Crackers — are people who, for purposes or to amuse themselves, like to break into other people’s computers — to steal information-are a clever bunch. If there is any vulnerability in a system, they will find it. Fortunately, the Linux development community is quick to find potential exploits and to find ways of slamming shut the door before crackers can enter. Fortunately, too, Red Hat is diligent in making available new, patched versions of packages in which potential exploits have been found. So your first and best security tool is making sure that whenever a security advisory is issued, you download and install the repaired package. This line of defense can be annoying, but it is nothing compared to rebuilding a compromised system.
And as good as the bug trackers are, sometimes their job is reactive. Preventing the use of your machine for bad purposes and guarding against intrusion are, in the end, your responsibility alone. Again, Red Hat Linux equips you with tools to detect and deal with unauthorized access of many kinds. In later posts, you’ll learn how to install and configure these tools and how to make sense of the warnings they provide. If your machine is connected to the Internet, you will be amazed at the number of attempts that are made to break into your machine.
Related Posts:-
Blogroll
Glossary
Installing Linux On a Server
- Installing and configuring Vmware2 to Run Linux (R...
- Installing Linux in a Server Configuration
- Performing Preinstallation Evaluation
- Linux System Administrator
- Installing and Configuring Servers
- Installing and Configuring Application Software
- Creating and Maintaining User Accounts
- Backing Up and Restoring Files
- Monitoring and Tuning Performance
- Configuring a Secure System
- Using Tools to Monitor Security
- Server Design
- Uptime
- Dual-Booting Issues
- Methods of Installation
- Determining a Server’s Functions
- Using the Red Hat Package Manager
- Initialization Scripts
Network Configuration
Filesystem Primer
- Understanding Filesystem Hierarchy Standard
- Basic Linux Directory Structure
- Partition Schemes
- Managing Partitions
- Managing partitions with fdisk
- Adding A New Hard Drive
- Basic Linux Formats
- Formatting a partition
- Tuning
- Troubleshooting With FSCK
- Exploring Logical Volume Management
- File Permissions 1
- File Permissions 2
- umask
- Concept of the i-Nodes and Superblocks in Linux/Un...
- Understanding ext3 file system and its advantages
Administering Users and Groups Securely
Network File System
Showing posts with label Duties system administrator. Show all posts
Showing posts with label Duties system administrator. Show all posts
Configuring a Secure System
Linux Administrator"s most important duty is the , security of the computer and data integrity.
What does this mean? The system administrator’s most important task, first and foremost, is to make certain that no data on the machine or network are likely to become corrupted, whether by hardware or power failure, by misconfiguration, or by malicious or inadvertent intrusion from elsewhere.
Everyone involved in computing are aware of the increasing serious attacks upon machines connected to the Internet. The majority of these have not targeted Linux systems, but that doesn’t mean that Linux systems
have been entirely immune, either to direct attack or to the effects of attacks on machines running other operating systems.
In one such Distributed Denial of Service (DDoS) attack aimed at several major online companies, many of the “zombie” machines(Machines unknowingly used to spread malware without its owners consent ) — so that the vandals could employ thousands of machines instead of just a few — were running Linux that had not been patched to guard against a well-known security flaw. In the various “Code Red” attacks of the summer of 2001, Linux machines themselves were invulnerable, but the huge amount of traffic generated by this “worm” infection nevertheless prevented many Linux machines from getting much Web-based work done for several weeks, so fierce was the storm raging across the Internet. While these infection did not corrupt Linux machines as it did those running a different operating system.
Security can be as simple as turning off unneeded services, monitoring the Red Hat Linux security mailing list to make sure that all security advisories are followed, and otherwise engaging in good computing practices to make sure the system runs robustly. Or it can be an almost full-time job involving levels of security permissions within the system and systems to which it is connected, elaborate firewalling to protect not just Linux machines but machines that, through their use of non-Linux software, are far more vulnerable, and physical security — making sure no one steals the machine itself! For any machine that is connected to any other machine, security means hardening against attack and making certain that no one is using your machine as a platform for launching attacks against others. If you are running Web, ftp, or mail servers, it means giving access to those who are entitled to it while locking out everyone else. It means making sure that passwords are not easily guessed and not made available to unauthorized persons.
So your job as a system administrator is to strike just the right balance between maximum utility and maximum safety, all the while bearing in mind that confidence in a secure machine.
