/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Hey Everyone, LOTS of updates in this one (I've been busy)! Sorry if its a bit overwhelming but I think you'll like some of the new changes. (sorry, no SGML yet, getting my new Mandrake 6.1 (machine ready to replace my old 486 is priority #1) The important changes are: 1) TrinityOS is now FULLY SCRIPTED with most of ALL the config files contained in the TGZ below. 2) Changed where the rc.firewall loads up for better security. 3) Cleaned up, enhanced, and moved the "sendlogs" script 4) Updated the STRONG IPCHAINS ruleset 5) Integrated in the separate PPP docs 6) Enhanced the sendmail configuration for better MASQ functionality 7) Added XNTP support in addition to the Getdate tool 8) Added UNIX SSH port forwarding 9) Moved over to AutoRPM for software update monitoring. This new system works of FTP sites and is more flexible. As it stands, the old RPM-Watch tool does NOT work for Redhat 5.2, 6.0, or 6.1. PS. There are now 293 members on the list. --David ------------------------------------------------------------------------------ All of TrinityOS's step-by-step instructions, files, and scripts are fully scripted out for an automatic installation at: http://www.ecst.csuchico.edu/~dranch/LINUX/TrinityOS-files/TrinityOS-security.tg z ----------------------------------------------------------------------------- N 11/28/99 - Updated the name of the SSH chapter *Sent [Section 3] Updates* N - Added a future feature to add a new IPCHAINS firewall for single interface users (eth and ppp) [Section 3] N - Added URLs for the CHKLOGs, Swatch, and LogCheck tools [Section 5] N - Added the URL for IP traf for an excellent Ncurses network sniffer/monitor [Section 5] N - Added a URL for a high level intro to Linux hardware and software RAID support [Section 5] I - Added a URL for AutoRPM and mentioned that RpmWatch will be phased out since it doesn't work with Redhat's new WWW layout for Redhat 5.2 and newer distro update pages. [Section 5] N - Added/Changed TrinityOS search/replace entries for: - PPP dialin accounts - the username replacement field - Added (2) more Explictly allowed hosts [Section 5] G - Fixed permissions (made recursively) for all cron directory entries [Section 5] G - Clarified the umask issue with multiple user systems [Section 5] G - Changed the perms for /etc/rc.d/init.d from 700 to 770 in favor of administration groups instead of just root users. [Section 7] - Changed some verbage: N - Put the Redhat section on top and Slackware on the bottom N - Put in a testing criteria for shadow passwords and noted that RH6 already supports shadow passwords. N - Put the MD5 method for shadow passwords on top [Section 7] G - Setting the sticky bit for /tmp/.X11-unix wasn't working (using 1777) so I used a different method (u+t). [Section 8] N - Changed the Redhat / Slackware order for the configuration files. [Section 9] G - Added permission changes for Slackware SYSLOG files [Section 9] G - Added extra file permission checks for SYSLOG files [Section 9] G - Added the option of how to disable the "--MARK--" lines in the various syslog files. [Section 9] G - Tuned a few more syslog files to compress via logrotate.d [Section 9] I - Removed the /etc/rc.d/rc.local lines to start the firewall and CDROM programs to their appropriate TrinityOS chapter. This is the kind of leftover old TrinityOS crap that needs to be cleaned up. I'm getting there. [Section 9] G - Cleaned up the "logit" script verbage a little and deleted the "recycle" script as it only pertained to the old "logit" script that used tail to send logs to TTY7/8 [Section 9] N - Mentioned that the "sendlogs" script will be REPLACED once I implement something like Swatch or CheckLog. [Section 9] G - Significantly cleaned up the "sendlogs" script and added the the search for RCMD files as well. [Section 9] N - Moved the new "sendlogs" script to /usr/local/sbin [Section 9] G - Added running the "makewhatis" program manually for new installations and if you get ERRORs running this command, there are instructions how to fix them. [Section 9] G - Appended to the logrotate section how to fix some of the logrotate error you might be receiving via email. [Section 9] N - Changed the /etc/bashrc file a little to give non-root users a "green" prompt and ROOT users a "red" prompt. [Section 9] I - Updated the IPCHAINS ruleset to v3.35 [Section 10] N - Updated the kernel configs for the 2.2.13 and 2.0.38 kernels [Section 12] N - reversed the kernel configs so that 2.2.13 is first and then 2.0.38 second [Section 12] N - Added a blurb regarding that Setserial isn't really needed for modern 2.2 kernels to get 115,200. [Section 16] N - Added a check when adding rc.serial to rc.sysinit [Section 16] N - Cleaned up some verbage about the /etc/aliases file [Section 18] N - Removed the references for NetWatch. Use IPTraf instead [Section 21] G - Updated /etc/ppp/options