Search Members Help

» Welcome Guest
[ Log In :: Register ]

Mini-ITX Boards Sale, Fanless BareBones Mini-ITX, Bootable 1G DSL USBs, 533MHz Fanless PC <-- SALE $200 each!
Get The Official Damn Small Linux Book. DSL Market , Great VPS hosting provided by Tektonic
Pages: (4) </ [1] 2 3 4 >/

[ Track this topic :: Email this topic :: Print this topic ]

reply to topic new topic new poll
Topic: Security Questions< Next Oldest | Next Newest >
jpeters Offline





Group: Members
Posts: 804
Joined: April 2006
Posted: April 21 2006,21:33 QUOTE

If I'm running DSL in ram and have the hardrive unmounted, is there any need for a firewall?
Back to top
Profile PM 
green Offline





Group: Members
Posts: 453
Joined: Oct. 2004
Posted: April 22 2006,03:57 QUOTE

Just my opinion, so take it with a grain of salt.

If you do not have FTP, ssh, webserver, etc. running, you should be okay.

To my knowlege, DSL does not have any ports open by default, which makes it pretty secure out of the box. Don't keep personal stuff on it and things like that. You could even remove the hard drive if you wanted to.

If someone does manage to molest it, a reboot will fix anything they managed to do since it is running toram.

I've ran one or two of my DSL boxen that way, and never had any issues.

I'm sure there are others around here that will not agree. However, with that said, I do use a dedicated firewall now all the time and one can be set up using old obsolete hardware if you so choose.
Back to top
Profile PM 
bigpilot Offline





Group: Members
Posts: 43
Joined: Jan. 2006
Posted: April 22 2006,05:32 QUOTE

We don't really know how much more secure Linux is than, say, Windows.

But I have a hunch it's not much more secure than Windows, to be honest. If you look at Mac OS X (also Unix based), for example, it was touted to be secure but right now bugs and exploits are being found almost on a weekly basis. There's no reason to believe it will be much better on Linux, although I do have a lot more confidence in open-source software than Apple's closed-source model.
Back to top
Profile PM 
green Offline





Group: Members
Posts: 453
Joined: Oct. 2004
Posted: April 22 2006,05:59 QUOTE

bigpilot,

One of the main reasons that Linux flavors are so much more secure that Windows is that the file structure is different and almost each *nix flavor's file structure is unique as compared to other flavors.

Thus, on a *nix machine, if an executable file is told to go to a certain file or program and then do this and that (the way viruses work) then you would have to write an executable file, enable it's permissions correctly, make sure it knows exactly what the file sturcture is then execute it's evil business, and all this to be designed with your specific flavor in mind. That is not very likely, at best.

Howver, if you write one for Windows, it'll kill 'em all cause they are all the same file structure and have all the same ports open (logical and virtual) and are all almost identical and most of the world uses it.

The second largest is the Mac. Therefore, Windows and Mac are more vulnerable to attack than Linux or other Nix systems due to their vast existence across the planet and so many people connecting to the 'net without conern to proper security.

Also, Windows must make a system that appeals to everyone, that's how they make their money. Again, that provides Linux with a strength. Linux can be customized down to the smallest of details, which can not be done in Windows or it would break. This is not a slam on Windows, it is just part of the reality of how the different operating systems are built.

Dedicated firewalls do not run on Windows. They run a unix-like OS. The same goes for mainframes, high-demand servers, network equipment, VPN concentrators, even secure terminal servers. Google, eBay, etc. run *nix systems. There is a reason that enterprise class IT shops use these. It is now trickeling down to the home user. Which is a good thing, if you ask me.

This is just a small example of the real world and a small security related tidbit. There is much more to learn if one has the time and desire to do so.

Lastly, I am not slamming Windows. I have to use it too. However, being in a field of work that gives me first hand knowlege of some of this stuff, that heavily influences my decisions about security and how I protect information/gear at home.

EDIT: Just thought I would throw this in.
A couple of years ago I read an article that spoke about how susceptible a windows box is when connected to the 'net without a firewall, etc. So, a friend and myself decided to sacrifice a windows box and a linux box. We hooked each one to the 'net via broadband access, there was no firewall protection, no anit-virus protoection, etc. After about 6 or 7 minutes, the Windows box had many ports open to who knows where and why. Another 30 minutes and the box was barely usable. The Linux box, under the same conditins, stayed connected all night and all day the next day. It had no issues and problems. I know this is not scientific, but it is proof enuf to me.

