Google Plus

Some Linux/Unix Security Guidelines

Written by Mel Kham on . Posted in Linux distributions, Uncategorized

Unix security  is  a big world including Software  and  hardware, there is no  guaranties to  make your  Unix system safe,  but you can make it very difficult for  the Crackers en Hackers; in this quick guide will show  you  some  simple  steps  to protect  your  system.

 1- Take Care With Passwords:

Use good ones (motherhood statement)

Don’t Use Real Words

Make Sure They Are Not Easily Guessed

Use Combinations Of Upper and Lower Case, Numbers, Punctuation One Method: Take first letter of a sentence or book title, insert numbers and punctuation.

 2- Use Shadow Passwords:

 Allows encrypted passwords to be in a file that is not world readable

3- Use Password Aging:

Requires shadow passwords

4- Restrict Superuser Access:

Restrict where root can log in from

/etc/security restricts root access to devices listed Use wheel group to restrict who can su to root Put users who can su to root in wheel group in /etc/group file.

 5- Use groups to allow access to files that must be shared:

 Otherwise users will set world permission

6- Be careful with SUID and SGID

Avoid setting executables to SUID root

Wrap SUID root wrapper around programs if they must be run SUID root Create special accounts for programs that must run with higher permissions

For questions please refer to our Q/A forum at : http://ask.unixmen.com

Mel Kham

Founder of Unixmen, Living in Amsterdam. Am working in my free time to help people to understand the Opensource and to explain them in easy way how to make the fist steps to the the light. Working day and night with my Co-founder Zinovsky to keep this website live even with less resources.
  • wzis

    Choose good password or pass phrase is important, but that’s just one part. Users of UNIX/Linux should also know that on UNIX/Linux systems, malicious person can use system call tracer, such as truss on Solaris/AIX, strace on Linux, tusc on HP-UX, to steal your password or pass phrase. Have a look http://wziss.com/demo/ssh%20sftp%20password%20security.mp4
    to understand the risks and try to find a solution.

Like us on Facebook

This week Top Posts

Write for us

Recent Comments

SK

|

I am working on it. Stay tuned. Thanks for the comment.

adriana rizzati

|

You are right, I saw them just now and they are awesome!

SK

|

Thanks for the comment Abdullah. Stay tuned with us always.

Abdullah Musazai

|

Thank you for such a great service you always do, hope you gain more power and more energy to work more & more

 
IDG Tech Network
Copyright © 2008-2013 Unixmen.com .
Maintained by Anblik .