[huskerlug] Re: CERT Advisory

Every time I start to feel like a dummy, for not
knowing as much as everybody else, someone in that
crowd describes something I've been doing for over
three years, since going onto broadband!  Stand alone
firewall/router, microshaft computer system on it's
own node, GNU/Linux-BSD LAN on the major hub, and no
two computers run the same distro! Everything
up-dated...
Cluster isolated to a sub-LAN...  and, this is just my
HOME SYSTEM!  

--- Jeff Ives <jives2@xxxxxxx> wrote:
> My comments is more about people looking for "one"
> security measure, =
> "one"
> perfect OS, "one"... And simply there is no such
> thing. It's all about =
> risk
> management vs. functionality. Plus never over look
> any part because it's =
> the
> simple exploits that get you most times.
> 
> I like dividing up tasks across lots of systems and
> having different =
> flavors
> of OSs and programs...Like a Novell file server to
> store the files
> (ncpmount), a Linux system to front end apps
> (Apache, PHP, etc) and a
> Solaris system to backend (MySQL, etc) all behind a
> firewall with IP
> masquerading (NAT) and port forwarding.  Try to give
> each system =
> non-root
> access to each other so if one piece is compromised
> the entire setup =
> isn't
> loss.
> 
> I've always thought if they hacked my apache server
> that it wouldn't do =
> them
> much good #1 only port 80 goes to that system, ssh
> and the like go to a
> different system the system many times use different
> flavors of Linux =
> and
> 80% share no passwds directly in common.
> 


=====
Patrick, Freedom Advocate 
Linux User #65411 http://lugww.counter.li.org
http://knopper.net/knoppix   http://yolinux.com 
http://distrowatch.com  http://sourceforge.net

__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software
http://sitebuilder.yahoo.com

----
Husker Linux Users Group mailing list
To unsubscribe, send a message to huskerlug-request@xxxxxxxxxxxxx
with a subject of UNSUBSCRIBE


Other related posts: