Securing Linux Servers for Service Providers.pdf
(
1044 KB
)
Pobierz
Securing Linux Servers for Service Providers
December 21, 2001
Bill Hilf
Sr. Consulting I/T Architect
IBM Corporation
billhilf@us.ibm.com
© Copyright IBM. Corp. 2001. All rights reserved.
- 1 -
Table of Contents
Overview of Linux in the Service Provider, or xSP, Space ....................................................................... 3
Intent and Background............................................................................................................................... 4
SANS/FBI Top 20 ................................................................................................................................ 5
Security Philosophy ................................................................................................................................... 6
Securing Linux Servers.............................................................................................................................. 6
General Practices .................................................................................................................................. 6
Develop a patch and upgrade strategy .................................................................................................. 7
Understand which programs have Set-UID and Set-GID ..................................................................... 8
Develop a password strategy................................................................................................................. 9
If you are not using a service, turn it off ............................................................................................. 11
Log intelligently.................................................................................................................................. 12
Use tools where possible..................................................................................................................... 14
Application security is critical ............................................................................................................ 16
Kernel level security ........................................................................................................................... 18
Know Your Enemy ............................................................................................................................. 20
Linux Firewalls........................................................................................................................................ 24
What is a packet filter? ....................................................................................................................... 24
Identification and Testing ................................................................................................................... 27
Linux FTP Servers................................................................................................................................... 30
Non-Anonymous FTP ......................................................................................................................... 30
Anonymous FTP ................................................................................................................................. 30
General Linux FTP Server suggestions............................................................................................... 31
Linux Mail Servers .................................................................................................................................. 32
Sendmail ............................................................................................................................................. 32
Postfix ................................................................................................................................................. 34
Qmail .................................................................................................................................................. 35
Linux Mail Virus and Spam Filters..................................................................................................... 36
Linux Web and Application Servers........................................................................................................ 37
Apache Security Configuration Tips................................................................................................... 38
Web server diagnosis .......................................................................................................................... 43
Web Services ...................................................................................................................................... 44
Web proxies ........................................................................................................................................ 45
Conclusion ............................................................................................................................................... 46
Acknowledgements.................................................................................................................................. 47
Appendix - Resources.............................................................................................................................. 48
Resources - Mailing Lists ................................................................................................................... 48
Resources - Web Sites ........................................................................................................................ 48
Resources - Books............................................................................................................................... 48
Resources - Tools................................................................................................................................ 49
Application Security ........................................................................................................................... 49
Intrusion Detection Systems ............................................................................................................... 49
Security Testing Tools ........................................................................................................................ 50
Password Tools ................................................................................................................................... 51
Network Scanners ............................................................................................................................... 52
Port Scan Detectors............................................................................................................................. 52
Encryption........................................................................................................................................... 53
Log and Traffic Monitors.................................................................................................................... 53
Sniffers................................................................................................................................................ 55
© Copyright IBM. Corp. 2001. All rights reserved.
- 2 -
Overview of Linux in the Service Provider, or xSP, Space
The term “xSP” is simply the consolidation of the Service Provider acronyms. Initially
only ISPs and ASPs were known in this domain, but as the Internet and eBusiness
matured, new service provider business models quickly followed. Infrastructure “SPs”
such as managed service providers (MSPs) which provide fully managed services
(network, storage, servers, administration, etc.) and business service providers (BSPs),
who provide business value to their customers through application access or aggregation
(ASPs), content providers or increasingly through outsourced business processes.
But let’s not get lost in the acronym soup, but rather focus on the common elements
among service providers and how these elements need to be secured under Linux. One of
the clear similarities among service providers is the ability to supply network enabled
customer services. Be it in the form of a dial-up service, a Web-enabled application,
relational databases, storage solutions, hosting, or an email account, these services all
share multiple traits.
Sharing infrastructure and services are primary components in the economies of scale for
building a service provider business. The degree that these components are shared will
vary at the hardware, network, server, or application layer – but there are few, if any,
scenarios where some part of the service provider fabric is not shared by multiple
customers. This is a critical factor to understanding security in a service provider
environment. Since these services are essentially available to the public, they must be
considered un-trusted. Although a service provider may not consider their customers
“the public” or un-trustworthy, if the service is accessible to users over the Internet
(regardless if they have to pay for that service) it could potentially be exploited by any
other machine on the Internet.
Operating system security in Internet based services is more important then ever. Beyond
the obvious heightened awareness around security after the tragedies of September 11
th
,
there are multiple financial trends that have elevated security as a critical IT issue.
Recently, PricewaterhouseCoopers updated its Security Benchmarking Service
1
to
include new data from InformationWeek's 2001 Global Information Security Survey.
The survey, fielded by PricewaterhouseCoopers, reveals that these global corporations
realized over
$1.39 trillion
in lost revenue due to security breaches over the past year.
Globally, the propagation of computer viruses is a significant contributor to the trillion
dollar losses, with 60% of survey respondents reporting they experienced lost
productivity due to computer viruses and denial of service attacks. The number one
security breach reported was against operating systems.
1
PricewaterhouseCoopers' Security Benchmarking Service evaluates an organization's security program
against a global database of approximately 4,500 survey responses from technology professionals in 50
countries.
© Copyright IBM. Corp. 2001. All rights reserved.
