Article Directory
Free Online Article Directory. For Article Authors & Publishers

Ubuntu and Debian Security Applications Review

Securing servers from potential attacks is of utmost importance in nowadays's economic climate. This article could be a personal review of a number of the best applications I've got reviewed recently to secure my very own server furthermore others. This document contains applications that might or could not fit each state of affairs to properly secure Web facing systems. But it does use entirely open source and free host based mostly software, So they can run while not the need for expensive external hardware.
When reviewing existing security policies some factors want to be accounted for first. These being performance, stability and overall use of system resources. Use this to see the need for each of your own requirements. Rather than just pushing all of the recommended on to one server. As some applications reviewed don't seem to be perpetually entirely interchangeable with the others mentioned.
That being said we'll begin with Apache the World’s most well-liked Internet Server.
Mod Security
Without doubt one among my personal favorite Apache modules is Mod Security. Though it does need registration to download and is not entirely free while not restriction. Mod Security is an invaluable Web Application firewall that deters tons of the scum and random bots floating round the Internet today. In line with the Mod Security web site over 70% of all attacks allotted on the internet nowadays are done on the web application level. That is extremely relevant since a single compromised web website will usually leak thousands if not tons of thousands of passwords and user credentials in just a single compromise.
Professionals
Mod Security contains a very strict rule-set that is capable of blocking many sorts of web application attacks most of which will be found in the rules set out by the OWASP top 10.
Cons
The default rules will break functionality of Net applications at first. But it will be mounted if you'll realize the offending rules by viewing log files and commenting those rules out. Common things that will happen is that users are unable to login or some other functionality such as a custom search might break.
Snort
The subsequent terribly attention-grabbing application is Snort the commonly known defector customary in intrusion detection. Snorts job is to monitor networks whereas being as light-weight weight as humanly possible. On not consume to many system resources and abate the users of the systems it could be running on. What really makes snort distinctive but is that it has heritage of being a very stable and sturdy IDS with each open supply rule-sets and more advanced industrial rule-sets which are on the market via subscription.
Professionals
Light-weight and flexible, Trusted and stable.
Cons
The free rules obtainable have a lot to be desired compared to the subscription rules.
AIDE
AIDE the file integrity checker will be used to create hashes of files or directories and is a generic replacement for the older Linux application trip wire. If an application has been changed without consent a easy cross reference via an image disk can reveal insights quickly on which files might have changed in the process. By providing SHA1 hashes or alternative algorithms. It's therefore very useful for analyzing the exact explanation for a vulnerability in the event of a possible intrusion and in many respects will be thought of a root-kit detector while not all the fancy bells and whistle like our next application.
Pros
Supports custom algorithms and makes up for where trip wire and others once failed.
Cons
Lack of documentation to properly implement and utilize for less experienced users it will be an idea you will offer up on quickly. (I don't blame you but it's worth it.)


RKHUNTER
Another smart Root-kit detector is RKHUNTER and works very a lot of the identical as AIDE however is a lot of specifically a root-kit detector in that it scans all the same old locations where it might make sense for root-kits to cover on a Linux system or where they need historically been stored.
Professionals
Terribly exhaustive and has support for a wide selection of common root-kits.
Cons
By default on debian and ubuntu it flags a false positive for gawk, awk and some different directories but I feel this to only be a false positive.
FAIL2BAN
Fail2Ban helps block out automated and typically brute-force queries by bots or potential attackers over SSH that make too several incorrect log-in attempts.
Execs
By automatically banning bots not only do you defend your system from compromise but additionally help keep performance of the server at a lot of optimal levels.
Cons
I've locked myself out quickly before by not setting the edge high enough and forgetting what password I used. As long as you do not do that you should be fine.

Author Resource:- Hulala has been writing articles online for nearly 2 years now. Not only does this author specialize in Security
You can also check out his latest website about :
Artist T ShirtWhich reviews and lists the best
customized t shirts
Submitted 2010-05-31 09:19:04
By: hulala bkaska 29 or more times read
Article Read 70 Times
Article From
Article Listed
[Valid RSS feed]  hulala bkaska's Author Feed
http://www.articlelisted.com/author-rss-feed.php?rss=8539
[Valid RSS feed]  Category Rss Feed
http://www.articlelisted.com/rss.php?rss=39

Related Articles

  • Do Free Anonymizing Services Protect Anything?


    Free anonymizing proxies are readily available all over the Internet. There are shows that you install on your computer to access these proxies as well as there are proxies that you can access over a webpage.
  • Could Possibly A VPN Be Penetrated?


    VPN services use sophisticated technologies to provide anonymity and information protection for users. They make it possible for users in foreign nations to accessibility content that might be restricted.
  • VPN Networks And Safety


    On home computer networks, info can easily be protected by encryption. Encryption indicates changing the data by having a scrambled strand of nonsense.
  • Why Might I Require VPN Software For?


    VPN services are extremely common and there are quite a couple different providers offering you various variations of them. Of course, this begs the question: Why would I even require one of these services?
  • VPN Services And Privacy


    VPN services provide a method to protect the privacy. The fascinating thing regarding exactly how these networks work is that the privacy security carries out additional than you may think initially.
  • 'Tis The Season For Facebook Identity Theft


    During this holiday season, is it better to give or receive? For identity thieves, it's neither; they prefer to take; and their latest hunting ground for victims is Facebook. Having surpassed 800 million users worldwide, there is plenty of targets on Facebook for crooks to go after. Knowing how they go about their schemes will help you be more informed about protecting yourself on Facebook.
  • Have You Looked Under The Virtual Mat?


    I wonder if Sony are aware of the Payment Card Industry Data Security Standard (PCI DSS) since they are very effectively stating their non-compliance.
  • PlayStation User? Kill The Cat!


    Today we hear confirmation about a breach of the Sony Playstation Network with the loss of millions of account names and personal details and potentially the loss of payment card details such as the payment card number and Expiry dates, but excluding the security code.
  • How Sophisticated Are The Cyber Thieves Who Breach Security?


    Why is it: whenever there is a breach of a company's security it is always attributed to the work of sophisticated cyber criminals? Is this because it really does take a sophisticated criminal to breach an environment these days or do victims prefer to characterise the cleverness of the criminal rather than the weakness of the security environment?
  • Transponder Keys - The Uses and Benefits


    Transponder keys becoming more and more technically advanced. The transponder keys purpose is to communicate with the lock. Auto theft can be reduced by using transponder keys and locks.

HTML Ready Article. Click on the "Copy" button to copy into your clipboard.




Firefox users please select/copy/paste as usual
Actions
Print This Article
Add To Favorites


Navigation
select
Home
select
Sign up
select
Login
select
Submit Articles
select
Submission Guidelines
select
learn more
select
Top Articles
select
About Us
select
Contact Us
select
Privacy Policy
select
RSS Feeds
   
Submit Your Articles To Our Other Article Directory
Morefreeinformation.com