Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Getting a minimal distro also gives you the possibility to install only the things which are needed, instead of uninstalling a lot of stuff which came in by default.

Additionally - if you are serious about monitoring, you should ship the logs to some external host in realtime, so they can't be deleted / changed.

Running services in jails is definitely a good idea. Additionally configuring Apparmor and Selinux could be a good idea too. Or even switching to a grsec kernel. For the consistency checking, I prefer Samhain.



I thought Ubuntu had AppArmor on and configured by default for many/most of the popular services (Apache etc). I often see 'updating AppArmor profile' log messages in system updates, in any case.


Only as long as you use the default paths and enforce the profiles... which should be the default for most people. But I think it's worth mentioning in case you have a specific application which you reverse-proxy, or install nginx, or ....




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: