Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Securing Gentoo
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
DanZ
n00b
n00b


Joined: 24 Sep 2004
Posts: 47
Location: Erie PA USA

PostPosted: Fri Sep 24, 2004 4:04 am    Post subject: Securing Gentoo Reply with quote

I'm looking for advice, tips and tricks to securing Gentoo. I'm real good at locking down Windows, but I'm a linux nub so I could use some help here. I've heard of logsentry and chkootkit, are these recommended and what other tools would round out a secure system?
Back to top
View user's profile Send private message
kashani
Advocate
Advocate


Joined: 02 Sep 2002
Posts: 2032
Location: San Francisco

PostPosted: Fri Sep 24, 2004 5:02 am    Post subject: Reply with quote

You'll want to checkout the security guide.
http://www.gentoo.org/doc/en/gentoo-security.xml

kashani
_________________
Will personally fix your server in exchange for motorcycle related shop tools in good shape.
Back to top
View user's profile Send private message
DaMightyWhightyMan
Tux's lil' helper
Tux's lil' helper


Joined: 16 Feb 2004
Posts: 116

PostPosted: Fri Sep 24, 2004 8:26 am    Post subject: Reply with quote

Depends on how hardcore you want security. My gentoo servers are Gentoo SELinux /w a grsecurity enabled kernel. I run all my services in a chroot environment etc etc, as kashani linked you to the gentoo-security guide, that's a good place to start. If you're just looking to firewall your connection, iptables is sufficent for moderate securing. Chkootkit is good to check to see if a rogue user is trying to run a root kit, only nessesary if you have users that you think plan on harming you.
Back to top
View user's profile Send private message
tuxmin
l33t
l33t


Joined: 24 Apr 2004
Posts: 838
Location: Heidelberg

PostPosted: Fri Sep 24, 2004 11:52 am    Post subject: Reply with quote

I made some good experiences with the hardend gentoo profile and grsecurity enabled. I do not use grsecuritys RSBAC subsystem, tghough. But I'd say this is a good compromise between security and usability.
The point is that hardened-gentoo provides you with a transparent mechanism that enables you to take fully advantage of grsecurity's PIE and ASLR feature. PIE stands for Position Independant Executable and ASLR means Address Space Layout Randomozation. Together with the --fstack-protector CFLAG in your make.conf you have done the best to avoid buffer overflow attacks to be succesful.
Read the docs at www.grsecurity.net and pax.grsecurity.net for more insight.
I find this succicent for server systems where only administrative staff is meant to login. However, you might want to activate RSBAC when lots of wanna-be hackers are authorized to connect to the system.
_________________
ALT-F4
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum