[5597] in RedHat Linux List
Re: RedHat4.0 security
daemon@ATHENA.MIT.EDU (Alex Mottram)
Fri Nov 22 15:59:26 1996
Date: Fri, 22 Nov 1996 10:00:32 -0600 (CST)
From: Alex Mottram <alex@net-connect.net>
To: Erik Troan <ewt@redhat.com>
cc: redhat-list@redhat.com
In-Reply-To: <Pine.LNX.3.93.961121184224.21340A-100000@redhat.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
On Thu, 21 Nov 1996, Erik Troan wrote:
> > PS Let's see how many suid-bit removals these discussions can cause :)
>
> /usr/X11R6/bin/SuperProbe is number one
>
> Erik
A suggestion for the "things to consider box." How about an option in
the setup program for different types of Network setups (and different
levels of "security"). I.e:
Desktop Workstation - SUID anything you like. Basically one or a few
trusted users logging in at the console.
Networked Workstation - trim the sticky bits a bit. rip a bunch of the
finger, rsh, rexec junk out of inetd.conf.
Network Server - Only suid things that absolutely need to be (i.e. no
suid mount/umount, etc..
etc...
Personally, I feel that the machine is only as secure as the person who
sets it up lets it be. No matter what happens, I'm still going to rip
the sticky bits off of nearly everything anyway. :)
More things for the wishlist:
Non-X config tools. (aside from "bash" and "vi" :) )
Config tool for inetd.conf.
Thanks!
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null