Ads by TechWords

See your link here
Receive the latest technology news and information.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Reduce risk and simplify maintenance via minimal installs

January 20, 2003 12:00 PM ET

Computerworld - Bob, IT director: Joe, did you see the latest warnings from CERT today? There's a BIG security hole in one of the X Windows programs. I think it was "xterm." Yikes! We've got 50 servers sitting on the Net! And, I saw something about a service called "comsat," whatever that is.


Joe, system administrator: No, I didn't get to it yet. No big deal though.


Bob: What? The advisory said that anyone can use some exploits that are all over the Net to get root access on any box! Isn't that bad?


Joe: Yeah, it's very bad. But don't worry, we're covered.


Bob: How so?


Joe: I took care of this over a year ago. None of our 50 servers ever needed the X Windows software. So, I never installed it. It's a little hard to exploit something that doesn't exist. As for the comsat service, I disabled that the minute I set up the boxes. It's not necessary to run a "new e-mail" notification service on a server that no one uses directly.


Bob: So, no xterm program on the server, no exploit? No comsat service running, no hole?


Joe: Neat, eh?


As Joe could tell you, by eliminating unnecessary software and services, you can increase the security of your systems and potentially reduce the pain you have to endure when security exploits abound. To do this effectively, you must know your operating system and software products intimately, what each and every program does, and what you can eliminate or configure to avoid security exploits.


Minimize, Disable and Tighten


By knowing all that you can about the software you're using, from operating systems to applications, you can customize and tailor installations to include only the pieces you actually need. If you understand the intricacies of your operating system and software packages, you can go further and disable those pieces that you are forced to install but don't actually need. Lastly, you can go even further and tightly configure the software that you need to install in such a way that it is less likely to be compromised.


Here are some examples:


  • Minimize your operating system: Many Internet servers need only 20 or so of the over 100 modules available in Solaris. This is true of Linux as well.


  • Minimize your applications: Most Internet servers just don't need X Windows (perhaps one in 100 servers do).


  • Disable services: Disable RPC daemons when possible; many servers don't require them.


  • Tighten configurations: Restrict MySQL access to the local machine only (using its Unix domain socket support), if you can.



Jump to comments

Operating Systems

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

White Papers & Webcasts

High Performance for Integrating Massive Data Volumes
Processing very large data sets provides unique constraints, especially when time windows available for this processing are shrinking. This Technical White Paper presents...  

Gartner Podcast: Driving SharePoint Adoption in Lotus Notes Shops
Learn how can you drive mainstream user adoption of Microsoft SharePoint when your users are committed to using email.

IDC Webcast: Linux Adoption in a Global Recession
Access this webcast, compliments of Novell and HP, for a limited time only!

Whitepaper: Drive SharePoint Adoption in Lotus Notes Shops
Learn how you can drive your users to Microsoft SharePoint when they rely on IBM Lotus Notes.  


IT Jobs