From Scratch

Robert Day <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Fri, 2003-12-19 at 05:56, quinte wrote:
> >Let's get this ball rolling people...  I love the idea, and I can tell
> >there are many who would agree with me.
> 
> >   Rob Day (BOFH)
> 
> agreed ;)
> 
> anathor questions wich could upcome at a later point:
> how do we ensure quality? (stress tests, security tests like "hacking" into
> the machine?)
> 
> i dont know anything about security (yet) but i want to test it out and get
> better ;)
> 

All of the above.  Of course, we cannot guarantee any system built on
LFS is secure...  No matter how much work we as a team put into it... 
The end user ultimately decides what to follow and where to deviate. And
even with a "followed the book to the letter" install..  By the time the
user gets it installed, an exploit may have been found that exploits a
package the user installed from the book, that was not there when that
user downloaded the book.

But, ensuring the kernel, libraries and all applications are secured
against all known threats, and that a sufficient firewall is in place at
the local level, that there is no room for privelage escalation via
buffer oferflows, stack manipulation, and what not, and testing the
machine with as many tools as we can get our greedy paws on <G> will
ensure that "this book, as of release date x.x.xxxx was secure against
all known threats as of that date." Of course, there will likely be more
than one place where "your mileage may vary" and "new exploits are being
discovered daily, monitor XXXX list and the errata pages at
linuxfromscratch.org/somepagehere" and "we cannot guarantee that any
system based off SLFS is secure against all threats. There may be new,
or unknown threats we cannot possibly protect systems against" warnings
are posted in the book...  Best we can do is minimise the chances of the
system being exploited, and test the hell out of it...  anyone with any
skills, and even some without skills, can test a box..  run security
scanners on it, attempt to hack it, locally and remotely, try to gain
elevated privelages, etc. etc.   All we can do is our best ;) 

  Rob Day (BOFH)

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.