Re: Re: Red Hat, IPOP, Security, and an aside on egress filtering

[email protected]
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
On Thu, 25 Sep 2003 Richard.Corfield.Admin-XZoyATsUNX5Wk0Htik3J/[email protected] wrote:

> It would seem that each system is most friendly towards those that
> know it. One of the first place I looked on the system for network
> interface settings was /etc/network, following Debian. I didn't notice
> /etc/sysconfig. I didn't know the chkconfig command. I expect a Red Hat
> user would not know dpkg --reconfigure.

Depends whether I'd read the Debian documentation recently. ;-)

Red Hat do produce rather good documentation for their distro, supplemented
by third party books and so forth. Also, their RHCE course is well-regarded,
even by at least one Debian afficionado of my acquaintance.

[snip]

> I'd like to suggest to Red Hat that their firewall blocks above 1024
> too.

The /etc/sysconfig/iptables file I have here from a RH8 install indicates
that all inbound SYNs are REJECTed. Not DROPped, admittedly, but it's a
minor detail.

> I was also informed that root on the box was emailed to say I'd
> remote logged in as root on ssh, so it seems to be running some form
> of log watch, though having got in as root was it too late? I remember
> the old recomendation of doing net logging to a very secure machine to
> prevent tampering, even net logging to a non existant address (its UDP
> if I remember correctly)

Logging to a central syslog server is a good practice for any organisation
with many hosts. There are event NT event log-to-syslog packages out there.

> and having a passive sniffer without its own
> IP address picking up the log packets. I digress

A network IDS, essentially. Again, a useful part of the armoury.

>  - Richard

Best Regards,
Alex.
-- 
Alex Butcher      Brainbench MVP for Internet Security: www.brainbench.com
Bristol, UK                      Need reliable and secure network systems?
PGP/GnuPG ID:0x271fd950                         <http://www.assursys.com/>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.