Linux Security
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   Web Development Archives Mailing Lists Linux Security

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Web Development Archives Sponsor:
  #1  
Old October 23rd, 2007, 01:09 PM
Ansgar -59cobalt- Wiechers
Guest
Dev Archives Newbie (0 - 499 posts)
 
Posts: n/a  
Time spent in forums:
Reputation Power:
Linux Hardening

2007-10-21 Liran Cohen wrote:
Ajai Khattri wrote:
>Wed, 17 2007, Liran Cohen wrote:

what is the machine's location on your network (LAN\DMZ etc) what
is the machine role, you should ask yourself some questions before
approaching hardening, I would not put the same effort on a machine
which is located on my LAN as much as I would make sure that DMZ
machines are protected
>
>I believe even machines on internal networks should all run local
>firewalls at the very least. There's always some Windoze user using
>and clicking on an email attachment they shouldn't click
>on


And then what? The services you need to be accessible in your LAN will
still be accessible (and thus exploitable) even if you run local packet
filters, because you need them to be accessible.

If any of your computers become infected because of someone clicking on
an attachment, your security concept has already failed several times,
and you should ask yourself some serious questions, including (but not
limited to):

- Why didn't the spam/malware filter on your mailserver catch the
attachment?
- Why didn't the local virus scanner catch the attachment?
- If the attachment is an executable: why did your Software Restriction
Policies (and temp directory settings) allow it to be executed?
- Why was an unneeded service running on the remote host?
- If it was started by a user: why did your Software Restriction
Policies allow that?
- If the exploit was not a 0day: why was the system not up-to-date?

top of that: running a packet filter always means running additional
code that may contain additional (remotely exploitable) bugs. There
already has been a case (W32/Witty.worm) where systems became vulnerable
*because* they were running a local firewall.

I completely agree providing you have the time and dont have a couple
of dozens of Linux machines to maintain daily, in many cases you have
to make a sensible choice what would be worth more or in other words
asses where the risk is higher and invest most of your efforts there.

Reasonable risk assessments will most likely lead to the conclusion that
host-based packet filters in the LAN are not worth the effort.

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
Coombs on Bugtraq

Reply With Quote
Reply

Viewing: Web Development Archives Mailing Lists Linux Security > Linux Hardening


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway
Stay green...Green IT