Author: Benjamin D. Thomas
Administration Notes
By: Benjamin Thomas
Knowing that your servers are up-to-date is a good way to help ensure that you will have uninterrupted holidays. What else can assure you that operations will run smoothly during time off? There are many pieces to the equation that are important. One of the most significant aspects is using servers that are properly configured and hardened. In addition, proper server administration procedures must be followed. While many intrusions are a result of vulnerable packages, a large number of them can also be attributed to improper software configuration and administration. This burden falls on the administrator. What can be done to reduce the risk of improper software configuration?
The easiest way, is to look for a pre configured or specialized security distribution. Because I am a long time contributor to EnGarde Secure Linux, I am biased in this recommendation. However, I personally feel that using a distribution such as EnGarde will dramatically improve your organization’s security stance with very little time, effort, and money invested. You’ll find that with EnGarde, administration becomes easy. I have used it for years and now I find myself becoming lazy when it comes to using other systems. I find myself not wanting to do anything manually. Administration has become easy and now it is possible to concentrate on more intellectually stimulating projects. A specialized distribution is ideal for administrators with multiple systems to maintain in a critical environment. More information can be found out about EnGarde at: www.engardelinux.org
If you’ve only installed Linux and Apache to host a personal Web site, or you are just looking to learn the inter workings of security and administration. I recommend finding a good Linux security book. An interesting book that I recently had the pleasure of reading is titled Linux Security Toolkit, by David Bandel. It covers host security, network security, firewalls & specialized security software, and Linux security auditing. It is easy to read and suitable for administrators wishing to concentrate on security. Like most books published today, it is not suitable for the seasoned administrator. Although the book is well written, it is not full of cutting edge knowledge. If you’re looking to learn more about security, I recommend taking a look. It is available used through Amazon.com at a very reasonable price.
Debian | ||
Debian: New phpgroupware packages fix several vulnerabilities |
||
17th, November, 2005
|
||
Debian: New egroupware packages fix several vulnerabilities |
||
17th, November, 2005
|
||
Debian: New fetchmail packages fix potential information leak |
||
18th, November, 2005
|
||
Debian: New gnump3d packages fix several vulnerabilities |
||
19th, November, 2005
|
||
Debian: New common-lisp-controller packages fix arbitrary code injection |
||
21st, November, 2005
|
||
Debian: New xmail packages fix arbitrary code execution |
||
21st, November, 2005
|
||
Debian: New fetchmail packages fix potential information leak |
||
21st, November, 2005
|
||
Debian: New unzip packages fix unauthorised permissions modification |
||
21st, November, 2005
|
||
Debian: New netpbm packages fix arbitrary code execution |
||
21st, November, 2005
|
||
Debian: New mantis packages fix several vulnerabilities |
||
22nd, November, 2005
|
||
Debian: New fetchmail-ssl packages fix potential information leak |
||
22nd, November, 2005
|
||
Debian: New sylpheed packages fix arbitrary code execution |
||
22nd, November, 2005
|
||
Debian: New ipmenu packages fix insecure temporary file creation |
||
23rd, November, 2005
|
||
Debian: New sylpheed-claws packages fix arbitrary code execution |
||
23rd, November, 2005
|
||
Debian: New horde3 packages fix cross-site scripting |
||
23rd, November, 2005
|
||
Debian: New zope2.7 packages fix arbitrary file inclusion |
||
24th, November, 2005
|
||
Gentoo | ||
Gentoo: Smb4k Local unauthorized file access |
||
18th, November, 2005
|
||
Gentoo: GNUMP3d Directory traversal and insecure temporary |
||
21st, November, 2005
|
||
Gentoo: FUSE mtab corruption through fusermount |
||
22nd, November, 2005
|
||
Gentoo: phpSysInfo Multiple vulnerabilities | ||
22nd, November, 2005
|
||
Gentoo: eix Insecure temporary file creation | ||
22nd, November, 2005
|
||
Gentoo: Horde Application Framework XSS vulnerability |
||
22nd, November, 2005
|
||
Mandriva | ||
Mandriva: Updated php packages fix multiple vulnerabilities |
||
17th, November, 2005
|
||
Mandriva: Updated file package fixes segfault |
||
18th, November, 2005
|
||
Mandriva: Updated drakxtools packages fix various bugs |
||
18th, November, 2005
|
||
Mandriva: Updated gdk-pixbuf/gtk+2.0 packages fix vulnerability |
||
18th, November, 2005
|
||
Mandriva: Updated binutils packages fix vulnerabilities |
||
23rd, November, 2005
|
||
Mandriva: Updated fuse packages fix vulnerability | ||
24th, November, 2005
|
||
Category:
- Security