MLUG: Re: [MLUG] Re: hacking for the grade
Re: [MLUG] Re: hacking for the grade
Email address obfuscation in effect -- please click here to turn it off.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
On Thu, 2 Mar 2006, Shawn Parker wrote:

i won't say 'impossible' simply because anything can be cracked given enough skill, time and effort. but, if you lock down a linux box by ensuring all unused ports are closed, all user accounts are configured correctly (permissions, access, etc) and you disable all unused daemons then it's certainly going to be tough to crack.

there have been exploitable code flaws in apache, mysql and php in recent months. not too mention if you don't lock mysql down right then sql injections could wreak havoc on your system and provide a back way in.

that said, i have a debian lamp box at my house that has survived 6+ months of daily brute force attempts and, i'm sure, other malicious attacks. i get ping of death warnings in my firewall logs sometimes.

so far, none of them have been successful. and, i'm by no means a security expert. i have faith in the security of linux.


I see it the same. If a new vulnerability opens up and someone happens to exploit it and attack my machine before I apply a security patch, then they'll get me. That doesn't happen very often and we have ways of coping with it. Thanks.

Mike

_______________________________________________
members mailing list
EMAIL:PROTECTED
http://mlug.missouri.edu/mailman/listinfo/members