bk99.de entertain the web since 1997

Securing Linux and BSD servers properly

Summary

Philipp Pobaschnig shows why default installations are not a finished security strategy and how small, systematic changes close typical attack paths. Server hardening is a recurring operational process rather than a one-off checklist. The most secure feature is often the service nobody had to install.

Ideas

  • Unnecessary services enlarge the reachable attack surface.
  • Default configurations often put compatibility before least privilege.
  • Up-to-date software only prevents known bugs, not wrong permissions.
  • Logs and integrity checks make successful attacks visible earlier.

Recommendations

  • Regularly take inventory of reachable ports and the processes responsible for them.
  • Automate updates, configuration checks and tested recovery.

References

Watch the talk

Search the Web Archive