Re: Red Hat, IPOP, Security, and an aside on egress filtering
Richard.Corfield.Admin-XZoyATsUNX5Wk0Htik3J/[email protected]
| Newsgroups | gmane.linux.usability.annoyances |
|---|---|
| Message-ID | <[email protected]> |
It would seem that each system is most friendly towards those that know it. One of the first place I looked on the system for network interface settings was /etc/network, following Debian. I didn't notice /etc/sysconfig. I didn't know the chkconfig command. I expect a Red Hat user would not know dpkg --reconfigure. Different distros have chosen different techniques, both an advantage of Open Source, and something that annoys business (but its not all about pleasing businesses IMHO). I'd like to suggest to Red Hat that their firewall blocks above 1024 too. I was also informed that root on the box was emailed to say I'd remote logged in as root on ssh, so it seems to be running some form of log watch, though having got in as root was it too late? I remember the old recomendation of doing net logging to a very secure machine to prevent tampering, even net logging to a non existant address (its UDP if I remember correctly) and having a passive sniffer without its own IP address picking up the log packets. I digress Another post mentions egress filtering for spoofed addresses. Linux has, for a long time, offered a block spoofed addresses feature. If one of my machines sent a packet claiming to be from anything other from 192.168.0 then it will be dropped, because the system knows that only 192.168.0 can be routed on that interface. It all gets NATed on the way out anyway. I'll add egress though for all but NTL's proxy, POP, SMTP, NNTP and FTP. - Richard -- _/_/_/ _/_/_/ _/_/_/ Richard dot Corfield at ntlworld dot com _/ _/ _/ _/ Fortune Cookie: This file will self-destruct _/_/ _/ _/ in five minutes. _/ _/ _/_/ _/_/_/