Ubuntu Forums ubuntu.com - launchpad.net - ubuntu help  

Go Back   Ubuntu Forums > The Ubuntu Forum Community > Forum Archive > Main Support Categories > Server Platforms
Register Reset Password Forum Help Forum Council Search Today's Posts Mark Forums Read

Hello, Unregistered You are browsing a READ only archive of the main support categories pre 4/21/2008. You will not be able to post or reply any threads in this section.

Server Platforms
Discussion regarding any server based ubuntu release.

 
Thread Tools Display Modes
Old December 8th, 2004   #1
ubuntu_demon
Ubuntu Master Roaster
 
ubuntu_demon's Avatar
 
Join Date: Oct 2004
Location: Netherlands
Beans: 2,968
Ubuntu 8.04 Hardy Heron
What are the real vulnerabilities of Ubuntu?

What are the real vulnerabilities of Ubuntu?

This is a nice article :

What are the real vulnerabilities of Linux?
http://www.newsforge.com/article.pl?.../12/01/2329229

I would like to know more about SELinux and Ubuntu
http://www.ubuntulinux.org/wiki/HoaryGoals
SELinux - Needs proof of concept derivative

I would like firestarter in ubuntu main and installed by default in hoary

I would like to know if the security settings of the default install of hoary are going to be equal to those generated by hardening scripts like Bastille (rendering them largely useless)
ubuntu_demon is offline   Reply With Quote
Old December 8th, 2004   #2
daniels
Ubuntu Developer
 
Join Date: Oct 2004
Location: Helsinki, FI
Beans: 369
Re: What are the real vulnerabilities of Ubuntu?

There would be no point to having Firestarter around, because we don't have any open ports by default. So you could have it running if you wanted to feel better, but there's nothing for anyone to connect to anyway. Efforts like Firestarter and Bastille have been based around the idea of securing already-running services, instead of just not running them and having them publicly visible anyway.
__________________
daniel dot stone at ubuntu dot com
daniels is offline   Reply With Quote
Old December 8th, 2004   #3
ubuntu_demon
Ubuntu Master Roaster
 
ubuntu_demon's Avatar
 
Join Date: Oct 2004
Location: Netherlands
Beans: 2,968
Ubuntu 8.04 Hardy Heron
Re: What are the real vulnerabilities of Ubuntu?

Quote:
Originally Posted by daniels
There would be no point to having Firestarter around, because we don't have any open ports by default. So you could have it running if you wanted to feel better, but there's nothing for anyone to connect to anyway. Efforts like Firestarter and Bastille have been based around the idea of securing already-running services, instead of just not running them and having them publicly visible anyway.
okay cool

What is your opinion about SElinux and Ubuntu? And how's the progress if any ?
ubuntu_demon is offline   Reply With Quote
Old January 3rd, 2005   #4
jdong
Ultimate Coffee Grinder
 
jdong's Avatar
 
Join Date: Oct 2004
Location: Cambridge. MA
Beans: 5,063
Ubuntu 8.10 Intrepid Ibex
Re: What are the real vulnerabilities of Ubuntu?

Quote:
Originally Posted by daniels
There would be no point to having Firestarter around, because we don't have any open ports by default. So you could have it running if you wanted to feel better, but there's nothing for anyone to connect to anyway. Efforts like Firestarter and Bastille have been based around the idea of securing already-running services, instead of just not running them and having them publicly visible anyway.
Can you guys set debconf to NOT put newly installed daemons in the default runlevel? I think that should be a conscious, self-made decision. (or prompt the user, like you can make sarge do)
jdong is offline   Reply With Quote
Old January 3rd, 2005   #5
daniels
Ubuntu Developer
 
Join Date: Oct 2004
Location: Helsinki, FI
Beans: 369
Re: What are the real vulnerabilities of Ubuntu?

It's not a debconf thing -- we'd need to change either update-rc.d, or change debhelper and then rebuild every package (rebuilding every package will not happen; if it gets rebuilt due to a new version, cool).
__________________
daniel dot stone at ubuntu dot com
daniels is offline   Reply With Quote
Old January 3rd, 2005   #6
jdong
Ultimate Coffee Grinder
 
jdong's Avatar
 
Join Date: Oct 2004
Location: Cambridge. MA
Beans: 5,063
Ubuntu 8.10 Intrepid Ibex
Re: What are the real vulnerabilities of Ubuntu?

Well, can we do one of the two for Hoary? I know that my old Debian Sarge installation prompted me before enabling a Daemon.
jdong is offline   Reply With Quote
Old January 3rd, 2005   #7
daniels
Ubuntu Developer
 
Join Date: Oct 2004
Location: Helsinki, FI
Beans: 369
Re: What are the real vulnerabilities of Ubuntu?

I'll check it out.
__________________
daniel dot stone at ubuntu dot com
daniels is offline   Reply With Quote
Old December 9th, 2004   #8
Hikaru79
Gee! These Aren't Roasted!
 
Hikaru79's Avatar
 
Join Date: Dec 2004
Location: Waterloo Ontario (Canada)
Beans: 171
Kubuntu 5.10
Send a message via AIM to Hikaru79 Send a message via MSN to Hikaru79 Send a message via Yahoo to Hikaru79
Re: What are the real vulnerabilities of Ubuntu?

Quote:
Originally Posted by demon666_nl
I would like firestarter in ubuntu main and installed by default in hoary
Just think about all the people we'd have in here and the Wiki and the IRC channel pleading about 'why is my bittorrent so slow' or 'why can't I connect to such-and-such an XDCC bot?' I agree with daniels; let those who are interested in the firewall get it themselves. For everyone else, it's probably more trouble than it's worth to solve all of the problems it will cause.
__________________
I seem to have discovered a truly remarkable proof for Fermat's Last Theorem, which this siggie is too small to contain.
Hikaru79 is offline   Reply With Quote
Old December 9th, 2004   #9
ubuntu_demon
Ubuntu Master Roaster
 
ubuntu_demon's Avatar
 
Join Date: Oct 2004
Location: Netherlands
Beans: 2,968
Ubuntu 8.04 Hardy Heron
Re: What are the real vulnerabilities of Ubuntu?

Quote:
Originally Posted by Hikaru79
Just think about all the people we'd have in here and the Wiki and the IRC channel pleading about 'why is my bittorrent so slow' or 'why can't I connect to such-and-such an XDCC bot?' I agree with daniels; let those who are interested in the firewall get it themselves. For everyone else, it's probably more trouble than it's worth to solve all of the problems it will cause.
True. I tend to forget my own plees about making stuff easy for the average-desktop-user. I tend to forget people don't even understand the easy interface of firestarter. Lot's of people don't understand anything about firewalls. It's a good thing we don't really need them in Ubuntu.
ubuntu_demon is offline   Reply With Quote
Old December 9th, 2004   #10
jdong
Ultimate Coffee Grinder
 
jdong's Avatar
 
Join Date: Oct 2004
Location: Cambridge. MA
Beans: 5,063
Ubuntu 8.10 Intrepid Ibex
Re: What are the real vulnerabilities of Ubuntu?

Daniel, I disagree about firestarter. The way you guys configured debconf, all newly installed daemons will listen on all interfaces, so as soon as you start apt-getting apache and stuff, you'll start getting open ports!


I like using Firestarter to prevent me from doing something really stupid, like leaving samba open on the wrong interface! LOL
jdong is offline   Reply With Quote

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 04:03 PM.


vBulletin ©2000 - 2009, Jelsoft Enterprises Ltd. Ubuntu Logo, Ubuntu and Canonical © Canonical Ltd. Tango Icons © Tango Desktop Project. bilberry