Open Network Architecture is commited to using paper with the highest recycled content 1Z0-133 available consistent with high quality.

This book is dedicated to OpenNA staff. Thanks, guys (no-gender)!! –Gerhard Mourani This book is printed on acid-free paper with 85% recycled content, 15% post-consumer waste. Open Network Architecture is commited to using paper with the highest recycled content  1Z0-133 available consistent with high quality.

Copyright ?2002 by Gerhard Mourani and Open Network Architecture, Inc.
All rights reserved. No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning or otherwise, except as permitted by Canada Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-copy fee to the copyright holders Gerhard Mourani and Open Network Architecture, Inc. 11090 Drouart, Montreal, PQ H3M 2S3, (514) 978-6183, fax (514) 333-0236. Requests to the Publisher for permission should be addressed to the Publishing Manager, at Open Network Architecture, Inc., E-mail: [email protected] This publication is designed to provide accurate and authoritative information in regard to the subject matter covered. It is sold with the understanding that some grammatical mistakes could have occurred but this won’t jeopardize the content or the issue raised herewith. Title: Securing and Optimizing Linux: The Hacking Solution Page Count: 1208 Version: 3.0 Last Revised: 2002-06-26 Publisher: Open Network Architecture, Inc. Editor: Ted Nackad Text Design & Drawings (Graphics): Bruno Mourani Printing History: June 2000: First Publication. Author’s: Gerhard Mourani Mail: [email protected] Website: http://www.openna.com/ National Library Act. R.S., c. N-11, s. 1. Legal Deposit, 2002 Securing and Optimizing Linux: The Hacking Solution / Open Network Architecture, Inc. Published by Open Network Architecture, Inc., 11090 Drouart, Montreal, H3M 2S3, Canada. Includes Index. ISBN 0-9688793-1-4 Printed in Canada

1

Overview
Part I
Chapter 1 Chapter 2

Installation Security
Introduction Installation Issues

Part II
Chapter 3 Chapter 4 Chapter 5 Chapter 6 Chapter 7

System Security & Optimization
General Security Pluggable Authentication Modules General Optimization Kernel Security & Optimization Process File System Management

Part III Network Security
Chapter 8 Chapter 9 Chapter 10 Chapter 11 Chapter 12 Chapter 13 TCP/IP Network Management Firewall Basic Concept GIPTables Firewall Squid Proxy Server SquidGuard Filter FreeS/WAN VPN

Part IV Cryptography & Authentication
Chapter 14 Chapter 15 Chapter 16 Chapter 17 GnuPG OpenSSL OpenSSH Sudo

Part V

Monitoring & System Integrity
sXid LogSentry HostSentry PortSentry Snort Tripwire

Chapter 18 Chapter 19 Chapter 20 Chapter 21 Chapter 22 Chapter 23

Part VI Super-Server
Chapter 24 Chapter 25 UCSPI-TCP Xinetd

Part VII Management & Limitation
Chapter 26 Chapter 27 NTP Quota

Part VIII Domain Name System & Dynamic Host Protocol
Chapter 28 Chapter 29 ISC BIND & DNS ISC DHCP

Part IX Mail Transfer Agent Protocol
Chapter 30 Chapter 31 Exim Qmail

2

Part X

Internet Message Access Protocol
tpop3d UW IMAP Qpopper

Chapter 32 Chapter 33 Chapter 34

Part XI
Chapter 35 Chapter 36 Chapter 37

Anti-Spam & Anti-Virus
SpamAssassin Sophos AMaViS

Part XII Database Server
Chapter 38 Chapter 39 Chapter 40 MySQL PostgreSQL OpenLDAP

Part XIII File Transfer Protocol
Chapter 41 Chapter 42 ProFTPD vsFTPD

Part XIV Hypertext Transfer Protocol
Chapter 43 Chapter 44 Chapter 45 Apache PHP Mod_Perl

Part XV NetBios Protocol
Chapter 46 Samba

Part XVI Backup
Chapter 47 Tar & Dump

Part XVII Appendixes Appendix A
Tweaks, Tips and Administration Tasks

Appendix B
Port list

3

Contents
Steps of installation Author note Audience These installation instructions assume Obtaining the example configuration files Problem with Securing & Optimizing Linux Acknowledgments 13 13 14 15 15 15 15

Introduction

19
21 21 21 22 22 23 24 25

What is Linux? Some good reasons to use Linux Let’s dispel some of the fear, uncertainty, and doubt about Linux Why choose pristine source? Compiling software on your system Build & install software on your system Editing files with the vi editor tool Recommended software to include in each type of servers

Installation Issues

29
31 31 33 34 35 39 50 53 53 56 57 65 66 66

Know your Hardware! Creating the Linux Boot Disk Beginning the installation of Linux Installation Class and Method (Install Options) Partition your system for Linux Disk Partition (Manual Partitioning) Selecting Package Groups Boot Disk Creation How to use RPM Commands Starting and stopping daemon services Software that must be uninstalled after installation of the server Remove unnecessary documentation files Remove unnecessary/empty files and directories Software that must be installed after installation of the server

General Security 73
BIOS Unplug your server from the network Security as a policy Choose a right password The root account Set login time out for the root account Shell logging The single-user login mode of Linux Disabling Ctrl-Alt-Delete keyboard shutdown command Limiting the default number of started ttys on the server The LILO and /etc/lilo.conf file The GRUB and /boot/grub/grub.conf file The /etc/services file 75 75 76 76 77 77 78 79 79 80 80 82 84

4

The /etc/securetty file Special accounts Control mounting a file system Mounting the /usr directory of Linux as read-only Tighten scripts under /etc/init.d Tighten scripts under /etc/cron.daily/ Bits from root-owned programs Don’t let internal machines tell the server what their MAC address is Unusual or hidden files Finding Group and World Writable files and directories Unowned files Finding .rhosts files Physical hard copies of all-important logs Getting some more security by removing manual pages System is compromised!

85 85 88 89 91 91 91 93 94 95 96 96 97 99 100

Pluggable Authentication Modules

101
103 105 105 106 107 109 111 112 113

The password length Disabling console program access Disabling all console access The Login access control table Tighten console permissions for privileged users Putting limits on resource Controlling access time to services Blocking; su to root, by one and sundry Using sudo instead of su for logging as super-user

General Optimization

116
118 119 120 121 122 127 128

Static vs. shared libraries The Glibc 2.2 library of Linux Why Linux programs are distributed as source Some misunderstanding in the compiler flags options The gcc specs file Striping all binaries and libraries files Tuning IDE Hard Disk Performance

Kernel Security & Optimization

133
135 138 139 141 141 142 143 145 190 190 192 194 195 195

Difference between a Modularized Kernel and a Monolithic Kernel Making an emergency boot floppy Preparing the Kernel for the installation Applying the Grsecurity kernel patch Obtaining and Installing Grsecurity Tuning the Kernel Cleaning up the Kernel Configuring the Kernel Compiling the Kernel Installing the Kernel Verifying or upgrading your boot loader Reconfiguring /etc/modules.conf file Rebooting your system to load the new kernel Delete programs, edit files pertaining to modules

5

Making a new rescue floppy for Modularized Kernel Making a emergency boot floppy disk for Monolithic Kernel

196 196

Process file system management

199
202 202 209 211 219

What is sysctl? /proc/sys/vm: The virtual memory subsystem of Linux /proc/sys/fs: The file system data of Linux /proc/sys/net/ipv4: IPV4 settings of Linux Other possible optimization of the system

TCP/IP Network Management

225
228 232 233 237 240

TCP/IP security problem overview Installing more than one Ethernet Card per Machine Files-Networking Functionality Testing TCP/IP Networking The last checkup

Firewall Basic Concept 241
What is the IANA? The ports numbers What is a Firewall? Packet Filter vs. Application Gateway What is a Network Firewall Security Policy? The Demilitarized Zone Linux IPTables Firewall Packet Filter The Netfilter Architecture 243 243 245 245 247 248 249 249

GIPTables Firewall 255
Building a kernel with IPTables support Compiling – Optimizing & Installing GIPTables Configuring GIPTables /etc/giptables.conf: The GIPTables Configuration File /etc/rc.d/rc.giptables.blocked: The GIPTables Blocked File /etc/init.d/giptables: The GIPTables Initialization File The GIPTables Firewall Module Files How GIPTables parameters work? Running the type of GIPTables firewall that you need The GIPTables configuration file for a Gateway/Proxy Server GIPTables-Firewall Administrative Tools 259 262 263 263 274 275 276 277 283 284 302

Squid Proxy Server 305
Compiling – Optimizing & Installing Squid Configuring Squid Running Squid with Users Authentication Support Securing Squid Optimizing Squid Squid Administrative Tools The cachemgr.cgi program utility of Squid 309 313 326 330 333 333 335

6

SquidGuard Filter 337
Compiling – Optimizing & Installing SquidGuard Configuring SquidGuard Testing SquidGuard Optimizing SquidGuard 340 342 350 351

FreeS/WAN VPN 355
Compiling – Optimizing & Installing FreeS/WAN Configuring FreeS/WAN Configuring RSA private keys secrets Requiring network setup for IPSec Testing the FreeS/WAN installation 360 363 367 372 374

GnuPG

379
382 384

Compiling – Optimizing & Installing GnuPG Using GnuPG under Linux terminal

OpenSSL

391
396 398 404 409

Compiling – Optimizing & Installing OpenSSL Configuring OpenSSL OpenSSL Administrative Tools Securing OpenSSL

OpenSSH

411
414 417 427 432 434

Compiling – Optimizing & Installing OpenSSH Configuring OpenSSH Running OpenSSH in a chroot jail Creating OpenSSH private & public keys OpenSSH Users Tools

Sudo

437
440 442 444 447 447

Compiling – Optimizing & Installing Sudo Configuring Sudo A more complex sudoers configuration file Securing Sudo Sudo Users Tools

sXid

451
454 455 457

Compiling – Optimizing & Installing sXid Configuring sXid sXid Administrative Tools

LogSentry

459

7

Compiling – Optimizing & Installing LogSentry Configuring LogSentry

462 466

HostSentry

467
470 474

Compiling – Optimizing & Installing HostSentry Configuring HostSentry

PortSentry

481
484 487 494

Compiling – Optimizing & Installing PortSentry Configuring PortSentry Removing hosts that have been blocked by PortSentry

Snort

495
499 501 507

Compiling – Optimizing & Installing Snort Configuring Snort Running Snort in a chroot jail

Tripwire

511
514 517 526 528 528

Compiling – Optimizing & Installing Tripwire Configuring Tripwire Running Tripwire for the first time Securing Tripwire Tripwire Administrative Tools

ucspi-tcp

533
536 538

Compiling – Optimizing & Installing ucsip-tcp Using ucsip-tcp

Xinetd

541
544 546 547

Compiling – Optimizing & Installing Xinetd Configuring Xinetd The /etc/xinetd.d directory

NTP

559
564 566 566 572 574 578

Compiling – Optimizing & Installing NTP Configuring NTP Running NTP in Client Mode Running NTP in Server Mode Running NTP in a chroot jail NTP Administrative Tools

Quota

581
584 584

Build a kernel with Quota support enable  1z0-133 dumps Compiling – Optimizing & Installing Quota

8

Comments are closed