Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 25/26 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Thread Tools Search this Thread Display Modes
Old 27th April 2011, 02:31 PM
Geekcalledsick Offline
Registered User
Join Date: Apr 2011
Posts: 8
How to configure firewall and software plus user rights


I am novice user of linux. I need to know how to configure firewall so my system cant be compromised...

In windows my system was greatly compromised. keyloggers were installed without my approval and my desktop was taken on remote.

What should I do so without my knowledge no software can be installed and i can close all ports and only open which ever port is required to open. What should i do so my desktop cant be taken on remote?

How do I configure user rights? So only root and one admin can install softwares and no one else.

Please advise...
Reply With Quote
Old 27th April 2011, 02:50 PM
Miikka Offline
Registered User
Join Date: Apr 2011
Location: Finland
Posts: 292
Re: How to configure firewall and software plus user rights

Only root can install software as default. Linux is much much much... much safer than windows as there is basically are viruses or keyloggers. You don't need to do anything to be secure.

EDIT: Did you get your problem solved here: http://forums.fedoraforum.org/showthread.php?t=261558 ?

Last edited by Miikka; 27th April 2011 at 02:55 PM.
Reply With Quote
Old 28th April 2011, 08:36 AM
Geekcalledsick Offline
Registered User
Join Date: Apr 2011
Posts: 8
Re: How to configure firewall and software plus user rights

But i hear there are viruses and root kits for linux...How to be secure against those viruses? First linux root kit was discovered in 1996 as per book Hacking Exposed...
Reply With Quote
Old 6th May 2011, 12:55 AM
synapsys Offline
Registered User
Join Date: May 2011
Posts: 5
Re: How to configure firewall and software plus user rights

Originally Posted by Miikka View Post
Only root can install software as default. Linux is much much much... much safer than windows as there is basically are viruses or keyloggers. You don't need to do anything to be secure.
WRONG! Simply using Linux doesn't make you secure.

Originally Posted by Geekcalledsick
But i hear there are viruses and root kits for linux...How to be secure against those viruses? First linux root kit was discovered in 1996 as per book Hacking Exposed...
Yes, there are viruses and root kits for Linux. The best way not to get infected is to use common sense on the internet, and get yourself a decent firewall. I would suggest looking at configuring iptables. By default, only root can install software. I would suggest setting up the administrator account as a "sudoer." This will allow you to run single commands as root without having to login as root. If you need anymore help with this, just ask. Also, you want to use secure passwords for all user accounts, especially root, and disable any unnecessary services you may be running.
Reply With Quote
Old 7th May 2011, 09:00 AM
Evil_Bert Offline
Retired Again - Administrator
Join Date: Nov 2007
Location: .
Posts: 3,413
Re: How to configure firewall and software plus user rights

I generally agree with synapsys's suggesitons with the possible exception of the efficacy of sudo - opinions vary on that score. But, I differ on the matter of Linux being more secure than Windows (to which he alludes) - that is, the user is more secure simply by using it (and by "it", I assume a modern, mainstream Linux distro).

And, please, don't turn this into a Windows-bashing thread!

Whereas there are > 1.8 million malware items for Windows and at least one independent study showed 8 out of 10 in-the-wild malware remain a valid concern for Windows 7, the number of Linux-specific malware items is thought to be ~1000 in total with only ~50 "detected" in-the-wild (IIRC). Linux rootkits are more prevalent than viruses per se because normally, outside of scripting in a browser or the like, executables don't run on your Linux machine unless you have given permission to do so. Whilst it's possible to download an executable as a user and run it, this still requires manual permission assignment and execution (again, this is outside of scripting in a browser or similar).

There are some web-based script and cross-platform risks, such as Adobe Flash, where some malware will work in Linux with user-level privileges, but normally (almost always) if the malware runs, its payload will be aimed at Windows vulnerabilities. Overall, in the typical desktop scenario (i.e. the same way a typical user would use Windows online), the risk of using Linux is much reduced.

However, Linux is not "provably secure" in the sense of some software that can be proven by mathematical means to be defect-free. Linux still has defects and vulnerabilities that are announced on CERT lists and the like and it is possible to exploit some of those vulnerabilities at least until they are patched. Linux vulnerabilities are usually patched sooner then Windows counterparts and there are fewer critical vulnerabilities in the first place, but this may change in the future - more Linux malware could be written and/or there could be more vulnerabilities. Personally, I believe using Linux will never become as risky as using Windows has been.

In many, but not all, Linux distributions, a fair degree of attention is already paid to security. For example, in Fedora, the default firewall configuration is quite adequate for home users (IMHO) and services, by default, do not accept external connection requests. The default SELinux configuration (for distros that use it) does add some additional security should a user actually encounter malware for Linux. These features can be tightened of course, particularly if you have unusual needs or are especially security conscious. Disabling unneeded services certainly does no harm, saves resources and may improve security - the basic principle there is the less code running on your system, the smaller the chance of a vulnerability being accessible, so it's a good thing to do if you have the time and knowledge. (In my case, I do prune running services and implement my own custom firewall to suit my needs).

