Skip to Main Content
Linux Server Security, Second Edition
book

Linux Server Security, Second Edition

by Michael D. Bauer
January 2005
Intermediate to advanced content levelIntermediate to advanced
544 pages
23h 44m
English
O'Reilly Media, Inc.
Content preview from Linux Server Security, Second Edition
This is the Title of the Book, eMatter Edition
Copyright © 2007 O’Reilly & Associates, Inc. All rights reserved.
70
|
Chapter 3: Hardening Linux and Using iptables
If nothing else, you should change the final field (default shell), in unknown or pro-
cess-specific accounts’ entries in /etc/passwd, from a real shell to /bin/false; only
accounts used by human beings should need shells.
Restricting Access to Known Users
Some FTP daemons allow anonymous login by default. If your FTP server is
intended to provide public FTP services, that’s fine, but if it isn’t, there’s no good
reason to leave anonymous FTP enabled.
The same goes for any other service running on a publicly accessible system: if that
service supports but doesn’t actually require anonymous connections, the service
should be configured to accept connections only from authenticated, valid users.
Restricting access to FTP, HTTP, and other services is described in subsequent chap-
ters.
Running Services in chrooted Filesystems
One of our most important threat models is that of the hijacked daemon: if a mali-
cious user manages to take over and effectively “become” a process on our system,
he will assume the privileges on our system that that process has. Naturally, develop-
ers are always on the alert for vulnerabilities, such as buffer overflows, that compro-
mise their applications, which is why you must keep on top of your distribution’s ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Linux: Powerful Server Administration

Linux: Powerful Server Administration

Uday Sawant, Oliver Pelz, Jonathan Hobson, William Leemans
Linux Server Hacks

Linux Server Hacks

Rob Flickenger
Linux Server Hacks, Volume Two

Linux Server Hacks, Volume Two

William von Hagen, Brian K. Jones

Publisher Resources

ISBN: 0596006705Supplemental ContentCatalog PageErrata