5 msgDSA/DSS keys and DSA 1576-1/CVE-2008-0166.
2 msgopenssl/openssh fixes for lenny (testing)
2 msgopenssl / x509 certs
2 msgleakage of keys?
2 msgdowkd.pl - how the blacklist data is generated ?
8 msgRe: [SECURITY] [DSA 1576-1] New openssh package...
4 msgdowkd.pl via Package
1 msgCHAO BAN
32 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
4 msgBroken link on Debian CVE Web page (Was: [SECUR...
10 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
3 msgRe: [SECURITY] [DSA 1575-1] New Linux 2.6.18 pa...
1 msgMystery of Lyle & Louise is Making Headlines
1 msgHerr Bühler Arbeite nicht mehr bei der V-ZUG AG
5 msgRe: [SECURITY] [DSA 1573-1] New php5 packages f...
4 msgRe: [SECURITY] [DSA 1572-1] New php5 packages f...
3 msgQuestion about Security

securing server
\ Jean-Paul Lacquement (7 May 2008)
. \ Yves-Alexis Perez (7 May 2008)
. . \ Jean-Paul Lacquement (7 May 2008)
. . . \ Abdul Bijur Vallarkodath (7 May 2008)
. . . . \ Steve (7 May 2008)
. . . . . \ Arture Le Coiffeur (7 May 2008)
. . . . . \ Abdul Bijur Vallarkodath (7 May 2008)
. . . . . . \ Steve (7 May 2008)
. . . . . . \ Harry Jackson (7 May 2008)
. . . . . . \ Daniel Leidert (7 May 2008)
. . . . . \ Bernd Eckenfels (7 May 2008)
. . . . \ Oliver Antwerpen (7 May 2008)
. . . . . \ Rich Healey (13 May 2008)
. \ weakish (7 May 2008)
. . \ martin f krafft (7 May 2008)
. \ Bernd Eckenfels (7 May 2008)
. . \ Jean-Paul Lacquement (7 May 2008)
. . . \ Julien Gormotte (7 May 2008)
. . . \ Maik Holtkamp (8 May 2008)
. \ Brent Clark (7 May 2008)
. \ Holger Wesser (7 May 2008)
. \ Stephen Vaughan (7 May 2008)
. \ Alex Mestiashvili (7 May 2008)
. . \ Alex Mestiashvili (7 May 2008)
. \ Ticlea Petru Alexandru (7 May 2008)
. \ Simon Brandmair (7 May 2008)
. . \ martin f krafft (7 May 2008)
. \ Simon Valiquette (7 May 2008)
. \ Onno Gabriel (7 May 2008)
. \ P PRABHU (8 May 2008)
. . \ Rich Healey (13 May 2008)
. \ Bjørn Mork (8 May 2008)
. \ phobot (9 May 2008)
. . \ Noah Meyerhans (9 May 2008)
. . . \ weakish (9 May 2008)
. . \ Johannes Graumann (9 May 2008)
. \ Simon Brandmair (9 May 2008)

1 msgRe: [SECURITY] [DSA 1570-1] New kazehakase pack...
2 msgRe: [SECURITY] [DSA 1569-1] New cacti packages ...
Subject:Re: securing server
Group:Debian-security
From:Arture Le Coiffeur
Date:7 May 2008


 
On Wednesday, 2008-05-07 at 12:47:37 +0200, Steve wrote:
> Le 07-05-2008, à 17:34:08 +0800, Abdul Bijur Vallarkodath (abdulbijur) a écrit :

> > just my two pence.

> and my two centimes.

> > * Change the ports of most ports like ssh, ftp, smtp, imap etc. from the
> > default ones to some other ones.

> >From my poor understanding of security related issues, I guess this is
> totally useless since any (good) port scanner will defeat this without
> any problem. Remember, security by obscurity is a bad idea.

"Security by Obscurity" refers to the attempt to protect a (usually
bad) crypto-algorithm by hiding it from review. This is called "Evasive
Maneuvers". The usual black hat scans will only look for services on
the standard ports as long as they find sufficient vulnerable machines
using those standard ports.

It will add a little security because the non-standard ports will only be
detected by an unsual scan, i.e. looking for SSH on ports 1..65535. This
takes so much longer than testing just port 22 that it will only be used
by somebody explicitly targeting the system in question.

Thus a whole class of attackers is eliminated. This means a
significantly smaller attack surface.

The more users a systems has, though, the more you will have that are
not capable of dealing with changed ports. Or who have software that
can't deal with changed ports...

Lupe Christoph
--
| The whole aim of practical politics is to keep the populace alarmed |
| (and hence clamorous to be led to safety) by menacing it with an |
| endless series of hobgoblins, all of them imaginary. |
| H. L. Mencken, "In Defense of Women", 1918 |


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com