Contact us

Sign up | United States |

Login

remember me

Go to my home page

Stay on current page

We will be undergoing scheduled maintenance on May 20th, 2013 at 02:00 GMT.

Host Security / Linux Host Lockdown Tools

Loading the player ...
View Full Size

Subtitles of the Movie (Using Security Tools / Host Security / Linux Host Lockdown Tools)

As secure as Linux host is, it's normally not as secure as you would like it to be when it's first installed so you may want to use various Linux host lockdown tools to lockdown your Linux distribution. Now, what these are is various tools used to lockdown the security configuration on a Linux box. Now, I would caution you that there are many different Linux distributions and as such, with Linux being an open source community, there are many different lockdown tools available. Some examples would be Bastille, which is a very popular Linux distribution tool that is used to lockdown various distributions of Linux and you can download that separately or it can be included in your Linux distribution. Some of the other distributions have various tools such as set check scripts and so forth that you can also download and use that are specific to distributions and some distributions even have tools included when you install them that will help you lockdown the various security configuration options on your Linux boxes; Red Hat, openSUSE, Gentoo, so forth. They all have their own unique tools that by and large are similar to most other tools out there so just that word of caution there that there are so many tools out there it's hard to nail down one particular tool that works across the board. So you're going to see various tools to do this with. Now, these tools configure various options automatically for security on your box and these could be things like file permissions, set get and set UID permissions and so forth, different things that you can use to secure your different security options and again, you'll see those on most Linux distributions. How you would use them, it really depends. Some of them are installed when you install the distribution, some of them you must download from a community repository or from a site and downloaded news. Bastille is one of them. You can download that from the Bastille site or a site that hosts Bastille and download it and install it of course. Let's just take a look at example tool that we'll see in openSUSE that's used to configure security on openSUSE in particular using YaST. Again, your tool may be different depending upon what distribution you're using. Let's go ahead and take a look at it. OK, we're in our YaST control center of our openSUSE 11 box and in YaST on open SUSE, you can control local security configuration through the local security applet that's in the security and users group. Again, this may differ based upon the distribution you're using; Red Hat, Gentoo, Mandriva and so forth all have similar utilities located in them; some GUI, some Command Line but they basically all do the same thing. Let's go ahead and take a look at the local security applet in YaST and so we can get an idea of how it configures security on an openSUSE distribution for example. It actually gives us different options we can use; a home work station, networked work station or network server so it is based on roles that your computer plays as to how it configures its settings and all these settings are basically the same; it's just by and large predetermined templates that it suggest, sort of like Windows templates do but based upon the role, we can configure different options. Let's go ahead and look at custom settings so we can look at all the wide variety of options you can set using this tool. So let's click Next and some of the options we can check are password settings, for example check new passwords and determine whether or not they're complicated or meet a particular password policy such as uppercase, lowercase and so forth or length and you can also configure the number of passwords to remember. For example, you don't want a user to use say the last ten passwords that they've used before. You want them to come up with a new password. You can also use different password encryption methods such as DES, MD5 or Blowfish. I would highly recommend you go with Blowfish. The minimum acceptable password length and we could use things like eight characters, which is a standard across the board. We could also minimum-age the passwords and make it so they can't change them before a certain amount of time has elapsed, say three days, and we can make it so they have to change their password every say 90 days and about seven days before they're going to get a warning saying that in seven days they're going to change their password. We can also change boot permissions on the, in the YaST tool, the interpretation of Control Alt Delete for example, whether it's going to reboot the system or it'll be ignored or whether it'll halt the system. We're going to leave that at the default and whether users can shut down the system from login manager. That's automatic, all users can do it, no one can do it or only root can do it. We'll stick with all users because right now all users should be able to shut down the system if we need to. A delay after incorrect login attempt; and so basically this is going to allow them to use incorrect logins only so many times and then their account may be locked or maybe disabled. Record successful login attempts in the security log and allow remote graphical login. We can turn that on or off as we please. Some other things we can do, this one we're adding users. We can automatically set the user ID and group ids. The reason you may want to do this is normally certain sets of user ids are reserved for privileged users so normal users may start at a certain user ID and by default openSUSE sits them as a thousand and a maximum of 60,000 and those are good defaults to leave them at. We can also change our file permissions so that by default they're easy permission; very relaxed or secure or very paranoid permissions and you may want to do this based upon the security level that you deem you need on your openSUSE box. We can also change other things such as path to add regular users into roots path so that when they sudo or su they can have access to root's path as well if we like. So those are some of the different options we can set using the local security settings in YaST and it's very similar to what you'll find on other Linux distributions. The tool may look a little bit different but you'll see those other options normally on there and also keep in mind that all these things can be done at the command prompt as well. You'll also see similar settings in various Windows tools as well so when configuring host or local security, there's different options but most of all you'll see those in various platforms; Windows, Linux and so forth. So that's just an example of one tool you can use to lockdown the host security of a Linux box.

