📄 00000004.htm
字号:
<HTML><HEAD> <TITLE>BBS水木清华站∶精华区</TITLE></HEAD><BODY><CENTER><H1>BBS水木清华站∶精华区</H1></CENTER>发信人: cybergene (活泼的基因), 信区: Linux <BR>标 题: Linux Security: It's Not Just About Security <BR>发信站: BBS 水木清华站 (Sun Jan 9 10:23:27 2000) <BR> <BR> <BR>Linux Security: It's Not Just About Security <BR>jeff covey - January 08th 2000, 23:59 EST <BR>Jon Lasser began the Bastille Linux Project in order to harden the <BR>security of Red Hat Linux, the distribution he uses at work. In the <BR>process, he began looking at the other distributions to see how they <BR>handle security updates, and he was not at all happy with what he found. <BR> In today's editorial, he shares his concerns and explains why it <BR>matters to you even if you do all your security monitoring for yourself. <BR> <BR> <BR> <BR> <BR>------------------------------------------------------------------------ <BR>-------- <BR> <BR>Copyright notice: All reader-written material on freshmeat is the <BR>property and responsibility of its author; for reprint rights, please <BR>contact the author directly. <BR> <BR>------------------------------------------------------------------------ <BR>-------- <BR> <BR> <BR>As a professional Unix systems administrator, I'm concerned about system <BR> security. Keeping unauthorized users off my systems is simply part of <BR>my job; doing this requires vigilance in the form of monitoring <BR>performance, reading logs, and keeping patches up-to-date. For me, <BR>security is about security; it's about keeping my users' projects safe <BR>and keeping them comfortable despite a full-time connection to the <BR>Internet. <BR> <BR>As Lead Coordinator of the Bastille Linux Project, a hardening script <BR>for Red Hat Linux, I thought my job was to make Linux more secure so <BR>beginning users could easily keep their boxes secure. Often, new Linux <BR>users have no experience as system administrators or often even any <BR>experience with Unix. I thought the best way to tackle the problem was <BR>to make it easy to do the right thing. <BR> <BR>Recently, I've been asked lots of questions about Linux system <BR>security by reporters. Often, I'm put on the defensive right away: <BR>Does Linux have a security problem? Why is Linux less secure than <BR>other operating systems? Is open-source software inherently less <BR>secure than commercial systems? <BR> <BR>I usually begin by explaining that more holes are reported in <BR>open-source software before they're exploited, and that the number of <BR>actually-exploited holes is no greater -- perhaps even less -- than <BR>commercial software. I explain that one reason there are so many <BR>break-ins into Linux systems is that there are so many Linux systems <BR>on the Internet, and I explain that Linux can be as secure as any <BR>other operating system. <BR> <BR>But Linux does have a security problem. It's not a universal problem, <BR>but look at the following list of security Web sites, mailing lists, and <BR> update tools for some common Linux distributions: <BR> <BR> <BR>Red Hat Linux <BR><A HREF="http://www.redhat.com/support/errata">http://www.redhat.com/support/errata</A> <BR>redhat-watch-list-<A HREF="mailto:request@redhat.com">request@redhat.com</A> <BR>Update Agent available only to purchasers of Red Hat 6.1 <BR>Debian <BR><A HREF="http://www.debian.org/security">http://www.debian.org/security</A> <BR>debian-security-announce-<A HREF="mailto:REQUEST@lists.debian.org">REQUEST@lists.debian.org</A> <BR>apt-get update <BR>SuSE <BR><A HREF="http://www.suse.de/security">http://www.suse.de/security</A> <BR>suse-security-announce-<A HREF="mailto:subscribe@suse.com">subscribe@suse.com</A> <BR>No official tool for auto updates -- AutoRPM works on both SuSE and <BR>Red Hat. <BR>Mandrake <BR><A HREF="http://www.linux-mandrake.com/en/security.php3">http://www.linux-mandrake.com/en/security.php3</A> <BR><A HREF="mailto:symp@linux-mandrake.com">symp@linux-mandrake.com</A> <BR>MandrakeUpdate <BR>Caldera <BR><A HREF="http://www.calderasystems.com/support/security">http://www.calderasystems.com/support/security</A> <BR>announce-<A HREF="mailto:subscribe@lists.caldera.com">subscribe@lists.caldera.com</A> is not just security updates but <BR>also product announcements, press releases, etc. <BR>No official tool for automatic updates <BR>Corel <BR>No known web page for security <BR>No known mail list for security <BR>No known tool for security updates. 'apt-get update' probably works, <BR>as it's based on Debian Linux <BR>Turbo Linux <BR>No known web page for security <BR>No known mail list for security <BR>No known tool for security updates <BR>Slackware Linux <BR>No known web page for security <BR>No known mail list for security <BR>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -