Information Technology News
Hardening Linux | Hardening Linux |
|
| by David M Williams | |
| Sunday, 12 August 2007 | |
|
Page 2 of 3 As mentioned, xinetd handles services which may only have periodic use and for which it would be wasteful to run independent listening processes for each and every one. The ramification of this is that services which do have anticipated high use are running stand-alone and from system boot, and which are not controlled by xinetd.Featured Whitepaper
5 Best Practices for Smartphone Support
This stops the process running immediately. However, as yet there’s nothing to stop it starting again when you next reboot. To solve this enter the command ntsysv. This is a simple tool to configure Linux runlevels and the services that run at each runlevel. Merely uncheck the box next to Apache, and similarly for any other services that auto-run which you do not use. A text tool to achieve the same thing, albeit with more skill required, is chkconfig. Patching the OS An essential requirement to maintaining security is to keep your operating system up-to-date. This ensures you receive updates to fix known exploits and vulnerabilities, as well as bug fixes and performance and feature enhancements.
Most Linux vendors provide information on available updates. For instance, Red Hat publish their list at www.redhat.com/security/updates/notes. (Information on Red Hat’s update and support policies, including how to sign up for automatic notification of errata is at www.redhat.com/security/updates.)
Pleasantly, you’re also not locked in to Bastille’s changes should you decide some of the setting changes weren’t for you. Running RevertBastille automatically restores the state of all config files and settings to just how they were before Bastille made any changes. Obviously, if you make changes to your system manually after running Bastille, you will lose these too so it is best to test changes as soon as possible after applying to ensure you won’t harm anything else if you need to revert.
|
| < Next story in category | Previous story in the category > |
|---|






