19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 12-6:<br />

Using<br />

NetScan<br />

Tools Pro to<br />

determine<br />

that<br />

Slackware<br />

Linux is<br />

running.<br />

Chapter 12: Linux<br />

Countermeasures against system scanning<br />

Although you can’t completely prevent system scanning, you can still implement<br />

the following countermeasures to keep the bad guys from gleaning too<br />

much information about your systems:<br />

✓ Protect the systems with either<br />

• A firewall, such as iptables that’s built into the OS<br />

• A host-based intrusion-prevention application, such as PortSentry<br />

(http://sourceforge.net/projects/sentrytools) and<br />

SNARE (www.intersectalliance.com/projects/Snare)<br />

✓ Disable the services you don’t need, including RPC, HTTP, FTP, telnet,<br />

and the small UDP and TCP services — anything for which you don’t<br />

have a true business need. This keeps the services from showing up in<br />

a port scan, which gives an attacker less information — and presumably<br />

less incentive — to break in to your system.<br />

✓ Make sure the latest software and patches are loaded to reduce the<br />

chance of exploitation if an attacker determines what services you’re<br />

running.<br />

233

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!