Feeds

Out of the box, Linux is ‘dreadfully insecure’

Bastille Day

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

LinuxWorld Jay Beale, the lead developer of Bastille Linux and an independent security consultant, says it's not the Unix-based systems with interesting stuff on them that get hacked, it's the vulnerable ones. And if you're not prepared to tighten up what you get from the vendor, it's just a matter of time.

Beale shared his philosophy for building a secure system Tuesday at a LinuxWorld Expo tutorial on securing Linux/Unix systems. "The purpose of tightening a system is just to make it hard to attack," he says.

As the development of Linux progresses, many people set up systems that are running lots of features. For instance, in the Mandrake Linux setup, you can choose to install software that makes your computer an FTP server, a Web server, or even an email server.

"If there's a bug in any one of these features," says Beale, "then the chances are that someone can exploit one of those features. If you've left your system as it is, from the vendor, you're going to be vulnerable."

The problem happens when people think that they don't need extra security measures because their system "just isn't interesting." Beale's example is the average university mathematics department. "If I'm the system administrator, I'm thinking, 'what could a hacker possibly want with my system?' so, why worry?" But, Beale says, even the math department he was a part of was continuously cracked.

"The issue is, while you can target a system, an attack more than likely isn't targeting you specifically," he says. A script kiddie looks for and downloads exploit code that tells him what to look for. "He sets up a scanner with a huge block of IP addresses. Out of the tens of thousands of addresses, he'll get a list of a few hundred that are vulnerable. In that list is perhaps my home machine, perhaps the university math department.

"They're not coming after us because we're interesting, they're coming after us because we're vulnerable."

The way to stop hackers, says Beale, is to employ what he calls minimalism. "If you can bring your system down from 10 functions to three functions, there's less of a chance to be exploited. This is why we tighten."

Beales lists five things that sysadmins can do to lock down their systems:

1. Set up a firewall. "This is not the end of the security process," Beale says. "But it is a good start."

2. Decrease the number of privileged programs. By this Beale means don't run too many applications that give the user power to make changes to the system.

3. Tighten configurations on the remaining programs. Most network daemons can be set to reduce their access and the kinds of interactions they permit.

4. Reduce the number of paths to root. Every user on the system is assigned a number, or UID. Root is assigned the number zero. Some programs automatically run with the root UID, a potential vulnerability. Reducing these kinds of programs reduces the "paths to root."

5. Deploy intrusion detection. "Tripwire (an application to detect intruders) can be amazingly effective," says Beale.

© Newsforge.com. All rights reserved.

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
10 ways wire data helps conquer IT complexity
IT teams can automatically detect problems across the IT environment, spot data theft, select unique pieces of transaction payloads to send to a data source, and more.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?