Re: Virus Adware & Spyware protection
- From: Colin McKinnon <colin.thisisnotmysurname@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 25 Oct 2007 18:40:12 GMT
anahata wrote:
Andy Cap wrote:<snip>
What do people recommend are the basic requirements
along with any personal recommendations.
There are AV packages for Linux (see clamav), but their main purpose is
to deal with Windows viruses in Linux mail servers that are used by
Windows clients.
I'd go with the CERT Unix/Linux checklist (
http://www.cert.org/tech_tips/usc20_full.html ) You should certainly have a
firewall configured both to restrict access and trap un-expected outgoing
traffic. If you're going to allow remote ssh access to the machine do think
about making it more difficualt for the worms to get in (different port,
port knocking, keypair only logins, no root login, AllowGroups). I'd
strongly recommend running a host based IDS (tripwire, L5 or similar).
You'll be so glad you did if you ever get root-kitted.
If you've got Windows clients using the Linux box as a server you definitely
want to be running AV on any services - mail and Samba are both easily done
with Clamav. Clamav is free, AND its quite good at detecting nasties. I'd
recommend using a different vendor's solution on the clients - in part
because its generally a good idea to have different AV products on
different tiers, but also because (AFAIK) Clamav doesn't do realtime
scanning on MSWin. You can virus scan web access via squid - I've not
looked at this recently though.
HTH
C.
.
- Follow-Ups:
- Re: Virus Adware & Spyware protection
- From: Andy Cap
- Re: Virus Adware & Spyware protection
- References:
- Virus Adware & Spyware protection
- From: Andy Cap
- Re: Virus Adware & Spyware protection
- From: anahata
- Virus Adware & Spyware protection
- Prev by Date: Re: Virus Adware & Spyware protection
- Next by Date: Re: Virus Adware & Spyware protection
- Previous by thread: Re: Virus Adware & Spyware protection
- Next by thread: Re: Virus Adware & Spyware protection
- Index(es):
Relevant Pages
|
|