TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Security Concerns:



Hi All:
    In about a week I'll be building an extreamly secure system.  Foir a
base OS it will Run Mandrake 6.5, With A Bare Install.  The Main Services
which are to run on it will Be Compiled by me.  I plan to Install Apache
1.3.9, PHP 4, and The Latsest version of Qmail.  TCPWrappers and a IPChanis
firewall will protect the whole thing.  I plan to make a admin group which
owns the fiels such as su, startx, X, and mc.For Hard Drive Partitions I am
Planning:
    /tmp :: 45MB, nosetuid
    /var/log :: 50MB,
    /var/qmail :: 200MB, Qmail Home Dir
    /var/spool :: 136MB, Spool FIles
    /usr/local/apache :: 1GB, Apache Home and HTDOCS Root
    /usr/local/software :: 200MB, nosetuid
    /home :: 136MB, nosetuid
    / :: 1GB
    swap = A Total of 128MB, in 2 Partitions.

Can anyone see any major or minor security flaws or concerns in this design?
Any have any ideas for other commands which can only be executed by the
owner and the admin group?

Thanks for your input!

-->Jonathan Kline<--