5 msgDSA/DSS keys and DSA 1576-1/CVE-2008-0166.
2 msgopenssl/openssh fixes for lenny (testing)
2 msgopenssl / x509 certs
2 msgleakage of keys?
2 msgdowkd.pl - how the blacklist data is generated ?
8 msgRe: [SECURITY] [DSA 1576-1] New openssh package...
4 msgdowkd.pl via Package
1 msgCHAO BAN
32 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
4 msgBroken link on Debian CVE Web page (Was: [SECUR...
10 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
3 msgRe: [SECURITY] [DSA 1575-1] New Linux 2.6.18 pa...
1 msgMystery of Lyle & Louise is Making Headlines
1 msgHerr Bühler Arbeite nicht mehr bei der V-ZUG AG
5 msgRe: [SECURITY] [DSA 1573-1] New php5 packages f...
4 msgRe: [SECURITY] [DSA 1572-1] New php5 packages f...
3 msgQuestion about Security

securing server
\ Jean-Paul Lacquement (7 May 2008)
. \ Yves-Alexis Perez (7 May 2008)
. . \ Jean-Paul Lacquement (7 May 2008)
. . . \ Abdul Bijur Vallarkodath (7 May 2008)
. . . . \ Steve (7 May 2008)
. . . . . \ Arture Le Coiffeur (7 May 2008)
. . . . . \ Abdul Bijur Vallarkodath (7 May 2008)
. . . . . . \ Steve (7 May 2008)
. . . . . . \ Harry Jackson (7 May 2008)
. . . . . . \ Daniel Leidert (7 May 2008)
. . . . . \ Bernd Eckenfels (7 May 2008)
. . . . \ Oliver Antwerpen (7 May 2008)
. . . . . \ Rich Healey (13 May 2008)
. \ weakish (7 May 2008)
. . \ martin f krafft (7 May 2008)
. \ Bernd Eckenfels (7 May 2008)
. . \ Jean-Paul Lacquement (7 May 2008)
. . . \ Julien Gormotte (7 May 2008)
. . . \ Maik Holtkamp (8 May 2008)
. \ Brent Clark (7 May 2008)
. \ Holger Wesser (7 May 2008)
. \ Stephen Vaughan (7 May 2008)
. \ Alex Mestiashvili (7 May 2008)
. . \ Alex Mestiashvili (7 May 2008)
. \ Ticlea Petru Alexandru (7 May 2008)
. \ Simon Brandmair (7 May 2008)
. . \ martin f krafft (7 May 2008)
. \ Simon Valiquette (7 May 2008)
. \ Onno Gabriel (7 May 2008)
. \ P PRABHU (8 May 2008)
. . \ Rich Healey (13 May 2008)
. \ Bjørn Mork (8 May 2008)
. \ phobot (9 May 2008)
. . \ Noah Meyerhans (9 May 2008)
. . . \ weakish (9 May 2008)
. . \ Johannes Graumann (9 May 2008)
. \ Simon Brandmair (9 May 2008)

1 msgRe: [SECURITY] [DSA 1570-1] New kazehakase pack...
2 msgRe: [SECURITY] [DSA 1569-1] New cacti packages ...
Subject:Re: securing server
Group:Debian-security
From:Maik Holtkamp
Date:8 May 2008


 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

Jean-Paul Lacquement wrote/schrieb @ 07.05.2008 13:03:

|> Besides that, what applications you plan to run?
|
| This server will only run proftpd, ssh, apache, nagios(via http),
samba and cups

*Oh*. IMHO you should consider whom you will serve, too.

If it is a limited group you can probably even change apache to listen
on different ports and tell your users to add :<port> to their urls.

If it should only serve you, you can probably even use portknocking to
start apache, limit access from several IPs or call your box to start
services. OTOH I see no reason to use just sshd if you will be the only
user it should serve.

If it should offer services for $WORLD, you can't.

BTW: If you think of offering services for $WORLD, I see absolutely no
~ reason to use cups or samba on such an exposed box. As you
~ mentioned those, I suppose you wouldn't offer public services.

YMMV.

- --
bye maik
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (MingW32)
Comment: Signature of Maik Holtkamp

iD8DBQFIIb6Sz3bq6aadmI8RAtOGAKDtMiU81qAk2N4+lIu4UEi+wymM2wCfXWNR
7khzXzpr1UioXrqfzk/OyEw=
=Epcw
-----END PGP SIGNATURE-----




© 2004-2008 readlist.com