/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hey Everyone,

LOTS of updates in this one (I've been busy)!  Sorry 
if its a bit overwhelming but I think you'll like 
some of the new changes.  

(sorry, no SGML yet, getting my new Mandrake 6.1 
(machine ready to replace my old 486 is priority #1)


The important changes are:

1) TrinityOS is now FULLY SCRIPTED with most of ALL
the config files contained in the TGZ below.

2) Changed where the rc.firewall loads up for better 
security.

3) Cleaned up, enhanced, and moved the "sendlogs" script

4) Updated the STRONG IPCHAINS ruleset

5) Integrated in the separate PPP docs

6) Enhanced the sendmail configuration for better MASQ
        functionality

7) Added XNTP support in addition to the Getdate tool

8) Added UNIX SSH port forwarding

9) Moved over to AutoRPM for software update monitoring.
   This new system works of FTP sites and is more flexible.
   As it stands, the old RPM-Watch tool does NOT work for
   Redhat 5.2, 6.0, or 6.1.


PS.  There are now 293 members on the list.

--David


------------------------------------------------------------------------------
All of TrinityOS's step-by-step instructions, files, and scripts are fully 
scripted out for an automatic   installation at:

http://www.ecst.csuchico.edu/~dranch/LINUX/TrinityOS-files/TrinityOS-security.tg
z
-----------------------------------------------------------------------------


N       11/28/99 - Updated the name of the SSH chapter
        *Sent           [Section 3]
        Updates*

N               - Added a future feature to add a new 
                  IPCHAINS firewall for single interface 
                  users (eth and ppp)
                [Section 3]


N               - Added URLs for the CHKLOGs, Swatch, and 
                  LogCheck tools
                [Section 5]

N               - Added the URL for IP traf for an excellent 
                  Ncurses network sniffer/monitor
                [Section 5]

N               - Added a URL for a high level intro to Linux 
                  hardware and software RAID support
                [Section 5]

I               - Added a URL for AutoRPM and mentioned that 
                  RpmWatch will be phased out since it 
                  doesn't work with Redhat's new WWW 
                  layout for Redhat 5.2 and newer distro 
                  update pages.
                [Section 5]

N               - Added/Changed TrinityOS search/replace 
                  entries for:
                        - PPP dialin accounts
                        - the username replacement field
                        - Added (2) more Explictly allowed hosts
                [Section 5]

G               - Fixed permissions (made recursively) for 
                  all cron directory entries
                [Section 5]

G               - Clarified the umask issue with multiple 
                  user systems
                [Section 5]


G               - Changed the perms for /etc/rc.d/init.d 
                  from 700 to 770 in favor of administration 
                  groups instead of just root users.
                [Section 7]

                - Changed some verbage:
N                       - Put the Redhat section on top and 
                          Slackware on the bottom
N                       - Put in a testing criteria for shadow 
                          passwords and noted that RH6 already 
                          supports shadow passwords.
N                       - Put the MD5 method for shadow 
                          passwords on top
                [Section 7]


G               - Setting the sticky bit for /tmp/.X11-unix 
                  wasn't working (using 1777) so I used a 
                  different method (u+t).
                [Section 8]


N               - Changed the Redhat / Slackware order 
                  for the configuration files.
                [Section 9]

G               - Added permission changes for Slackware 
                  SYSLOG files
                [Section 9]

G               - Added extra file permission checks for 
                  SYSLOG files
                [Section 9]

G               - Added the option of how to disable the 
                  "--MARK--" lines in the various syslog 
                  files.
                [Section 9]

G               - Tuned a few more syslog files to compress 
                  via logrotate.d
                [Section 9]

I               - Removed the /etc/rc.d/rc.local lines to 
                  start the firewall and CDROM programs to 
                  their appropriate TrinityOS chapter.  This 
                  is the kind of leftover old TrinityOS crap 
                  that needs to be cleaned up.  I'm getting 
                  there.
                [Section 9]

