Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Reduce risk and simplify maintenance via minimal installs

January 20, 2003 12:00 PM ET

Computerworld - Bob, IT director: Joe, did you see the latest warnings from CERT today? There's a BIG security hole in one of the X Windows programs. I think it was "xterm." Yikes! We've got 50 servers sitting on the Net! And, I saw something about a service called "comsat," whatever that is.


Joe, system administrator: No, I didn't get to it yet. No big deal though.


Bob: What? The advisory said that anyone can use some exploits that are all over the Net to get root access on any box! Isn't that bad?


Joe: Yeah, it's very bad. But don't worry, we're covered.


Bob: How so?


Joe: I took care of this over a year ago. None of our 50 servers ever needed the X Windows software. So, I never installed it. It's a little hard to exploit something that doesn't exist. As for the comsat service, I disabled that the minute I set up the boxes. It's not necessary to run a "new e-mail" notification service on a server that no one uses directly.


Bob: So, no xterm program on the server, no exploit? No comsat service running, no hole?


Joe: Neat, eh?


As Joe could tell you, by eliminating unnecessary software and services, you can increase the security of your systems and potentially reduce the pain you have to endure when security exploits abound. To do this effectively, you must know your operating system and software products intimately, what each and every program does, and what you can eliminate or configure to avoid security exploits.


Minimize, Disable and Tighten


By knowing all that you can about the software you're using, from operating systems to applications, you can customize and tailor installations to include only the pieces you actually need. If you understand the intricacies of your operating system and software packages, you can go further and disable those pieces that you are forced to install but don't actually need. Lastly, you can go even further and tightly configure the software that you need to install in such a way that it is less likely to be compromised.


Here are some examples:


  • Minimize your operating system: Many Internet servers need only 20 or so of the over 100 modules available in Solaris. This is true of Linux as well.


  • Minimize your applications: Most Internet servers just don't need X Windows (perhaps one in 100 servers do).


  • Disable services: Disable RPC daemons when possible; many servers don't require them.


  • Tighten configurations: Restrict MySQL access to the local machine only (using its Unix domain socket support), if you can.



Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...  

IDC Webcast: Linux Adoption in a Global Recession
Join Al Gillen from IDC and Michael Applebaum from Novell in this on-demand webcast to see how Linux has emerged as an even...

ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...  

Bringing Order and Security to your Mobile Workforce: Corporate Mobility Policy and Device Management
(Source: Nokia) In many businesses, mobile devices are managed the way that laptops were managed ten years ago - as a kind of...

Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....