Re: securing server

2008-05-09 Thread weakish
On Fri, 2008-05-09 at 09:24 -0400, Noah Meyerhans wrote: > > At least tripwire has the ability to encrypt its database, which helps > to mitigate this problem. The claim that tripwire is only useful with > read-only media is too strong; it can be quite useful without it. > And you can sign yo

Re: securing server

2008-05-07 Thread weakish
Just too many things. For example, Use update-rc.d or sysv-rc-conf to disable unwanted daemons Edit /etc/security/limits.conf logcheck use integrit/aide/tripwire configrue firewall (via shorewall or iptables directly) etc. You may consider chroot. It's a good idea to read through securin