G               - Cleaned up the "logit" script verbage a 
                  little and deleted the "recycle" script 
                  as it only pertained to the old "logit" 
                  script that used tail to send logs to 
                  TTY7/8
                [Section 9]

N               - Mentioned that the "sendlogs" script 
                  will be REPLACED once I implement something 
                  like Swatch or CheckLog.
                [Section 9]

G               - Significantly cleaned up the "sendlogs" 
                  script and added the the search for RCMD 
                  files as well.
                [Section 9]

N               - Moved the new "sendlogs" script to 
                  /usr/local/sbin
                [Section 9]

G               - Added running the "makewhatis" program 
                  manually for new installations and if 
                  you get ERRORs running this command,
                  there are instructions how to fix them.       
                [Section 9]

G               - Appended to the logrotate section how to 
                  fix some of the logrotate error you 
                  might be receiving via email.
                [Section 9]

N               - Changed the /etc/bashrc file a little 
                  to give non-root users a "green" prompt 
                  and ROOT users a "red" prompt.
                [Section 9]


I               - Updated the IPCHAINS ruleset to v3.35
                [Section 10]


N               - Updated the kernel configs for the 
                  2.2.13 and 2.0.38 kernels 
                [Section 12]

N               - reversed the kernel configs so that 
                  2.2.13 is first and then 2.0.38 second
                [Section 12]


N               - Added a blurb regarding that Setserial 
                  isn't really needed for modern 2.2 
                  kernels to get 115,200.
                [Section 16]

N               - Added a check when adding rc.serial 
                to rc.sysinit
                [Section 16]


N               - Cleaned up some verbage about the 
                  /etc/aliases file
                [Section 18]

N               - Removed the references for NetWatch. 
                  Use IPTraf instead
                [Section 21]


G               - Updated /etc/ppp/options file to use 
                  LOCKs and to reflect the modern PPPd 
                  config file setup
                [Section 22]

G               - Changed the formatting of this section
                [Section 22]

I               - Integrated my old separate PPP docs into 
                  TrinityOS
                [Section 22]


N               - Cleaned up the formatting a little and 
                  updated the example root-hints.db file
                [Section 24]


G               - Updated the trinityos.mc file to reflect 
                  the paths for procmail and how to do some 
                  .cf tricks via the .mc files directly.
                Thanks to [EMAIL PROTECTED] for some the tips.
                [Section 25]

G               - Disable sendmail help in the /etc/sendmail.cf 
                  file.
                [Section 25]


G               - Added xntp support in addition to getdate
                [Section 26]

N               - Deleted the references to PPP within the 
                  NTP script
                [Section 26]


N               - Made a clarification that this example 
                  ONLY runs on eth1
                [Section 27]

G               - Added the config to have DHCPd load 
                  upon boot
                [Section 27]


N               - Updated the title of the chapter
                [Section 30]

N               - Cleaned up a few things in the verbage 
                  to configure SSH
                [Section 30]

G               - Moved the "ssh" alias to /etc/bashrc
                [Section 30]

G               - Added a whole subsection on how to do 
                  SSH tunnels with UNIX clients.  Its 
                  pretty simple once you see it.
                [Section 30]

G               - Added the "preferred master = yes" 
                  option to the /etc/smb.conf file 
                  to make the Samba box the subnet 
                  master browser.
                [Section 33]

N               - reordered the configuration file to 
                  reflect the newer 2.0.5a format
                [Section 33]

G               - Added the addition of the send/receive 
                  buffers to the "socket options" field
                [Section 33]


N               - Added how to start NFS in redhat
                [Section 40]


I               - Removed the incomplete section on 
                  "rhlupdate" and replaced it with 
                  "AutoRPM".  AutoRPM is now the preferred 
                  method for update checking in TrinityOS 
                  because the old "RpmWatch" tool was 
                  not compatible with Redhat's newer WWW 
                  site layout, ONLY worked with Redhat, 
                  and it required that the WWW site be 
                  constantly updated vs. checking the FTP 
                  site itself.

                  Please note that I'm still in the process 
                  of learning and tuning this tool, if 
                  you have comments, etc, please let me 
                  know.
                [Section 43]


==================


------------------

N       11/25/99        Changed some formatting and cleaned 
                        up some light verbiage throughout.
                        [Sections 1-6]

------------------

N       11/24/99        - Revamped the URL section for MASQ, 
                          NAT, Load Balancing, and High
                          availability
                        [Section 5]

------------------

I       11/21/99        - Added a buffer overflow attack for 
                          NFS
                        - Added a DoS attack notice for Syslogd
                        [Section 60]

------------------

G       11/16/99        - Added the master Mandrake updates 
                          URL
                        [Section 5]

N                       - Fixed the permissions for the
                        /etc/info/suid-results-checked file 
                        to 600.
                        [Section 8]

G                       - Added a blurb on checking for 
                          .rhosts and host.equiv files much 
                          like the SUID search.
                        [Section 8]

I                       - Made several changes to the DNS 
                          config section:

                                - Moved the global "allow-transfer" 
                                parameter to each zone file.  This 
                                give better granularity per zone.

                                - Added the "allow-query" parameter 
                                PER zone file to restrict what 
                                internal DNS info is released to
                                the Internet.  This is somewhat 
                                like a split DNS setup but not 
                                quite.

                                - Fixed the in-addr-arpa names to 
                                  reflect the backwards TCP/IP 
                                  address for acme123.com.  It
                                  was something like 50.0.201.101 
                                  instead of 212.0.200.100 
                                  (remember, read that backwards 
                                  octet for octet).

                                - Added the "allow-transfer" 
                                  parameter to disable slave servers 
                                  from giving out DNS xfers!!

                                - Doh!  Missed the in-addr.arpa 
                                  file for the slave section.

                        [Section 24]

G                       - Added the FEATURE(masquerade_envelope) 
                          feature to the Sendmail config to better 
                          hide internal hosts.
                        [Section 25]

G                       - It should be noted that I've been having 
                          a LOT of problems with the mirror sites 
                          offered by the MandrakeUpdate tool.  The
                          only reliable mechanism I've found is to 
                          edit the .mandrake-update file and use 
                          the url: 

                                mirror: ftp://ftp.linux-mandrake.com/pub/

                          This worked for me.
                        [Section 60]

------------------

G       11/15/99        - Added the email address on how to add 
                          yourself to the BIND Annoucement list.  
                        [Section 5]

*C*                     - All versions of BIND v8.2.2p5 are 
                          vulnerable to a ROOT attack.  Upgrade 
                          your version of BIND NOW!
                        [Section 24]

G                       - Added a recommendation for ALL DNS 
                          admins to subscribe to the BIND 
                          announcement list.
                        [Section 24]

N                       - Moved the blurb on how to get your 
                          own Domain name and legal issues to 
                          the end of the section.
                        [Section 24]

G                       - Added a recommendation for ALL Sendmail 
                          admins to subscribe to the Sendmail 
                          announcement list.
                        [Section 25]

G                       - Noted the ROOT exploit to BIND in the 
                          Security hack section
                        [Section 60]

------------------

G       11/13/99        - Changed the IPFWADM NON-MASQ firewall 
                          revision to 2A.97.  Fixed a variable 
                          name typo in the non-MASQed IPFWADM 
                          BackOrofice filter.
                          [Section 10]

G                       - Added a line to create the empty files 
                          using the "touch" command for secondary 
                          DNS zone files.
                          [Section 24]

--------------
.----------------------------------------------------------------------------.
|  David A. Ranch - Linux/Networking/PC hardware         [EMAIL PROTECTED]  |
!----                                                                    ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to