Hey Everyone,
Sorry I haven't put out a new update in a while but I've been pretty
busy. Anyway.. lots of changes, a few critical patches added, etc..
159 users and counting..
--David
--
C* 5/05/99 There is a new exploit out on Bugtraq for Wu-FTPd. Since Redhat
hasn't
* Sent updated their RPMs, you need to do it yourself.
Update * [Section 100]
------------------
I 5/03/99 Noted a /etc/shadow fix for Caldera users
[Section 100]
------------------
I 5/02/99 Updated the IPFWADM ruleset to v2.94
# v2A.94 - Added explict INPUT filters for NFS and OUTPUT
filters for Mountd
and RPC
[Section 10]
I Disabled VRFY and EXPN in sendmail to secure Sendmail up a bit
better.
[Section 25]
------------------
I 4/26/99 Added a little blurb on what Samba is all about
[Section 33]
Doh! Updated the /etc/smb.conf file to use ENCRYPTED
passwords!
I use encrypted passwords now and the section already
documented
how to set them up but the smb.conf file wasn't configured to
use it. Thanks to [EMAIL PROTECTED] for this observation!
[Section 33]
------------------
N 4/25/99 Added the RFC URLs for DHCP
[Section 5]
Added a little blurb on what BOOTP/DHCP is.
[Section 27]
------------------
C* 4/19/99 Installed (3) new RPMs for security stuff
[Section 50]
------------------
G 4/14/99 Updated the APCUPSD URL
[Section 5]
G Updated the Samba URLs and added URLs for the Abacus, Network
Flight
Recorder (NFR), and SHADOW network monitoring tools.
[Section 5]
G Changed to a a recurisive chmod 700 to the /etc/rc.d/init.d dir
[Section 7]
G Added the note that root and user passwords should include
special
characters [ `~!@#$%^&*()-_=+{[]}\|'";:,<.>/? ] in addition to
the
normal upper and lowercase letters and numbers.
[Section 8]
N Noted that some security paranoid people DELETE all unused
lines out
of /etc/services instead of #ing the lines out.
[Section 8]
N Added /etc/hosts.allow examples for more granular access
restrictions
to remote hosts.
[Section 8]
G Made a big clarification that when you use Secure CRT for SSH
port
forwarding, you must re-configure the given to-be-SSHed
client, say
Eudora for POP-3 email, to connection to IP 127.0.0.1 and NOT
the
normal POP-3 server.
[Section 30]
I Added a little blurb that Brad wrote about issues when trying
to figure
out if your box has been hacked. This is a good little read.
[Section 46]
N Noted that users should be careful where they download there
source code,
RPMs, etc. I cited the example where win.tue.nl has hacked
and had
a trojaned version of TCP-wrappers, there. Ack!
[Section 50]
I I want to thank Bradley M Alexander <[EMAIL PROTECTED]> for all of
these great
editorial comments to TrinityOS and for his port of TrinityOS
to MS Word.
------------------
N 4/12/99 [EMAIL PROTECTED] been pointed out to me that the recent
sysklogd-1.3-26.i386.rpm RPM from Redhat has a little bug. It
seems
that upon system shutdown, you will see:
Shutting down system loggers: klog:306(PID) syslogd:294(PID)
no such pid
The previous sysklogd-1.3-25.i386.rpm doesn't exibit this
behavior.
I don't think is is any big issue but I though you might like
to know.
[Section 50]
G Brad Alexander <[EMAIL PROTECTED]> has
ported TrinityOS
v.3/31/99 to Microsoft Word. Though this isn't the newest
version of
TrinityOS, this should help a lot of people who have been
complaining about
TrinityOS's formatting. This should go a ways while I
complete the
TrinityOS
port to SGML. You can find this Word port on my main Linux
WWW page.
------------------
N 04/07/99 Added to the Future Feature section the automation of of the
firewall
hits trending file.
[Section 3]
G Added Kurt Seifried's "Linux Administrators Security Guide"
(LASG)
URL
[Section 5]
N Added the option to disable floppy WRITE access and even the
drive
all together for the truely paranoid
[Section 8]
I Added a little blurb on the importance of creating a little
offline
firewall hits log on: who, when, and how people are either
probing or
fully attacking you. This is an important thing for sys
admins. I
later hope to automate this.
[Section 9]
G Added the password option to LILO so that unless the password
is given
a hacker cannot alter its booting procedure.
[Section 15]
N A user noted that Slackware comes with "netdate" which is very
similar
to my documented "Getdate" but since its only for Slackware,
I've left
the NTP section as it is but I have noted this in the section.
[Section 26]
N Added a recommendation to the truely paranoid that you can
convert DHCPd
to run in a CHROOT'ed way. This is documented in Kurt
Seifried's "Linux
Administrators Security Guide" (LASG). The URL was added to
Section 5.
[Sectiom 27]
------------------
N 03/31/99 Fixed a typo in the ssh2_config referencing "sshd1path" and
not the
correct "ssh1path"
[Section 30]
------------------
G 03/30/99 Updated the security blurb to have initial connections only
prompt
with "Login:" instead of also showing the Linux kernel version.
[Section 9]
C* Added (4) Security patches for Redhat.
[Section 50]
------------------
C* 03/28/99 There is a new Xfree86 /tmp race condition. Apply the
workaround
until there is a new Xfree version. I've also noted this
sticky
bit recommendation at the end of Section 8.
[Section 50]
------------------
N 03/27/99 Doh! Though my basic and strong firewalls use REJECT in the
explict deny statements, the default policies was DENY. I've
changed
it to REJECT.
[Section 10]
------------------
N 03/24/99 After some recent experimentation, I found that the Probe
Multi-LUN
support for my SCSI CD-changer was breaking things so I pulled
it out
of the kernel config
[Section 12 - kernel setup]
N Like above, I added a blurb on what the Multi-LUN option does
in the
kernel and made the recommendation to try your changer with
OUT this
option initially and then to try it out if needed.
[Section 32 - CD Changers]
------------------
.----------------------------------------------------------------------------.
| David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] |
!---- ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]