file to use LOCKs and to reflect the modern PPPd config file setup [Section 22] G - Changed the formatting of this section [Section 22] I - Integrated my old separate PPP docs into TrinityOS [Section 22] N - Cleaned up the formatting a little and updated the example root-hints.db file [Section 24] G - Updated the trinityos.mc file to reflect the paths for procmail and how to do some .cf tricks via the .mc files directly. Thanks to [EMAIL PROTECTED] for some the tips. [Section 25] G - Disable sendmail help in the /etc/sendmail.cf file. [Section 25] G - Added xntp support in addition to getdate [Section 26] N - Deleted the references to PPP within the NTP script [Section 26] N - Made a clarification that this example ONLY runs on eth1 [Section 27] G - Added the config to have DHCPd load upon boot [Section 27] N - Updated the title of the chapter [Section 30] N - Cleaned up a few things in the verbage to configure SSH [Section 30] G - Moved the "ssh" alias to /etc/bashrc [Section 30] G - Added a whole subsection on how to do SSH tunnels with UNIX clients. Its pretty simple once you see it. [Section 30] G - Added the "preferred master = yes" option to the /etc/smb.conf file to make the Samba box the subnet master browser. [Section 33] N - reordered the configuration file to reflect the newer 2.0.5a format [Section 33] G - Added the addition of the send/receive buffers to the "socket options" field [Section 33] N - Added how to start NFS in redhat [Section 40] I - Removed the incomplete section on "rhlupdate" and replaced it with "AutoRPM". AutoRPM is now the preferred method for update checking in TrinityOS because the old "RpmWatch" tool was not compatible with Redhat's newer WWW site layout, ONLY worked with Redhat, and it required that the WWW site be constantly updated vs. checking the FTP site itself. Please note that I'm still in the process of learning and tuning this tool, if you have comments, etc, please let me know. [Section 43] ================== ------------------ N 11/25/99 Changed some formatting and cleaned up some light verbiage throughout. [Sections 1-6] ------------------ N 11/24/99 - Revamped the URL section for MASQ, NAT, Load Balancing, and High availability [Section 5] ------------------ I 11/21/99 - Added a buffer overflow attack for NFS - Added a DoS attack notice for Syslogd [Section 60] ------------------ G 11/16/99 - Added the master Mandrake updates URL [Section 5] N - Fixed the permissions for the /etc/info/suid-results-checked file to 600. [Section 8] G - Added a blurb on checking for .rhosts and host.equiv files much like the SUID search. [Section 8] I - Made several changes to the DNS config section: - Moved the global "allow-transfer" parameter to each zone file. This give better granularity per zone. - Added the "allow-query" parameter PER zone file to restrict what internal DNS info is released to the Internet. This is somewhat like a split DNS setup but not quite. - Fixed the in-addr-arpa names to reflect the backwards TCP/IP address for acme123.com. It was something like 50.0.201.101 instead of 212.0.200.100 (remember, read that backwards octet for octet). - Added the "allow-transfer" parameter to disable slave servers from giving out DNS xfers!! - Doh! Missed the in-addr.arpa file for the slave section. [Section 24] G - Added the FEATURE(masquerade_envelope) feature to the Sendmail config to better hide internal hosts. [Section 25] G - It should be noted that I've been having a LOT of problems with the mirror sites offered by the MandrakeUpdate tool. The only reliable mechanism I've found is to edit the .mandrake-update file and use the url: mirror: ftp://ftp.linux-mandrake.com/pub/ This worked for me. [Section 60] ------------------ G 11/15/99 - Added the email address on how to add yourself to the BIND Annoucement list. [Section 5] *C* - All versions of BIND v8.2.2p5 are vulnerable to a ROOT attack. Upgrade your version of BIND NOW! [Section 24] G - Added a recommendation for ALL DNS admins to subscribe to the BIND announcement list. [Section 24] N - Moved the blurb on how to get your own Domain name and legal issues to the end of the section. [Section 24] G - Added a recommendation for ALL Sendmail admins to subscribe to the Sendmail announcement list. [Section 25] G - Noted the ROOT exploit to BIND in the Security hack section [Section 60] ------------------ G 11/13/99 - Changed the IPFWADM NON-MASQ firewall revision to 2A.97. Fixed a variable name typo in the non-MASQed IPFWADM BackOrofice filter. [Section 10] G - Added a line to create the empty files using the "touch" command for secondary DNS zone files. [Section 24] -------------- .----------------------------------------------------------------------------. | David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] | !---- ----! `----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----' _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
