Download securing-debian

Transcript
Kapitel 1. Einleitung
13
• Changed APACHECTL line in the Apache chroot example (even if its not used at all) as
suggested by Leonard Norrgard.
• Added a footnote regarding hardlink attacks if partitions are not setup properly.
• Added some missing steps in order to run bind as named as provided by Jeffrey Prosa.
• Added notes about Nessus and Snort out-of-dateness in woody and availability of backported packages.
• Added a chapter regarding periodic integrity test checks.
• Clarified the status of testing regarding security updates. (Debian bug 233955)
• Added more information regarding expected contents in securetty (since it’s kernel specific).
• Added pointer to snoopylogger (Debian bug 179409)
• Added reference to guarddog (Debian bug 170710)
• Apt-ftparchive is in apt-utils, not in apt (thanks to Emmanuel Chantreau for pointing this
out)
• Removed jvirus from AV list.
1.6.14
Version 2.98 (December 2003)
Changes by Javier Fernández-Sanguino Peña
• Fixed URL as suggested by Frank Lichtenheld.
• Fixed PermitRootLogin typo as suggested by Stefan Lindenau.
1.6.15
Version 2.97 (September 2003)
Changes by Javier Fernández-Sanguino Peña
• Added those that have made the most significant contributions to this manual (please
mail me if you think you should be in the list and are not).
• Added some blurb about FIXME/TODOs
• Moved the information on security updates to the beginning of the section as suggested
by Elliott Mitchell.
• Added grsecurity to the list of kernel-patches for security but added a footnote on the
current issues with it as suggested by Elliott Mitchell.