Security Basics mailing list archives
Re: security advice
From: Robert Larsen <robert () the-playground dk>
Date: Wed, 25 Aug 2010 12:22:00 +0200
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Not knowing how you work makes your question hard to answer but a few quick ones: * Keep the system up to date (apt-get update && apt-get upgrade or similar) * Install a host based intrusion detection system like Tripwire or AIDE * Install a network based intrusion detection system like Snort * Harden your installations with something like Bastille * Run your system from a read-only filesystem and having only your mail folders on writable media. Mount the writable media with noexec. * Have lots of graphs showing the typical behaviour (load, memory usage, network traffic, etc.) so that you can spot "weird" changes (rrdtool for instance) * Monitor your network services with something like Nagios (so that your users won't have to tell you that something isn't right) * Monitor your logs with something like logwatch Just my 2 cents worth -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAkx07sgACgkQzDMeisFqGZaRSwCg1zVbepwFr2PBHfd4qVUJBpWF OVAAoKRqGxUvlRTF+ba518bHGa5WOnd8 =Ug/W -----END PGP SIGNATURE----- ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
Current thread:
- security advice Edmund (Aug 24)
- Re: security advice irado furioso com tudo (Aug 24)
- Re: security advice Todd Haverkos (Aug 24)
- RE: security advice Andrei Popescu (Aug 25)
- Re: security advice Erik (Aug 26)
- RE: security advice Andrei Popescu (Aug 25)
- RE: security advice Murda (Aug 25)
- Re: security advice Robert Larsen (Aug 25)
- Re: security advice debiantech (Aug 25)
- RE: security advice Grant, Richard (KYTC) (Aug 25)
- <Possible follow-ups>
- Re: security advice Mike Razzell (Aug 25)