- 3 -
The rapid evolution of Internet based security exploits is clearly seen in the statistics from
CERT/CC, the canonical organization for reporting computer security incidents and
vulnerabilities. The number of security incidents for just the first three quarters of 2001
was 34,754. The number of security incidents for the year 2000 was 21,756. The total
number on incidents reported from 1989 - 1999 was 25,949.
2
Amazingly, in just nine
months in 2001, CERT has reported more security incidents then in a decade’s worth of
incidents between 1989 and 1999. The scourge of attacks, viruses, worms, and Trojan
horses being used by way of the Internet is woefully apparent.
3
Increasingly, service providers are using Linux as a secure, reliable, high performing, and
cost effective server operating system. The choice of Linux makes perfect sense to
service providers as the Linux operating system itself was designed and developed with
the Internet in mind. Linus Torvalds credits much of the success of Linux to the
existence of the Internet, which allowed for the creation of a complete operating system
between hundreds, if not thousands, of professionals in a decentralized development
model.
4
Utilizing an operating system designed and developed via the Internet is an ideal
match for service providers, which build and operate their businesses by means of the
Internet. The total cost of ownership, flexibility and outstanding track record of the
Linux operating system is driving this usage, and more than ever, service provider
customers need to understand how to ensure their Linux systems are secure.
Intent and Background
The intent of this document is to clearly explain the steps needed to secure a Linux server.
It will describe general security practices relevant to any Linux server, as well as specific
steps to take for the most commonly used implementations of Linux servers in the service
provider environment. It is beyond the scope of this document to illustrate every facet of
Linux security, or the tools and methods for protecting against all attacks. The
vulnerabilities and recommended security solutions are based on professional experiences
and are meant to provide examples and best practices in many of the common security
threats found in running Linux servers today.
Many of the examples and practices in this document are from my own experiences
designing, developing and operating Web systems. As an architect in the IBM Emerging
& Competitive Markets organization, I am involved with a variety of service provider
and emerging businesses. My primary area of expertise is in Linux based infrastructures
as it applies to these market segments. Prior to joining IBM, I headed up the engineering
department for eToys, a popular e-commerce site for children’s products. Due to the
exposure of the eToys.com site, we were the recipients of daily, and at times hourly, port
scans, denial of service attacks, and intrusion attempts. For better (learning) or worse
(sleep) my team and I were the folks paged at 2 a.m. to respond to these threats. Before
2
http://www.cert.org/stats/cert_stats.html
3
According to the CSI 2001 Computer Crime and Security Survey, the rise in those citing their Internet
connections as a frequent point of attack rose from 59% in 2000 to 70% in 2001
(
http://www.gocsi.com/prelea/000321.html
)
.
4
http://resources.cisco.com/app/tree.taf?asset_id=75234
© Copyright IBM. Corp. 2001. All rights reserved.
- 4 -
eToys, I was an engineer at CNET Networks, which is composed of a variety of Web
sites, such as Cnet.com, News.com, Download.com, Shareware.com, Computers.com,
and others. As each of these site provided different services (such as content distribution,
advertising, software archives, Web-based applications, and other managed and hosted
services), CNET was exposed to a wide array of probes and intrusion attempts. Through
these experiences, I have “cut my teeth” on real world attacks on Linux and Unix server
systems. Hopefully, this document will provide some practical advice that can help you
or your customers from getting a page or phone call at 2 a.m.
SANS/FBI Top 20
As a framework, this paper will use a recently published report from the SANS/FBI
National Infrastructure Protection Center (NIPC) on the top twenty security
vulnerabilities. This list is often used by many businesses as a guide for which
vulnerabilities to protect against, and the relative importance of each security threat. This
list has proven valuable as it is compiled by well respected security organizations, and
moreover, because many of today’s successful attacks on computer systems via the
Internet can be traced to exploitation of security flaws on this list. The list is composed
of three parts, General Vulnerabilities, Windows Vulnerabilities, and Unix
Vulnerabilities. For the purpose of securing Linux servers in a service provider
environment, this document will utilize issues from the General and Unix Vulnerability
list, the Top Windows Vulnerabilities will not be included.
Top General Vulnerabilities:
1. Default installs of operating systems and applications
2. Accounts with no passwords or weak passwords
3. Non-existent or incomplete backups
4. Large number of open ports
5. Not filtering packets for correct incoming and outgoing addresses
6. Non-existent or incomplete logging
7. Vulnerable CGI programs
Top UNIX Vulnerabilities:
1. Buffer overflows in RPC services
2. Sendmail vulnerabilities
3. BIND weaknesses
4. R commands
5. LPD (remote print protocol daemon)
6. sadmind and mountd
7. Default SNMP strings
I recommend visiting the SANS/FBI Web site, as it provides detailed descriptions of each
vulnerability and generic security solutions and resources. This document will address
each of these as it directly relates to securing Linux servers in a service provider
environment.
© Copyright IBM. Corp. 2001. All rights reserved.
- 5 -
Plik z chomika:
WMatrixie
Inne pliki z tego folderu:
Redhat Network Services and Security Administration.pdf
(15030 KB)
Maximum Linux Security - 2nd Edition.pdf
(11166 KB)
Center for Internet Security - Benchmark for Debian Linux v1.0 (2007).pdf
(309 KB)
Linux Administrators Security Guide.pdf
(357 KB)
Securing Debian Manual (2011).pdf
(1132 KB)
Inne foldery tego chomika:
Apache
BotNets
Building Secure
CISSP
Computers Security
Zgłoś jeśli
naruszono regulamin