5 msgDSA/DSS keys and DSA 1576-1/CVE-2008-0166.
2 msgopenssl/openssh fixes for lenny (testing)
2 msgopenssl / x509 certs
2 msgleakage of keys?
2 msgdowkd.pl - how the blacklist data is generated ?
8 msgRe: [SECURITY] [DSA 1576-1] New openssh package...
4 msgdowkd.pl via Package
1 msgCHAO BAN
32 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
4 msgBroken link on Debian CVE Web page (Was: [SECUR...
10 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
3 msgRe: [SECURITY] [DSA 1575-1] New Linux 2.6.18 pa...
1 msgMystery of Lyle & Louise is Making Headlines
1 msgHerr Bühler Arbeite nicht mehr bei der V-ZUG AG
5 msgRe: [SECURITY] [DSA 1573-1] New php5 packages f...
4 msgRe: [SECURITY] [DSA 1572-1] New php5 packages f...
3 msgQuestion about Security

securing server
\ Jean-Paul Lacquement (7 May 2008)
. \ Yves-Alexis Perez (7 May 2008)
. . \ Jean-Paul Lacquement (7 May 2008)
. . . \ Abdul Bijur Vallarkodath (7 May 2008)
. . . . \ Steve (7 May 2008)
. . . . . \ Arture Le Coiffeur (7 May 2008)
. . . . . \ Abdul Bijur Vallarkodath (7 May 2008)
. . . . . . \ Steve (7 May 2008)
. . . . . . \ Harry Jackson (7 May 2008)
. . . . . . \ Daniel Leidert (7 May 2008)
. . . . . \ Bernd Eckenfels (7 May 2008)
. . . . \ Oliver Antwerpen (7 May 2008)
. . . . . \ Rich Healey (13 May 2008)
. \ weakish (7 May 2008)
. . \ martin f krafft (7 May 2008)
. \ Bernd Eckenfels (7 May 2008)
. . \ Jean-Paul Lacquement (7 May 2008)
. . . \ Julien Gormotte (7 May 2008)
. . . \ Maik Holtkamp (8 May 2008)
. \ Brent Clark (7 May 2008)
. \ Holger Wesser (7 May 2008)
. \ Stephen Vaughan (7 May 2008)
. \ Alex Mestiashvili (7 May 2008)
. . \ Alex Mestiashvili (7 May 2008)
. \ Ticlea Petru Alexandru (7 May 2008)
. \ Simon Brandmair (7 May 2008)
. . \ martin f krafft (7 May 2008)
. \ Simon Valiquette (7 May 2008)
. \ Onno Gabriel (7 May 2008)
. \ P PRABHU (8 May 2008)
. . \ Rich Healey (13 May 2008)
. \ Bjørn Mork (8 May 2008)
. \ phobot (9 May 2008)
. . \ Noah Meyerhans (9 May 2008)
. . . \ weakish (9 May 2008)
. . \ Johannes Graumann (9 May 2008)
. \ Simon Brandmair (9 May 2008)

1 msgRe: [SECURITY] [DSA 1570-1] New kazehakase pack...
2 msgRe: [SECURITY] [DSA 1569-1] New cacti packages ...
Subject:Re: securing server
Group:Debian-security
From:Julien Gormotte
Date:7 May 2008


 
Le Wed, 7 May 2008 13:03:03 +0200,
"Jean-Paul Lacquement" <zelos414> a écrit :

> > > I already did the followings:
> > > - installed chkrootkit
> > > - installed fail2ban (for ssh and proftpd)
> >
> > Beware of DOS.
> >
> >
> > > - allow only one user (not root) via /etc/ssh/sshd_config, only
> > > ssh v2
> >
> > If you have multiple administrators, you should not do that.
>
> I am the only one.
> >
> >
> > > Would you please list me which packages to install and which
> > > rules to apply ?
> >
> > There are some hardening packages to look for. Beside that you
> > should review all running processes and turn those off which you
> > dont need (X11 related, rpc, hotplug stuff, etc)
>
> Ok. I'll disable them
>
> >
> > Besides that, what applications you plan to run?
>
> This server will only run proftpd, ssh, apache, nagios(via http),
> samba and cups

Nagios via https could be a good idea. Same for apache, if you can. You
can set RewriteRules that will redirect http connections to https.

For security of ssh, if you plan to access the server via a limited
number of machines, you can consider using port knocking.

>
> >
> > Gruss
> > Bernd
>
> Jean-Paul
>
>


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com