PaulDotCom mailing list archives

home firewall/server


From: mailing at vankets.com (Bert Van Kets)
Date: Tue, 14 Jul 2009 10:00:40 +0200

I'm not paranoid, just realistic. ;-)

The question I still have is whether a combination of a fully patched
system, IPTables, SELinux and OSSec is as good as the "ready to
configure" packages. What's the added value of those things?

Bert

Pat wrote:
This all depends on how paranoid you are


http://bastille-linux.sourceforge.net/

Kernel patches:
http://www.securityfocus.com/infocus/1539
http://www.openwall.com/linux/

https://wiki.ubuntu.com/SELinux

friend of mines page on bsd jailsa in linux:
http://www.marlow.dk/site.php/tech/vserver

Host based IDS?
Tripwire is old now
OSSEC HIDS


Firewall rules using IPTABLES?
There are addons for more advanced functionality here two


*_
So how paranoid are you?_*




------------------------------------------------------------------------

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com



Current thread: