Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

user friendly

  linux-magazine.com » Issues » 2008 » 91 » PREVENTION  

Print this page. Recommend
Slashdot it! Delicious Digg

Staying one step ahead of the intruders

PREVENTION

Author(s): Tim Schürmann and Joe Casad

Internet intruders have many ingenious ways of escalating privileges and hiding their presence once they get inside your system. The best protection is to keep them out in the cold.

Just when you think you’ve mastered the art of intrusion protection, the cyber-criminals discover new some techniques for slipping through your security. Attackers use every possible advantage to stay hidden and gain control. Shouldn’t you use every trick to keep them out?

This month’s cover story focuses on techniques for keeping intruders off your system. In our lead-off article, “Who's There: Single Packet Port Knocking with fwknop,” we study a powerful technique that lets you keep your firewall ports closed to all unauthorized users – but still open to traffic from friends. The next article, “Closing the Book: Fighting Dictionary Attacks with Sshutout and Fail2ban,” discusses a pair of tools that will help you keep intruders from guessing your passwords.

Next, we show you how to apply more flexible and precise permissions to files and other objects using Access Control Lists (ACLs). We end with a workshop on the powerful security tool known as SELinux.


Read full article as PDF »


Comments


Print this page. Recommend
Slashdot it! Delicious Digg
Related Articles
Ask Klaus!
Ask Klaus!
SECURITY HARDENED Mandatory Access Control with SELinux
COUNTERPOINT Novell and Red Hat security experts face off on AppArmor and SELinux
BREAKING IN AND KEEPING OUT Kernel 2.6 rootkits and the quest for Linux security
PROTECTIVE ARMOR Shutting out intruders with AppArmor
ApacheCon US video archive

All about Apache in 19 talks

Watch 19 talks from the ApacheCon US in New Orleans from the convenience of your home or office. Topics are: Scaling Apache 2.x in all dimensions, Securing Communications with your Apache HTTP Server, Scripting your Java Application with BSF 3.0 and much more.

Find out more

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux-Nachrichten] [Linux Events]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Darmowe Programy Poland] [Open Source DVD Poland] [Linux Magazin Romania]
International: [Linux Magazine Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]