Finding Linux Security Holes

(URL: )

By Mark Fincher and Ray Bruni
VARBusiness


2:58 PM EDT Mon. Jul. 29, 2002


Taking security seriously has become a necessity these past few years. KeyLabs regularly puts servers on the Internet to see how long it takes before the first hack attempt. Our record for the shortest time is 17 seconds. In that case, you wouldn't even have time to download the latest patches before someone started poking around, trying to see what was exposed.

KeyLabs aimed its own Internet-vulnerability scanning tool at the default installations of each distribution to see how exposed they are.

All sorts of services and configuration settings can harden a system from Internet attacks, so our focus was on default installations. When possible, we accepted the default installer recommendation. Upon completion of the install, we configured an IP address and ran the KeyLabs vulnerability-scanning tool, an enhanced version of the Nessus 1.2.0 scanning engine.

Full vulnerability scan reports are available on KeyLabs' Web site.

Vendor-by-Vendor View of Security
Up Close With the Distributions
Methodology


Copyright 2009 Everything Channel