There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Tag Cloud
access acer asus bios bsod computer crash desktop dns driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop lcd malware memory monitor motherboard netgear network printer problem ram registry router slow software sound toshiba trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless xbox
Search
Search for:
Tech Support Guy Forums > Operating Systems > Linux and Unix >
Best Security combination for Linux

Reply  
Thread Tools
Fungusamongus27's Avatar
Member with 31 posts.
 
Join Date: Mar 2009
Experience: Beginner
25-Apr-2009, 12:49 AM #1
Best Security combination for Linux
Hi again. I've just installed Ubuntu for my laptop computer. As I'm a complete newb to Linux and even general computing itself, I want to know what's the best security configuration for Ubuntu? I've replaced AppArmor with SELinux and is this a good choice? Thanks again.
lotuseclat79's Avatar
Distinguished Member with 21,345 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
25-Apr-2009, 09:58 AM #2
First things first.

Linux kernel (all distributions) comes with the firewall capability known as iptables, however, to use the capability you need to start it up with rules which are not in any default setup - i.e. it is up to the user.

SELinux is more of a policy framework for security in Linux - I have it for Fedora Core 3 (FC3). Not a bad choice. I too checked out AppArmor use with Firefox and decided I did not want it (one of my threads in this forum addressed AppArmor w/Firefox and how to do it).

The choices you have for iptable firewall are:
1) Download Firestarter, install it and make it startup on boot.

2) Go to UbuntuForums.org to the Tips and Tutorials subforum and search for Firewall which should have a Beginner's tutorial followed by a link to an Advanced tutorial. I use the restricted firewall script.

You can search posts I (lotuseclat79) have initiated in this forum and find the thread that will step you through the above UbuntuForums.org links for Beginner's and Advanced tutorials.

3) You can purchase Linux Firewalls by Michael Rash at CipherDyne.org web site for all the details about iptables and intrusion detection (if you have any desire to learn them) - at a 30% discount if you buy it from that web site's links to No Starch Press.

4) You can purchase a hardware router (if you do not have one) with NAT and SPI and its own firewall for additional protection if you already have a high speed connection. If you do, then set it up w/DHCP for every power up to get an IP address assigned, and stealth off all of the ports - test it from nmap-online.com.

Using SELinux does not turn on the iptables firewall.

Also, remember, never surf as root whatever your OS.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction
between a mere artisan or specialist and a real seeker after truth. - Einstein 1944
Imagination is more important than knowledge. - Einstein
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 08:24 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.