Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help |
Name: zzsecurity | Distribution: Unknown |
Version: 3.0 | Vendor: Unknown |
Release: 7 | Build date: Mon Dec 18 10:23:35 2000 |
Group: System Environment/Base | Build host: eva01.open-it.org |
Size: 3080578 | Source RPM: zzsecurity-3.0-7.src.rpm |
Summary: Fixes several permission problems, stops known bad daemons from running |
Turns off many normally unneeded services that may pose a security risk. Tightens file permissions. Installs libsafe to defend against buffer overflows
David Brumley - All rights reserved 1999
* Mon Dec 18 2000 Joe Little <jlittle@stanford.edu> - (v7) fixed the same in kshell - fixed server_args in eklogin xinetd config file; noted by Susan Feng + user * Fri Nov 03 2000 Joe Little <jlittle@stanford.edu> - typo in service handling - moved /etc/leland/conf files to zzsecurity.tgz proper. * Wed Nov 01 2000 Joe Little <jlittle@stanford.edu> - Major change: dropped inetd and provided xinetd confs - used chkconfig to disable most xinetd default on settings to off - moved random files into a tgz for correct install * Tue Oct 24 2000 Joe Little <jlittle@stanford.edu> - changed /etc/issue, added webmin rpm placement in /root for post install * Sat May 13 2000 David Brumley <dbrumley@stanford.edu> - Added pre to do the backup of files - now we keep info on state before install. - changed files to be /etc/leland/conf -- whole directory will be included * Thu Jan 20 2000 David Brumley <dbrumley@stanford.edu> - Worked more on /etc/resolv.conf fix. Fix is echoing into /etc/sysconfig/network * Tue Jan 18 2000 Susan Feng <sfeng@stanford.edu> - Install /etc/resolv.conf - Fix /etc/hosts to include FQDN host name * Fri Jan 07 2000 Susan Feng <sfeng@stanford.edu> - Changed /etc/leland/conf/services to add ident as an alias service for auth. * Fri Sep 03 1999 David Brumley <dbrumley@stanford.edu> - Took out /etc/leland/conf/inetd.conf-krb - Changed /etc/hosts.allow to allow anything .stanford.edu * Thu Sep 02 1999 David Brumley <dbrumley@stanford.edu> - Added uninstall script. * Mon Aug 23 1999 David Brumley <dbrumley@stanford.edu> - changed /etc/hosts.allow to allow by default anything on .stanford.edu * Thu Aug 12 1999 David Brumley <dbrumley@stanford.edu> - fixed scripting error * Tue Aug 10 1999 David Brumley <dbrumley@stanford.edu> - Made script copy files before replacing them. Copied files are in /etc/leland/backup * Sun Aug 08 1999 David Brumley <dbrumley@stanford.edu> - added safe_file to change owner to root and change setting to 0755 * Wed Jul 21 1999 David Brumley <dbrumley@stanford.edu> - fixed /etc/leland/conf/hosts.allow * Tue Jul 20 1999 David Brumley <dbrumley@stanford.edu> - left setuid bit on dump/restore because it is needed for amanda backup (per joe little) - left setuid bit on mountd/umount because of functionality needed (per joe little) - left setuid bit on Xwrapper because it is needed by xauth (per mary washburn) - created non-kerberized /etc/leland/conf/inetd.conf-nokrb to be installed (per me) - created kerberized /etc/leland/conf/inetd.conf-kerb to be installed (per me) - put in /etc/leland/conf/inetd.conf-full with every service known (per joe little) - changed everything to use install command. - linked /etc/hosts.{allow,deny} to /etc/leland/hosts.{allow,deny} - changed group to be utilities/system from application/security - added /etc/leland/conf/services (more services :) - added our own /etc/issue.net - added our own /etc/issue
/etc/leland/conf/hosts.allow /etc/leland/conf/hosts.deny /etc/leland/conf/issue /etc/leland/conf/issue.net /etc/leland/conf/redhat-transparent.png /etc/leland/conf/resolv.conf /etc/leland/conf/services /etc/xinetd.d/eklogin /etc/xinetd.d/kftgtd /etc/xinetd.d/kshell /etc/xinetd.d/telnet /root/webmin-0.82.i386.rpm /usr/sbin/ifstatus
Generated by rpm2html 1.4
sulinux-help@leland.stanford.edu, Thu Dec 28 16:49:47 2000