Sysadmin:Security Todo

From UGCS
Revision as of 06:16, 5 February 2008 by Jdhutchin@ugcs.caltech.edu (Talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Contents

Monitoring services

  • Tripwire
  • Process accounting, especially on Kerberos and AFS servers
  • Other intrusion detection

Security Libraries

  • libpam-tmpdir
  • Check the wrapper scripts for php and cgi scripts

Configuration changes

Policy Changes

  • Keep researching breaking vectors
  • Check login machine's auth.log to look for root accesses
  • Check core server login logs
  • Implement password expiration for sysadmins
  • Bootloader passwords

SSH

Personal tools