Linux Hardening Tips

Post on 22-Mar-2016

220 views 1 download

Tags:

description

Cheat sheet for Debian hardening

Transcript of Linux Hardening Tips

/sbin/iptables -L

/etc/hosts.allow /etc/hosts.deny.

# apt-get install openssh-client openssh-server

# ssh-keygen -l -f /etc/ssh/ssh_host_rsa_key.pub2048 44:c3:7c:1e:0c:f6:24:82:2f:b7:f8:83:93:1f:08:13/etc/ssh/ssh_host_rsa_key.pub

Protocol 2Port 222SilentDeny yesPasswordAuthentication noPermitRootLogin noRSAAuthentication yesAllowedAuthentications publickeyRequiredAuthentications publickeyMaxStartups 2

LoginGraceTime 30IdleTimeout 15mCiphers anycipherCiphers anystdcipherForwardAgent noForward X11 no

# What to do when CTRL-ALT-DEL is pressed.#ca:12345:ctrlaltdel:/sbin/shutdown -t1 -a -r nowca:12345:ctrlaltdel:/usr/bin/logger -s -p auth.notice -t [INIT]"CTRL+ALT+DEL caught but ignored! This is not a Windows(r) machine."

This manual is free software; you may redistribute it and/or modify it under the

terms of the GNU General Public License

(http://www.debian.org/releases/stable/amd64/apf.html.en)

serveur:~# apt-get update[...]serveur:~# apt-get dist-upgrade

password --md5 passwordhashSecuring Debian Manual ,”

http://www.debian.org/doc/manuals/securing-debian-howto/.

# /etc/init.d/openbsd-inetd stop

# update-rc.d -f openbsd-inetd remove

apt-get remove --purge acpid dhcp3-common dhcp3-client klogd

/sbin/grub-md5-crypt.

# /etc/fstab: static file system information.[...]/dev/ida/c1d1p3 /home ext3 defaults,nosuid 0 2/dev/ida/c1d1p1 /srv ext3 defaults 0 2/dev/ida/c1d1p2 /tmp ext3 defaults,nosuid 0 2[...]

# vi /etc/issue*********************Warning*********************Authorized uses only.All activity may be monitored and reported.*************************************************