Tutorial Information

Course: Using Security Tools
Author: Bobby Rogers
SKU: 34068
ISBN: 1-935320-88-2
Release Date: 2009-12-04
Duration: 9 hrs / 91 lessons
Captions: No
Compatibility: Vista/XP/2000, OS X, Linux
QuickTime 7, Flash 8

VTC Sign up & Benefits

  • Unlimited Access
  • 81,350 Video Tutorials (14,200 free)
  • Video Available as Flash or QuickTime
  • Over 715 Courses
  • $30 for One Month Access
  • Multi-User Discounts Available

VTC Terms and Conditions

TERMS & CONDITIONS OF USE

BY SUBSCRIBING TO THIS SERVICE, YOU ARE CONSENTING TO BE BOUND BY AND ARE BECOMING A PARTY TO THIS AGREEMENT, THE TERMS AND CONDITIONS OF WHICH SHALL PREVAIL IN GOVERNING YOUR RIGHTS OF USE. BY CLICKING THE "BECOME A MEMBER" BUTTON, THE INDIVIDUAL OR ENTITY LICENSING THE PRODUCT ("YOU") IS CONSENTING TO BE BOUND BY AND IS BECOMING A PARTY TO THIS AGREEMENT. IF LICENSEE DOES NOT AGREE TO ALL OF THE TERMS OF THIS AGREEMENT, THE BUTTON INDICATING "BECOME A MEMBER" MUST NOT BE SELECTED, AND LICENSEE MUST NOT INSTALL OR USE THE SOFTWARE.

1. DEFINITIONS

"VTC" refers to Virtual Training Company, Inc.
"You" refers to the user or subscriber.
"Software" refers to the VTC training content and software.

2. LICENSE: VTC hereby grants to You a worldwide, non-royalty bearing, non-exclusive license to use the Software according to the provisions contained herein and subject to payment of the applicable subscription fees.

3. RESTRICTIONS: You may not do any of the following:

Save the Software to Your hard disk or other storage medium; permit others to use the Software except as specified by addendum; modify, reverse engineer, decompile, or disassemble the Software; make derivative works based on the Software; publish or otherwise disseminate the Software. VTC, Inc., VTC Online University, and the Virtual Training Company site is owned and operated by VTC, Inc. as a corporation of record.
All materials on this site are the property of VTC unless otherwise specified. No material from these pages may be copied, reproduced, republished, downloaded, uploaded, posted, transmitted, or distributed in any way. Modification of the materials or use of the materials for any other purpose is a violation of U.S. copyright law and other proprietary rights. For purposes of this Agreement, the use of any such material on any other web site or networked computer environment is prohibited.

4. FEES: The rights granted under this Agreement are effective only upon payment of the subscription fees, which are strictly non-refundable other than as expressly provided herein. The term "monthly subscription" is defined as any 30 day period. The term "yearly subscription" is defined as one 365 day period. A yearly subscription ends on the same numerical date as it began (example July 28, 2004 to July 28, 2005).

The VTC Online University is access to every VTC training tutorial in our library. You pay a flat fee for access to these titles. You are billed according to your renewal selection below, and can renew monthly, yearly, or in any other increment offered. If you choose to be billed monthly, you will be billed every 30 days for the subscription until you request the subscription be cancelled. Our terms of service state that you must cancel a monthly subscription at least two business days before your renewal date. These two days give us enough time to ensure that you will not be charged again.

5. LIMITED WARRANTY: VTC warrants that the Software, if operated as directed, will substantially achieve the functionality described. VTC does not warrant, however, that Your use of the Software will be uninterrupted or that the operation of the Software will be error-free or secure. In addition, the security mechanisms implemented by the Software have inherent limitations, and You must determine that the Software sufficiently meets Your requirements. VTC also warrants that the media containing the Software, if provided by VTC, is free from defects in material from the date You acquired the Software. VTC's sole liability for any breach of this warranty shall be, in VTC's sole discretion: (i) to replace Your defective media or Software; or (ii) to advise You how to achieve substantially the same functionality with the Software as described; or (iii) if the above remedies are impracticable, to refund the subscription fee You paid for the Software. Only if You inform VTC of Your problem with the Software during the applicable subscription period will VTC be obligated to honor this warranty. VTC will use reasonable commercial efforts to repair, replace, advise, or refund pursuant to the foregoing warranty within thirty (30) days of being so notified. If any modifications are made to the Software by You during the warranty period; if the medium is subjected to accident, abuse, or improper use; or if You violate the terms of this Agreement, then this warranty shall immediately terminate. This warranty shall not apply if the Software is used on or in conjunction with hardware or software other than the unmodified version of hardware and software with which the Software was designed to be used as described.

