View previous topic :: View next topic |
Author |
Message |
kLOCKwork n00b
Joined: 09 Jul 2006 Posts: 19
|
Posted: Mon Jul 24, 2006 9:38 am Post subject: Security apps install without internet? |
|
|
This may be a very silly question from a noob, but is there any way I could install and run some security apps, such as a rootkit hunter, a vulnerability scanner and a firewall before connecting to internet (e.g. via CDrom). The reason is that my computer is brand new and I only have installed Gentoo and KDE from Installation CDs. It would seem to me like a good time to run rootkit hunter or chkrootkit or something before any connection to internet. If the installation would be on CDrom, how would Portage react? |
|
Back to top |
|
|
ToeiRei Veteran
Joined: 03 Jan 2005 Posts: 1191 Location: Austria
|
Posted: Mon Jul 24, 2006 9:50 am Post subject: |
|
|
You just need to have the distfiles and place them in your distfiles dir (which would usually be in /usr/portage/distfiles).
Your Gentoo-Box is pretty secure as long as you do not have unneeded services up and running.
Rei _________________ Please stand by - The mailer daemon is busy burning your messages in hell... |
|
Back to top |
|
|
Aurisor Guru
Joined: 20 Sep 2003 Posts: 361 Location: Boston MA
|
Posted: Mon Jul 24, 2006 1:05 pm Post subject: |
|
|
If you check the md5sums on the installation cds you can be sure the cds are not compromised. Then just keep all of your services off the net while you connect to get your security tools.
IMO it's kind of silly to worry about your clean install getting owned in the amount of time it takes to download some security tools. |
|
Back to top |
|
|
ToeiRei Veteran
Joined: 03 Jan 2005 Posts: 1191 Location: Austria
|
Posted: Mon Jul 24, 2006 3:18 pm Post subject: |
|
|
ishan wrote: | IMO it's kind of silly to worry about your clean install getting owned in the amount of time it takes to download some security tools. |
If you're on windows, you've got a maximum time of 40 Sec. if you're lucky.
As ishan said - if you're paranoid you can turn off every service that opens a port (check with netstat -anp)
Rei _________________ Please stand by - The mailer daemon is busy burning your messages in hell... |
|
Back to top |
|
|
|