There are several avenues to explore if a Linux user is really keen to lock down their system - some easy, some complicated - but the best recommendation to a new Linux user, IMHO, is to get software only from trusted repositories, that host only signed packages, which is the default in Fedora. If you use third-party repositories, do your research and obtain, verify and import the package signing key carefully.

So is Linux "secure"? Strictly speaking, no, but I can see how some everyday users could be forgiven for saying that it is, especially when they've only ever used Windows.
Marching to the beat of his own conundrum.
Reply With Quote
Old 30th May 2011, 10:10 PM
mitmblues Offline
Registered User
Join Date: May 2011
Posts: 6
Re: How to configure firewall and software plus user rights

Did you get this fixed - I can coach you through what you ask if need be.

The steps I think you need to take are as follows:

1) Batten down the hatches and make sure there is no direct access to the machine by a hacker. Local crime will prefer to hack a computer by getting direct access to the keyboard if at all possible. It's easier than hacking over the Internet (i.e., a MITM attack). So you need to make sure at a minimum the door is padlocked behind you before you open a root console. If you can install home CCTV and check the footage of you entering and leaving the room before logging into root (crime has the intrusion capabilities of Houdini it is not without reason Houdini wrote extensively on crime) - a very basic setup can be done using webcams and the Motion package. Secure window shutters if possible (you may not think you need these but you do). A good alarm system can add to internal security. Some TEMPEST shielding if you can afford $1000 (I get the feeling local crime has at least one TEMPEST setup that they move around), but otherwise make sure no clear text passwords are displayed on screen - if setting, e.g., a VPN password on a website xclip and 'read -s' can be used to input autogenerated passphrases/keys etc. without displaying.

2) Encrypt and obfuscate passwords (i.e., don't write them down in clear text). I'm sure you can dream up all sorts of schemes personal to yourself. You need schemes to generate a short password that will only be used to login to a user login (something that can be remembered easily for frequent use), but also schemes to generate the passphrase to encrypt the hard disk which you will only use once in a while etc. You need a scheme as well that will allow you to very quickly reset the password to something new if the need arises (which it does). At one time for example I would open a particular webpage on my mobile 'phone listing English castles, and created passwords noting only the login and # of the castle in the list, using encryption schemes residing largely in my head based on the name of the castle - a scheme that was easy to remember for non crytical/throwaway logins, something more complex for longer passphrases, etc.

3) Lock the X desktop down by creating a public kiosk style setup - run an X window manager but without any menu options that will allow any kind of access to the file system. TWM or openbox are good window managers for doing this. Code xterms to only open after a password has been entered, etc.

4) Setup iptables to open only http and https ports. Connecting to your ISP involves bringing up the network interface, 'ifup [device]' (you may have to set config options for the interface for dhcp); create iptables for connecting to your router in the first instance, and then once the network connection is up connecting to your ISP with only (as a starting point) http and https ports open. Also create a table for when you bring the connection down, blocking all network traffic in either direction.

5) If you have a MITM type hacking problem (SSL certificate errors, data injection), find a VPN, I use ivpn.net OpenVPN servers - all VPNs are not unfortunately created equal, iVPN I personally have found to be about the best (in fact the only one I've tried that prevents most hacks). You will have to add an additional iptable for bringing up the VPN connection. (Note though a VPN only encrypts the Internet connection up to the VPN server, not from the server to the website, and doesn't protect you from compromised websites).

6) Run the browser in a SELinux sandbox - this is an absolute must, I'm still working on a data injection problem even with a VPN.

7) Optional Install the Fedora security spin packages (there is a post on the forum with a script to do this) and join the forum, read the chapter on security in the RH docs, and make a career of a network engineer - at which point you can provide consultancy services to myself, as being a programmer I do not particularly want to go down this route

MITM attacks are described in the presentation on this page... http://www.thoughtcrime.org/software/sslstrip/ (which doesn't seem to be working at the moment - I'm sure if you google'd it it will be found elsewhere).

If you want to go down the above route post back and we can make a start The first thing you need to do though you may find is bolt the door of the room behind you, and make sure the windows are secure.
Reply With Quote

configure, firewall, rights, software, user

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Normal User Rights Problem F12? VideoRoy Using Fedora 12 7th January 2010 06:59 AM
User rights problem geometro Using Fedora 2 1st July 2007 04:41 AM
Samba user rights changed since 3.0.10 TDR Servers & Networking 0 9th August 2006 04:07 PM
Routing+Firewall software? how to configure? woosting Servers & Networking 1 3rd June 2005 12:46 PM

Current GMT-time: 13:14 (Wednesday, 16-08-2017)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat