Size: 257
Comment:
|
← Revision 4 as of 2009-11-17 00:49:00 ⇥
Size: 281
Comment:
|
Deletions are marked like this. | Additions are marked like this. |
Line 1: | Line 1: |
My view on securing a debian/ubuntu machine: | === My view on securing a debian/ubuntu machine: === |
Line 3: | Line 3: |
1 fail2ban 2 ssh on non standard port 3 iptables + ulog, troubleshootinginmyownballs aka fascist firewall 4 no sudo on the system 5 removing __ALL__ setuid programs 6 remote backup of log, rsyslog |
1. fail2ban 2. ssh on non standard port 3. iptables + ulog, troubleshootinginmyownballs aka fascist firewall 4. no sudo on the system 5. removing __ALL__ setuid programs 6. remote backup of log, rsyslog |
My view on securing a debian/ubuntu machine:
- fail2ban
- ssh on non standard port
- iptables + ulog, troubleshootinginmyownballs aka fascist firewall
- no sudo on the system
removing ALL setuid programs
- remote backup of log, rsyslog