Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: no daemons listening and errata updates (secure or not?) |
|---|---|
| Date: | Fri, 28 Jul 2006 22:51:09 +0800 |
Hi colleague
I am using Fedora Core as workstation. To lock down the OS, I disable all network daemons: only dhclient is listening for network connections. Furthermore I regularly update my installation using yum. All other setting are out-of-the-box from Red Hat.
Is my simple setup secure to be connected directly to the Internet? Does an attacker have a chance to break my workstation? How high is the risk? What can I do to improve the security? How would you break in my system? Please show me vulnerabilites in my setup.
Nico
There is always a risk of being compromised, but you are doing good progress. I would put up an iptables firewall to make sure that no errant network service accidentally being enabled would compromise your security (you could investigate blocking outbound traffic too, if you are really paranoid). The rest is basically behavior: only run software that comes from good sources, beware of strangers etc....
If there is no service to break in to (and there is no nasty kernel bug you can exploit), the only way to get in to your system would be tricking you to open it up in one way or another (browser/email client/other software you use exploits, get you to install trojaned software etc...).
Best regards Michael Boman
-- IT Security Researcher & Developer http://proxy.11a.nu | http://www.11a.nu
--------------------------------------------------------------------------- This list is sponsored by: Norwich University
http://www.msia.norwich.edu/secfocus ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Deny client from obtaining IP address, Dubber, Drew B |
|---|---|
| Next by Date: | Re: AW: How to stop Admins from sniffing ?, Bryan S. Sampsel |
| Previous by Thread: | no daemons listening and errata updates (secure or not?), sun sadm |
| Next by Thread: | AW: How to stop Admins from sniffing ?, Christian . Assfalg |
| Indexes: | [Date] [Thread] [Top] [All Lists] |