1. any out of the box installation of any OS is not secure.
2. Number of ports open, does not mean more or less security.
    I have 22, 21, 113, 80 open all the time, they are left open for a
reason.. for access. If you only access your machine locally, then there is
no reason to keep them open.

anyway, please realize that, if u have a lot of ports open, or closed
doesn't mean you're more open to hackers, or less. a hacker needs just one
exploitable service(port) running, to wreak havoc, sometimes he doesn't even
need a port, (I could send hidden code, to you in an email on your windows
box, u open it in outlook.. and boom.. we have a little melissa clone).

the security problem is the administrator.. /user. i've seen NT boxes that
are rock solid(unhackable/crashable), and i've seen unix boxes that are
unhackable/crackable. it's not the OS.. it's the user.





----- Original Message -----
From: "root" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, March 15, 2000 5:28 AM
Subject: [newbie] Security problem!!!!!


> Hi all,
> No I have not found a security problem. Though my own lack of knowlegde
> (newbie) I had caused one for myself. Although Mandrake could have
> prevented it. I did a complete install of 7.02, this included Apache and
> postfix etc. This programs are started at boot up by default. Both leave
> ports open, which can be used by hackers to do what they do. I was not
> using this programs/services so I simply de-selected them in drakconf->
> startup services.
>
> If anyone is interested in testing their Linux box to see if they have
> open ports try grc.com. They have a free online util which will test
> your security for possible open ports. I found it very surprising to
> find my win98 install more secure than my Linux install.  Something is
> definitly wrong there. I thought my Linux box was SO secure, till I
> found EVERY port open.
>
> Check out grc.com, ponder your finding, then bag me out if you feel you
> need to.
>
> I hope Mandrake pay some attention. Maybe do a how-to secure your linux
> box.
>
> Regards
>
> Steve Rex
>

Reply via email to