-
basic post-hdinstall security
I'm new to knoppix. What do I need to do right after installing to get secure? I know most new boxes get probed quickly so I'm anxious to get my security up.
-
Administrator
Site Admin-
For a start and for a DSL user like yourself, I consider a router an absolute must. I would not connect high speed without one. Windows is more vulnerable than Linux, and Knoppix run from CD is pretty secure. But Linux attacks are getting worse, and particularly if you think installing Knoppix to hard disk is a good idea, then I would start at using a router.
A DSL/cable router will give you a good hardware firewall and your system can't be "probed" through it unless you set it up wrong, do something stupid like run an infected program, or move into the "dmz". These things are dirt cheap now; my little Linksys originally cost arround $150, I paid over $100 for it and it was still worth it (and I'm a cheap s.o.b.). Now this and other routers, many even wireless routers, are frequently sold at $10 US or less after reate and usually not much more without a rebate. You can still buy expensive routers, but they are not usually a good choice. If you don't know why you need an expensive one, don't just think it must be better because it costs more.
A router will also make your use of Knoppix much cleaner. You will not have to run PPPoE software, for example. And if you still use Windows that will be much safer (after you clean out the infections you must have by now without one).
I expect others will join in with some of the Linux security and firewall issues as well.
---
Verifying of md5 checksum and burning a CD at slow speed are important.
-
really now
Getting a router is the tip of the iceberg when it comes to security. Everyone is eventually going to have to open a port or use a service of some kind, besides there are known exploits for 2wire routers, certain linksys models, and plenty of reverse backdoors that barely give notice to the router. I would suggest doing the following things to begin.
-Edit /etc/inetd.conf and comment out any services you don't need
-Google rc.firewall
-Get a rookit hunter
-You may want to look into /etc/hosts.allow and hosts.deny if you only have certain people you want connecting
-Always use public keys for ssh
-Do not trust anyone
Anyway you can build on this but this is good for getting secure quickly.
Similar Threads
-
By anders in forum Hardware & Booting
Replies: 3
Last Post: 04-24-2005, 05:35 AM
-
By lavaman094 in forum Hdd Install / Debian / Apt
Replies: 1
Last Post: 09-01-2004, 02:09 PM
-
By hybridus in forum General Support
Replies: 2
Last Post: 03-27-2004, 10:24 PM
-
By schunn99 in forum The Lounge
Replies: 2
Last Post: 02-27-2004, 02:22 AM
-
Replies: 1
Last Post: 04-10-2003, 02:52 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

(New) AMD Ryzen 7 5700X 8 Core 16 Thread AM4 Unlocked 3.4 GHz CPU OEM Tray
$174.99

Pair ID-COOLING A8-SP3 CPU Heatsink Coolers and AMD EPYC 7601 32 Core Processors
$290.00

AMD Ryzen 7 PRO 8700GE 8-Core/16-Thread Up to 5.1GHz AM5 (FL1)
$189.00

Dell OptiPlex 5070 SFF i7-9700 (8-Core) 3.0GHz 16GB 256 SSD Windows 11
$250.00

AMD Ryzen 7 7800X3D 4.20GHz Quad Core 100-000000510 8 Thread AM4
$279.99

Apple Macbook Pro 13" M1 8-Core 16GB 512GB - Good
$464.99

AMD Ryzen 7 9800X3D 8-Core 16-Thread AM5 Zen 5 Desktop Processor NEW
$399.00

Intel Xeon E5 - 2667V2 / SR19W 3.30GHz 25MB 8-Core CPU Socket LGA2011
$30.00

Apple Macbook Pro 14" M1 Pro 8-Core 16GB 512GB - Good
$614.99

SGIN 17.3" Laptop Intel Quad-Core Up to 2.4 GHZ 8GB RAM 256GB SSD HD
$229.99