THIS IS A LIMITED WARRANTY, AND IT IS THE ONLY WARRANTY MADE BY VTC OR ITS SUPPLIERS. VTC MAKES NO OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NONINFRINGEMENT OF THIRD PARTIES' RIGHTS. YOU MAY HAVE OTHER STATUTORY RIGHTS. HOWEVER, TO THE FULL EXTENT PERMITTED BY LAW, THE DURATION OF STATUTORILY REQUIRED WARRANTIES, IF ANY, SHALL BE LIMITED TO THE ABOVE LIMITED WARRANTY PERIOD. MOREOVER, IN NO EVENT WILL WARRANTIES PROVIDED BY LAW, IF ANY, APPLY UNLESS THEY ARE REQUIRED TO APPLY BY STATUTE NOTWITHSTANDING THEIR EXCLUSION BY CONTRACT. NO DEALER, AGENT, OR EMPLOYEE OF VTC IS AUTHORIZED TO MAKE ANY MODIFICATIONS, EXTENSIONS, OR ADDITIONS TO THIS LIMITED WARRANTY.

6. PROPRIETARY RIGHTS: VTC reserves all proprietary rights in and to the Software, is protected by copyright and other intellectual property laws and by international treaties. VTC, Inc.

Trademark Notice: VTC, Virtual Training Company, Inc., The VTC Logo, and VTC Online University, are trademarks of VTC, Inc. All other company and product names may be trademarks of their respective owners.
The information contained herein is subject to change without notice. Copyright © 1995 - 2005 VTC, Inc. All rights reserved.

7. TERMINATION: This Agreement shall automatically terminate if You fail to comply with the restrictions described herein. Your obligations to pay outstanding subscription fees shall survive any termination of this Agreement.

8. LIMITATION OF LIABILITY: UNDER NO CIRCUMSTANCES AND UNDER NO LEGAL THEORY, TORT, CONTRACT, OR OTHERWISE, SHALL VTC OR ITS SUPPLIERS OR RESELLERS BE LIABLE TO YOU OR ANY OTHER PERSON FOR ANY INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES OF ANY CHARACTER, INCLUDING WITHOUT LIMITATION, DAMAGES FOR LOSS OF GOODWILL, WORK STOPPAGE, COMPUTER FAILURE OR MALFUNCTION, OR ANY AND ALL OTHER COMMERCIAL DAMAGES OR LOSSES. IN NO EVENT WILL VTC BE LIABLE FOR ANY DAMAGES IN EXCESS OF THE AMOUNT VTC RECEIVED FROM YOU FOR A LICENSE TO THE SOFTWARE, EVEN IF VTC SHALL HAVE BEEN INFORMED OF THE POSSIBILITY OF SUCH
DAMAGES, OR FOR ANY CLAIM BY ANY OTHER PARTY. THIS LIMITATION OF LIABILITY SHALL NOT APPLY TO LIABILITY FOR DEATH OR PERSONAL INJURY RESULTING FROM VTC'S NEGLIGENCE TO THE EXTENT APPLICABLE LAW PROHIBITS SUCH LIMITATION. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION OF INCIDENTAL OR CONSEQUENTIAL DAMAGES, SO THIS EXCLUSION AND LIMITATION MAY NOT APPLY TO YOU.

9. Links To Other Materials: Linked sites found at the VTC site are not under the control of VTC, and we are not responsible for the content of any linked site or any link contained in a linked site. VTC may change links based solely on our discretion, and we reserve the right to terminate any link or linking program at any time. VTC does not, by linking to sites, endorse companies or products to which it links and reserves the right to note as such on its web pages. If you decide to access any of the third party sites linked to this site, you do this entirely at your own risk.

Forums, and Chat are not always screened by VTC, and we are not responsible for the content of any public or open forum content at the site. VTC may change these public forums based solely on our discretion, and we reserve the right to terminate any forum at any time. VTC does not, by allowing these forums, endorse companies or products which may be mentioned in these forums, and reserves the right to note as such on its web pages. If you decide to access any of the public forums in this site, or linked to this site, you do this entirely at your own risk.

9. GOVERNING LAW & DISPUTE RESOLUTION: This Agreement is governed by Virginia law. All disputes between You and VTC shall be finally resolved through arbitration in Winchester, Virginia. This site is controlled by VTC from its offices within the United States of America. VTC makes no representation that materials in the site are appropriate or available for use in other locations, and access to them from territories where their content is illegal is prohibited. Those who choose to access this site from other locations do so on their own initiative and are responsible for compliance with applicable local laws. You may not use or export the Materials in violation of U.S. export laws and regulations. Any claim relating to the Materials shall be governed by the internal substantive laws of the Commonwealth of Virginia, USA.

VTC may revise these Terms at any time by updating this posting. You should visit this page from time to time to review the then-current Terms because they are binding on you. Certain provisions of these Terms may be superseded by expressly designated legal notices or terms located on particular pages at this Site.

If you have any questions regarding this policy, or your information specifically,
you may email us at:
admin@vtc.com.