Re: AW: Secure Linux From Scratch
Robert Day <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 2003-12-19 at 05:56, quinte wrote: > >Let's get this ball rolling people... I love the idea, and I can tell > >there are many who would agree with me. > > > Rob Day (BOFH) > > agreed ;) > > anathor questions wich could upcome at a later point: > how do we ensure quality? (stress tests, security tests like "hacking" into > the machine?) > > i dont know anything about security (yet) but i want to test it out and get > better ;) > All of the above. Of course, we cannot guarantee any system built on LFS is secure... No matter how much work we as a team put into it... The end user ultimately decides what to follow and where to deviate. And even with a "followed the book to the letter" install.. By the time the user gets it installed, an exploit may have been found that exploits a package the user installed from the book, that was not there when that user downloaded the book. But, ensuring the kernel, libraries and all applications are secured against all known threats, and that a sufficient firewall is in place at the local level, that there is no room for privelage escalation via buffer oferflows, stack manipulation, and what not, and testing the machine with as many tools as we can get our greedy paws on <G> will ensure that "this book, as of release date x.x.xxxx was secure against all known threats as of that date." Of course, there will likely be more than one place where "your mileage may vary" and "new exploits are being discovered daily, monitor XXXX list and the errata pages at linuxfromscratch.org/somepagehere" and "we cannot guarantee that any system based off SLFS is secure against all threats. There may be new, or unknown threats we cannot possibly protect systems against" warnings are posted in the book... Best we can do is minimise the chances of the system being exploited, and test the hell out of it... anyone with any skills, and even some without skills, can test a box.. run security scanners on it, attempt to hack it, locally and remotely, try to gain elevated privelages, etc. etc. All we can do is our best ;) Rob Day (BOFH) -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page