There are many tools that Red Hat Linux provides to help you guard against intrusion, even to help you prevent intrusion into non-Linux machines that may reside on your network. Linux is designed from the beginning with security in mind, and in all of your tasks you should maintain that same security awareness
Related posts:-
What does this mean? The system administrator’s most important task, first and foremost, is to make certain that no data on the machine or network are likely to become corrupted, whether by hardware or power failure, by misconfiguration, or by malicious or inadvertent intrusion from elsewhere.
Everyone involved in computing are aware of the increasing serious attacks upon machines connected to the Internet. The majority of these have not targeted Linux systems, but that doesn’t mean that Linux systems
have been entirely immune, either to direct attack or to the effects of attacks on machines running other operating systems.
In one such Distributed Denial of Service (DDoS) attack aimed at several major online companies, many of the “zombie” machines(Machines unknowingly used to spread malware without its owners consent ) — so that the vandals could employ thousands of machines instead of just a few — were running Linux that had not been patched to guard against a well-known security flaw. In the various “Code Red” attacks of the summer of 2001, Linux machines themselves were invulnerable, but the huge amount of traffic generated by this “worm” infection nevertheless prevented many Linux machines from getting much Web-based work done for several weeks, so fierce was the storm raging across the Internet. While these infection did not corrupt Linux machines as it did those running a different operating system.
Security can be as simple as turning off unneeded services, monitoring the Red Hat Linux security mailing list to make sure that all security advisories are followed, and otherwise engaging in good computing practices to make sure the system runs robustly. Or it can be an almost full-time job involving levels of security permissions within the system and systems to which it is connected, elaborate firewalling to protect not just Linux machines but machines that, through their use of non-Linux software, are far more vulnerable, and physical security — making sure no one steals the machine itself! For any machine that is connected to any other machine, security means hardening against attack and making certain that no one is using your machine as a platform for launching attacks against others. If you are running Web, ftp, or mail servers, it means giving access to those who are entitled to it while locking out everyone else. It means making sure that passwords are not easily guessed and not made available to unauthorized persons.
So your job as a system administrator is to strike just the right balance between maximum utility and maximum safety, all the while bearing in mind that confidence in a secure machine.
There are many tools that Red Hat Linux provides to help you guard against intrusion, even to help you prevent intrusion into non-Linux machines that may reside on your network. Linux is designed from the beginning with security in mind, and in all of your tasks you should maintain that same security awareness
Related posts:-
9:35 PM | Filed Under Duties system administrator, system administrator | 0 Comments
Backing Up and Restoring Files
Until equipments becomes absolutely failure proof, and until people lose their desire to harm the property of others for personal benefits (and, truth be known, until system administrators become perfect), there is always a need to back up important files and data so that in the event of a failure of hardware, security, or administration, the system can be up and running again with minimal disruption. Only the system administrator may do this.
(Because of its built-in security features, Linux may not allow users to be able even to back up their own files to floppy disks.)
Again, knowing that file backup is your job is not enough. You need to formulate a proper strategy for making sure your system is not vulnerable to disruption. If you have a high-capacity tape drive and several restore diskettes, you might make a full system backup in every few days. If you are managing a system with scores of users, It is more sensible to back up user accounts and system configuration files, from the distribution CDs. (Don’t forget the applications you’ve installed separately from your Red Hat Linux distribution, especially including anything heavily customized!)
Once you’ve decided what to back up, you need to decide how frequently to perform backups and whether you wish to maintain a series of incremental backups — adding only the files that have changed since the last backup — or multiple full backups, and when these backups are to be performed — do you trust an automated, unattended process?
A strategy should be the maintenance of perfect backups without ever needing to resort to them. This means encouraging users to keep multiple copies of their own important files, all in their home directories, so that you are not being asked to mount a backup so as to restore a file that a user has corrupted.(And if the system is stand-alone, you as your own system administrator might want to make a practice of backing up configuration and other important files.)
The chances are that even if you’re working for a company, you’ll make these decisions — all your boss wants is a system that works perfectly, all the time. Backing up is only half the story, too. You need to formulate a plan for bringing the system back up in the event of a failure.
RELATED POSTS:-
(Because of its built-in security features, Linux may not allow users to be able even to back up their own files to floppy disks.)
Again, knowing that file backup is your job is not enough. You need to formulate a proper strategy for making sure your system is not vulnerable to disruption. If you have a high-capacity tape drive and several restore diskettes, you might make a full system backup in every few days. If you are managing a system with scores of users, It is more sensible to back up user accounts and system configuration files, from the distribution CDs. (Don’t forget the applications you’ve installed separately from your Red Hat Linux distribution, especially including anything heavily customized!)
Once you’ve decided what to back up, you need to decide how frequently to perform backups and whether you wish to maintain a series of incremental backups — adding only the files that have changed since the last backup — or multiple full backups, and when these backups are to be performed — do you trust an automated, unattended process?
A strategy should be the maintenance of perfect backups without ever needing to resort to them. This means encouraging users to keep multiple copies of their own important files, all in their home directories, so that you are not being asked to mount a backup so as to restore a file that a user has corrupted.(And if the system is stand-alone, you as your own system administrator might want to make a practice of backing up configuration and other important files.)
The chances are that even if you’re working for a company, you’ll make these decisions — all your boss wants is a system that works perfectly, all the time. Backing up is only half the story, too. You need to formulate a plan for bringing the system back up in the event of a failure.
RELATED POSTS:-
8:14 PM | Filed Under Duties system administrator, system administrator | 0 Comments
Creating and Maintaining User Accounts
Anyone cannot log on to a Linux machine. An account must be created for each user and — you guessed it — no one but the system administrator may do this. That’s simple enough.
But there are decisions that either you or your company must make. You might want users to select their own passwords, which would be easier for them to remember, but which probably would be easier for an external factor to crack. You might assign passwords, which is more secure in theory but which increases the chances that users will write them down on a conveniently located scrap of paper — a risk if many people have access to the area where the machine(s) is located. You might want that users must change their passwords periodically, and you can configure Red Hat Linux to prompt users to do so.
And what to do about old accounts? Perhaps someone has left the company. What happens to his or her account? You probably don’t want him or her to continue to have access to the company network. On the other hand, you don’t want to simply delete the account, because it might contain some essential data which is reside nowhere else.
There are aspects of your business that make World Wide Web access desirable, but you don’t want user"s spending their working hours surfing the Web.
The following issues and others are parts of the system administrator’s duties in managing user accounts. The administrator or his employer must establish the policies governing them— if in an enterprise, preferably in writing — for the protection of all concerned.
RELATED POSTS:-
But there are decisions that either you or your company must make. You might want users to select their own passwords, which would be easier for them to remember, but which probably would be easier for an external factor to crack. You might assign passwords, which is more secure in theory but which increases the chances that users will write them down on a conveniently located scrap of paper — a risk if many people have access to the area where the machine(s) is located. You might want that users must change their passwords periodically, and you can configure Red Hat Linux to prompt users to do so.
And what to do about old accounts? Perhaps someone has left the company. What happens to his or her account? You probably don’t want him or her to continue to have access to the company network. On the other hand, you don’t want to simply delete the account, because it might contain some essential data which is reside nowhere else.
There are aspects of your business that make World Wide Web access desirable, but you don’t want user"s spending their working hours surfing the Web.
The following issues and others are parts of the system administrator’s duties in managing user accounts. The administrator or his employer must establish the policies governing them— if in an enterprise, preferably in writing — for the protection of all concerned.
RELATED POSTS:-
7:44 PM | Filed Under Duties system administrator, system administrator | 0 Comments
Installing and Configuring Application Software
It’s crucial and important for the new Linux system administrator to understand two characteristics that set Linux apart from other popular commercial operating systems: The first is the root or super user, and the second is that Linux is a multiuser operating system. Each user has (or shares) an account on the system, it may be on a separate machine or on a single machine with multiple accounts.Reason for there importance is found in the administration of application software — productivity programs.
Individual users can install some applications in their home directories — drive space set aside for their own files and customizations — these applications are not available to other users. Besides, if an application is to be used by more than one user, it needs to be installed higher up in the Linux file hierarchy, which is a job
of the system administrator only. (The administrator can even decide which users may use which applications by creating a “group” for that application and enrolling individual users into that group.)
Note:- The location of the installation of application usually matters only if you compile the application from source code; if you use a Red Hat Package Manager (RPM) application package, it automatically goes where it should.
Configuration and customization of applications is to some extent at the user’s
discretion, but not entirely. “Skeleton” configurations — administrator can determine default configurations . For example-
If there are particular forms, that are used throughout an enterprise, the system administrator would set them up or make them available by adding them to the skeleton configuration. The same applies, too, in configuring user desktops and determine what applications should appear on user desktop menus. Your company may not want the games that comes with modern Linux desktops to be available to users.
Related Posts:-
Single Users vs. Multiusers vs. Network Users
Installing and Configuring Servers
Individual users can install some applications in their home directories — drive space set aside for their own files and customizations — these applications are not available to other users. Besides, if an application is to be used by more than one user, it needs to be installed higher up in the Linux file hierarchy, which is a job
of the system administrator only. (The administrator can even decide which users may use which applications by creating a “group” for that application and enrolling individual users into that group.)
Note:- The location of the installation of application usually matters only if you compile the application from source code; if you use a Red Hat Package Manager (RPM) application package, it automatically goes where it should.
Configuration and customization of applications is to some extent at the user’s
discretion, but not entirely. “Skeleton” configurations — administrator can determine default configurations . For example-
If there are particular forms, that are used throughout an enterprise, the system administrator would set them up or make them available by adding them to the skeleton configuration. The same applies, too, in configuring user desktops and determine what applications should appear on user desktop menus. Your company may not want the games that comes with modern Linux desktops to be available to users.
Related Posts:-
Single Users vs. Multiusers vs. Network Users
Installing and Configuring Servers
5:10 AM | Filed Under Duties system administrator | 0 Comments
Installing and Configuring Servers
In the world of Linux, the word “server” has a broader meaning than you might be used to. For instance, the standard Red Hat Linux graphical user interface (GUI) requires a graphical layer called XFree86. This is a server. It can run even on a standalone machine with one user account. It must be configured. (Fortunately, Red Hat Linux has made this a simple and painless part of installation on all).
Similarly, printing in Linux takes place after you have configured a print server. Again, this has become so easy. In certain areas the client-server nomenclature can be confusing, though. While you cannot have a graphical desktop without a server, you can have World Wide Web access without a Web server, File transfer protocol (FTP) access without running an FTP server, and Internet e-mail capabilities without ever starting a mail server. You may want to use these servers, all of which are included in Red Hat Linux, but then again you may not. And whenever a server is connected to other machines outside your physical control (remotely), there are security implications — you want users to have easy access to the things they need, but you don’t want to open up the system you’re administering to the whole wide world.
Linux distributions used to be shipped with all imaginable servers turned on by default. This was earlier thinking. But the realities of a modern, more dangerous world have dictated that essential servers are off unless they are manually enabled and configured. This duty falls to the system administrator. Administrator need to know what servers you need and how to employ them, and to be aware that it is a potential security nightmare to enable services that the system isn’t using and doesn’t need.
Similarly, printing in Linux takes place after you have configured a print server. Again, this has become so easy. In certain areas the client-server nomenclature can be confusing, though. While you cannot have a graphical desktop without a server, you can have World Wide Web access without a Web server, File transfer protocol (FTP) access without running an FTP server, and Internet e-mail capabilities without ever starting a mail server. You may want to use these servers, all of which are included in Red Hat Linux, but then again you may not. And whenever a server is connected to other machines outside your physical control (remotely), there are security implications — you want users to have easy access to the things they need, but you don’t want to open up the system you’re administering to the whole wide world.
Linux distributions used to be shipped with all imaginable servers turned on by default. This was earlier thinking. But the realities of a modern, more dangerous world have dictated that essential servers are off unless they are manually enabled and configured. This duty falls to the system administrator. Administrator need to know what servers you need and how to employ them, and to be aware that it is a potential security nightmare to enable services that the system isn’t using and doesn’t need.
6:41 AM | Filed Under Duties system administrator | 0 Comments
Install Softwares
- Install Vuze(Azureus) Bittorent client on Linux 64..
- Install Skype(pc2pc calling software) On Linux 64 ...
- Install WEBMIN to Graphically Administer Your Linu...
- Opening And Extracting .rar Files in Linux/Unix sy...
- Installing vlc player in Fedora/Red Hat/ CentOS
- Linux text to speech festival
- Installing Thunderbird E-mail client