Dave - Dave.net.nz wrote:
> It seems to get discussed fairly frequently about securing a box is all
> about the admins ability.
>
> Well a close friend of mine, and BSD/Linux admin for a living, decided
> to setup a Windows box for serving some game or other, and not once, but
> twice got blaster(two tries)... it appears that he didn't realise that
> Windowsupdate existed, or how to shut off remote services in windows,
> weird.
>
> Now I must say that Im pretty much the other way inclined, Windows
> security is easy to me, BSD/Linux on the other hand confuses me.
>
> Anyway, the machine is now up and running, fully patched, and doing the
> miniscule(reletive) amount of traffic that it is meant to be, instead of
> the 24Mbit constant it had flooded the rest of the network with.
>
>
> I've since passed him my Linux box and got him to update it, and show me
> how, and I introduced him to Windowsupdate, services and firewall etc.
When Bill Gates says (or used to say) Windows is easy to install, he is
right, (its no easier than Linux). As usual its a half truth, building
is pretty easy, what it takes is someone who; wants to, and can secure
the box (whether they do not know how, are not given time/tools etc).
I know of a recent external security audit on a company, which the main
site passed. A subsidary run by "guru's" failed, while they had the
capability to patch and maintain easily they did not. It was I guess
beneath them, something I have noticed too much in olde unix people,
complacancy mixed with arrogance.
www.cisecurity.org has a good linux hardening howto document, I am in
the process of in-corporating it into a rh kickstart build...I will post
how to on my web site when done.
regards
Thing