First Run: What are your security protocols for fresh installs?

Discussion in 'all things UNIX' started by TomeiNingen, Nov 15, 2016.

  1. TomeiNingen

    TomeiNingen Registered Member

    Joined:
    Nov 8, 2016
    Posts:
    50
    Location:
    Fort Meade, Maryland
    Working on putting a hardening reference together and would love to get an idea of some of your "best practices" for locking down a Linux system confidently. What Do's and Don'ts do you subscribe to when it comes to locking your machines down after a fresh OS install?

    Lynis, Tripwire, Samhain, Suricata... any favorites worth exploring? Prefer one program over another?
     
  2. Anonfame1

    Anonfame1 Registered Member

    Joined:
    May 25, 2016
    Posts:
    224
    grsecurity, setup iptables (or use UFW), LUKS (disk encryption), mandatory access control at least for web browser (apparmor, RBAC, tomoyo, SELinux), firejail (for the web browser and other network facing apps), KVM (only VM option that works with grsecurity) with Whonix (for Tor), and try to build it as light as possible (less code, less holes).

    I dont use intrusion detection since I'm usually behind a router...
     
  3. Amanda

    Amanda Registered Member

    Joined:
    Aug 8, 2013
    Posts:
    2,115
    Location:
    Brasil
    • Zero-Fill
    • Cryptsetup/LUKS on LVM
    • System install
    • Backup of GPT/MBR, boot sectors, etc
    • rkhunter install
    • rkhunter --propupd
    • Firewall config
    • general programs install
    • firejail everything
    • grsec compile and install
    • reboot
    And only then I can use my computer without worries.
     
  4. TomeiNingen

    TomeiNingen Registered Member

    Joined:
    Nov 8, 2016
    Posts:
    50
    Location:
    Fort Meade, Maryland

    Great, thanks! Could I trouble you for your insight over in this thread? I'm hoping to have a reference together by EOY and would be in your debt for any help you might offer :).
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.