Sorry for the long post. I digress.....
Back to top
Profile PM 
pr0f3550r Offline





Group: Members
Posts: 378
Joined: Dec. 2005
Posted: April 22 2006,10:07 QUOTE

Quote (jpeters @ April 21 2006,17:33)
If I'm running DSL in ram and have the hardrive unmounted, is there any need for a firewall?

I have the same settings as yours and:
Code Sample
root@box:~# netstat -a
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State      
tcp        0      0 *:bootpc                *:*                     LISTEN      
tcp        1      0 10.0.2.15:1184          www.paypal.com:https    CLOSE_WAIT  
tcp        1      0 10.0.2.15:1033          l2.login.vip.scd.:https CLOSE_WAIT  
tcp        1      0 10.0.2.15:1032          l2.login.vip.scd.:https CLOSE_WAIT  
tcp        0      0 10.0.2.15:1166          damnsmalllinux.or:https CLOSE_WAIT  
tcp        1      0 10.0.2.15:1060          www.fastmail.fm:https   CLOSE_WAIT  
tcp        1      0 10.0.2.15:1061          www.fastmail.fm:https   CLOSE_WAIT  
tcp        1      0 10.0.2.15:1062          www.fastmail.fm:https   CLOSE_WAIT  
tcp        0      0 10.0.2.15:1138          www.fastmail.fm:https   CLOSE_WAIT  
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags       Type       State         I-Node Path
unix  2      [ ACC ]     STREAM     LISTENING     2858   /var/run/pump.sock
unix  2      [ ACC ]     STREAM     LISTENING     3466   /tmp/.X11-unix/X0
unix  2      [ ACC ]     STREAM     LISTENING     3509   /tmp/dsl-jhl9v6/dpid.sr                                                s
unix  2      [ ACC ]     STREAM     LISTENING     3511   /tmp/dsl-jhl9v6/bookmar                                                ks.dpi
unix  2      [ ACC ]     STREAM     LISTENING     3513   /tmp/dsl-jhl9v6/downloa                                                ds.dpi
unix  2      [ ACC ]     STREAM     LISTENING     3515   /tmp/dsl-jhl9v6/file.dp                                                i
unix  2      [ ACC ]     STREAM     LISTENING     3517   /tmp/dsl-jhl9v6/ftp.fil                                                ter.dpi
unix  2      [ ACC ]     STREAM     LISTENING     3519   /tmp/dsl-jhl9v6/hello.f                                                ilter.dpi
unix  2      [ ACC ]     STREAM     LISTENING     3521   /tmp/dsl-jhl9v6/https.f                                                ilter.dpi
unix  3      [ ]         STREAM     CONNECTED     3848   /tmp/.X11-unix/X0
unix  5      [ ]         STREAM     CONNECTED     3847  
unix  3      [ ]         STREAM     CONNECTED     3489   /tmp/.X11-unix/X0
unix  3      [ ]         STREAM     CONNECTED     3488  
unix  3      [ ]         STREAM     CONNECTED     3487   /tmp/.X11-unix/X0
unix  3      [ ]         STREAM     CONNECTED     3486  
unix  3      [ ]         STREAM     CONNECTED     3481   /tmp/.X11-unix/X0
unix  3      [ ]         STREAM     CONNECTED     3480  
unix  3      [ ]         STREAM     CONNECTED     3470   /tmp/.X11-unix/X0
unix  3      [ ]         STREAM     CONNECTED     3469  
root@box:~#


I think the X client/server connections are exposed to attacks.
A firewall is never overkill.


--------------
THE QEMU FORUM: http://qemu.dad-answers.com/index.php

QEMU ON WINDOWS: http://www.h7.dion.ne.jp/~qemu-win/

How to use floppy, CD-ROM and hard disk - http://www.h7.dion.ne.jp/~qemu-win/HowToFloppyCdrom-en.html

How to use network - http://www.h7.dion.ne.jp/~qemu-win/HowToNetwork-en.html
Back to top
Profile PM 
18 replies since April 21 2006,21:33 < Next Oldest | Next Newest >

[ Track this topic :: Email this topic :: Print this topic ]

Pages: (4) </ [1] 2 3 4 >/
reply to topic new topic new poll
Quick Reply: Security Questions

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code