Education Center on Computational Science and Engineering

Network Security Precautions

Prepared by: Tom Handal

Tommy@edcenter.sdsu.edu

16 July, 1999

    1. SUN Ultra-2 System Running Solaris 5
    2. Pentium-II PCs Running RedHat Linux 6.0, 3 each
    3. Pentium-II Machines running Windows NT 4.0

1. Recommend upgrading Operating System to Solaris 7

Source: SUN Microsystems - http://www.sun.com/solaris/faqs/sol7faqs.html#security

2. Recommend disabling TELNET on edcenter.sdsu.edu

3. List of deamons running on Sun Ultra-2 must be obtained and analyzed for known security holes, namely open ports that are not used.

4. Recommend limiting users that have SENDMAIL access to Sun Ultra-2 System. This will help prevent spamming through our server and also prevent mail bombing and things of that nature.

5. Sociology Workbench Web Site Security Measures

    1. List of deamons running on these machines must be obtained and analyzed for known security holes, namely open ports that are not used.
    2. SSH should be installed on all PCs running RedHat Linux 6.0
    3. APACHE Web Server (httpd) should be shut down on these machines, due to the fact that we do not serve web sites from these systems.
    4. Recommend disabling INETD on these machines. This will effectively disable TELNET and FTP.
    5. Recommend disabling SENDMAIL deamon on these machines
    6. Check with RedHat for possible updates/patches for versions of software, especially network software on these machines. This should be done periodically to maintain a high level of network security.
    7. Be sure that all accounts on these machines have passwords that are at least 6 characters in length and are not dictionary words, names, or plain numbers. Have passwords on accounts changed every few months.

1. Recommend machines are updates with latest Service Packs and patches.

2. Microsoft Internet Explorer must be periodically checked for security issues by checking http://www.microsoft.com

3. Be sure that all accounts on these machines have passwords that are at least 6 characters in length and are not dictionary words, names or plain numbers. Have passwords on account changed every few months.