Welcome, Guest. Please login or register.

Author Topic: Server Hardening Checklist for Red Hat  (Read 655 times)

Offline Adi Sunardy

  • The man who sold the world
  • Administrator
  • Hero Member
  • *****
  • Posts: 595
  • Just an Ordinary Man

  • Activity
    0.6%
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.5 Firefox 3.0.5
    • sharing is caring
Server Hardening Checklist for Red Hat
« on: February 04, 2009, 01:20:54 PM »
Sebagai seorang sysadmin, kita diharuskan untuk selalu memperhatikan sisi sekuriti dari server-server yang kita administering...(halah, gak tau benar apa gak istilahnya neh :)))

Beberapa rekomendasi checklist yang bisa kita gunakan sebagai referensi dapat dilihat di sini: You are not allowed to view links. Register or Login

Untuk Operating System yang lain bisa di cek disini:

Untuk mengaplikasikan standar sekuriti tersebut, di Red Hat Linux, kita bisa saja melakukannya dengan script bash sederhana, seperti contoh:

Code: You are not allowed to view links. Register or Login
#setup time out in /etc/profile;
cp /etc/profile /etc/profile.orig;
echo "TMOUT=600" >> /etc/profile;
echo "export TMOUT" >> /etc/profile;

#setup /etc/bashrc;
cp /etc/bashrc /etc/bashrc.orig;
sed 's/umask 002/umask 027/g' /etc/bashrc > /tmp/buffer;
cat /tmp/buffer > /etc/bashrc;
sed 's/umask 022/umask 027/g' /etc/bashrc > /tmp/buffer;
cat /tmp/buffer > /etc/bashrc;

#setup /etc/ntp.conf;
cp /etc/ntp.conf /etc/ntp.conf.orig;
sed '/server/d' /etc/ntp.conf > /tmp/buffer;
cat /tmp/buffer > /etc/ntp.conf;
echo "server ntp.domain.com" >> /etc/ntp.conf;

#setup /etc/syslog.conf;
cp /etc/syslog.conf /etc/syslog.conf.orig;
echo "*.info    syslog.domain.com" >> /etc/syslog.conf;

#setup /etc/resolv.conf;
cp /etc/resolv.conf /etc/resolv.conf.orig;
echo "search domain.com" > /etc/resolv.conf;
echo "nameserver dns1.domain.com" >> /etc/resolv.conf;
echo "nameserver dns2.domain.com" >> /etc/resolv.conf;

#disabled unimportant service;
chkconfig sendmail off;
chkconfig vsftpd off;
chkconfig telnet off;
chkconfig bluetooth off;
chkconfig cpuspeed off;
chkconfig cups off;

#disable PermitRootLogin /etc/ssh/sshd_config
cp /etc/ssh/sshd_config /etc/ssh/sshd_config.orig;
sed 's/#PermitRootLogin yes/PermitRootLogin no/g' /etc/ssh/sshd_config > /tmp/buffer;
cat /tmp/buffer > /etc/ssh/sshd_config;

Konfigurasi di atas bisa disesuaikan dengan kebutuhan atau requirement di masing-masing network environtment. (Susah euy...kalau istilah-istilah IT di Indonesiakan...kira-kira bisa diartikan sebagai Lingkungan Kerja).
« Last Edit: February 04, 2009, 01:22:50 PM by Adi Sunardy »
Jabat Erat,


Adi Sunardy
You are not allowed to view links. Register or Login

lili

  • Guest
Re: Server Hardening Checklist for Red Hat
« Reply #1 on: February 15, 2009, 11:57:26 PM »
Guys (Admin), do you apply the security system in this forum?

Offline Adi Sunardy

  • The man who sold the world
  • Administrator
  • Hero Member
  • *****
  • Posts: 595
  • Just an Ordinary Man

  • Activity
    0.6%
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.6 Firefox 3.0.6
    • sharing is caring
Re: Server Hardening Checklist for Red Hat
« Reply #2 on: February 16, 2009, 08:52:42 AM »
Security system di forum ini lebih mengacu ke standar Securitynya SMF. Ditambah hardening di beberapa sisi dengan perubahan-perubahan modul.

Untuk security yang dimaksud diatas, tidak bisa kita yang olah...server nya kan bukan punya kita :D kita cuma kebagian hosting (web server) yang securitynya mengacu (inhirited) dari main server. Tapi sepengetahuan aku termasuk hasil ngobrol sama yang punya server, securitynya bisa dikasih poin 7 lah....

Untuk SMF sendiri, kita terus memantau perkembangannya di forum-forum SMF mengenai security, bug dan updatenya.

Kalau Bu Lili punya issue mengenai security ini, terutama mengenai SMF, sudi kiranya menginformasikannya kepada kita sehingga bisa di follow up...thx ya...
Jabat Erat,


Adi Sunardy
You are not allowed to view links. Register or Login

 
Share this topic...
In a forum
(BBCode)
In a site/blog
(HTML)


Related Topics

  Subject / Started by Replies Last post
0 Replies
133 Views
Last post July 03, 2010, 01:07:41 PM
by staff forum EUS
0 Replies
182 Views
Last post July 23, 2010, 07:05:11 AM
by staff forum EUS
0 Replies
386 Views
Last post December 23, 2010, 07:37:10 PM
by staff forum EUS
0 Replies
211 Views
Last post January 17, 2011, 01:09:28 AM
by staff forum EUS
0 Replies
29 Views
Last post March 06, 2012, 07:03:04 PM
by Forum Poster