Vous voulez voir cette page en français ? Cliquez ici.


or
Sign in to turn on 1-Click ordering.
More Buying Choices
Have one to sell? Sell yours here
Real World Linux Security
 
See larger image
 

Real World Linux Security [Paperback]

Bob Toxen
4.6 out of 5 stars  See all reviews (45 customer reviews)
List Price: CDN$ 62.99
Price: CDN$ 42.59 & this item ships for FREE with Super Saver Shipping. Details
You Save: CDN$ 20.40 (32%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
Temporarily out of stock.
Order now and we'll deliver when available. We'll e-mail you with an estimated delivery date as soon as we have more information. Your account will only be charged when we ship the item.
Ships from and sold by Amazon.ca. Gift-wrap available.

Formats

Amazon Price New from Used from
Paperback CDN $42.59  

Product Details


Product Description

Book Description

Your Linux system will be attacked. Be ready! Real World Linux Security, Second Edition brings together state-of-the-art solutions and exclusive software for protecting yourself against today's most vicious Internet attacks. Highlights include surprising new research on IP Tables effectiveness; new ways to block ARP attacks; advances in adaptive firewalls; quick recovery from intrusions; securing wireless systems, instant messaging, VPNs, Samba, and Linux 2.4 kernels; and much more. Includes CD-ROM with the author's exclusive security software tools!

From the Inside Flap

PrefaceIntroduction

Linux is a solid operating system. It is easy to use and install, has very powerful capabilities, runs fast on almost any hardware, and rarely crashes. It has few bugs and its widespread support from a cast of thousands ensures that any remaining bugs get fixed as soon as they are discovered. It is highly versatile and can be made as secure as any UNIX system.

Unfortunately, UNIX and Linux machines are broken into every day, not because they are inherently insecure, but because the steps required to expose a system to the real world safely—the modern Internet—are not always so obvious. The single goal of this book is to teach any Linux or UNIX system administrator how to secure his systems, keep them secure, and feel confident that all necessary steps have been taken.

Introduction to the Second Edition

Much has happened in the two years since the first edition of Real World Linux Security was published and much that was anticipated has not come to pass. Rather than the anticipated upward-compatible version of IP Chains with additional features and security, we have IP Tables. Transitioning to IP Tables requires a major rewrite of any firewall script, and some features present in IP Chains under the Linux 2.2 kernel are absent from both IP Tables and IP Chains in the 2.4 kernel. IP Tables is addressed in this book in great detail, and I include some fascinating original research and firewall tips and techniques (see ""Firewalls with IP Tables and DMZ" on page 446). You will not find this information elsewhere.

The Internet has become a much more dangerous place. Two years ago an unhardened system stood a reasonable chance of not being compromised for months or even years. Now, an unsecured system probably will be broken into within a week or two, and a complete compromise within one day of being placed on the Web is common. With the popularity of always-on DSL and cable connections, the exposure to possible compromise is increased by a factor of 10, too. It is guaranteed that each system on the Internet gets scanned for various vulnerabilities on a daily basis now.

The cyber warfare of science fiction is now a fact! There is credible evidence that the Al Qaeda is preparing to commit damaging attacks against U.S. businesses and government. A number of countries' governments or individuals have staged massive cyber attacks against their enemies. With almost every Internet-connected computer handling credit card data, and crackers (sometimes called hackers) getting more vicious and more interested in financially profiting from their attacks, there is far more at risk.

In 2000 and later, there was much talk about the U.S. Federal Bureau of Investigation (FBI) getting more involved in solving computer crime, and there was much talk worldwide about more laws to reduce computer crime. In 2000, Microsoft promised to make great improvements in Windows security and again promised this in early 2002. I have seen none of this come to pass. While the big Linux vendors have made good on their promises to improve on security, they still have made big goofs in the security of even their latest offerings and even the "rock solid" Apache has not been immune from recent major vulnerabilities.

It is my opinion that even the viruses that have caused billions of dollars in damage due to lost files and wasted time are mild compared to what is possible. Viruses that can attack both Windows and Linux and viruses that can attack Linux and several flavors of UNIX have been demonstrated. As I write this, there are major security vulnerabilities in the current versions of Apache on Linux, UNIX, and Windows (the first in five years), as well as in Internet Explorer and Internet Information Services (IIS) running on most systems. It would not be especially difficult for a hacker to create a virus that attacks all of these platforms, sniffs these systems for credit card, bank account, and investment account numbers, and drains the accounts of money before anyone discovers it.

Real World Linux Security has undergone a major revision in the second edition. Problems that people did not worry about two years ago are now big concerns and have been addressed here. New technologies, such as wireless networks and IP Tables, have been addressed in depth. Hackers now are using more subtle attacks that were rare two years ago. These include attacking at the address resolution protocol (ARP) level. Even the lowly network switch now is being compromised with regularity. All of these situations are addressed.

Better methods for monitoring your network and instantly locking out attackers in this more vicious world are explained in step-by-step detail. Arpwatch, Logcheck, Portsentry, the newest versions of Samba and the GNU Privacy Guard (the GNU answer to Pretty Good Privacy PGP), the 2.4 kernel, Red Hat 7.3 and SuSE 8.0, VPNs, and greatly improved Adaptive Firewall techniques all are covered in depth in this book. About 150 pages of new material have been added, while appendices containing listings of programs on the CD-ROM and obsolete material have been removed or revised.

Who Should Read This Book?

This book will aid Linux and UNIX System Administrators (SysAdmins) in making their systems and networks as secure as possible from intruders and improper action of the users. It covers both quick and simple solutions, and some more involved solutions to eliminate every possible vulnerability.

It is organized to allow the busy SysAdmin to increase the security of the systems one piece at a time. It is recognized that one cannot take a system down for a week and work exclusively on its security for that week. In the real world, a SysAdmin's time is divided up by many tasks that cannot wait and systems are too critical to stay down for long.

In the real world, some systems will be broken into despite the best efforts of talented SysAdmins. This book devotes over 60,000 words to dealing with a possible break-in. It deals with how to prepare for it, how to detect it, and how to recover from it quickly and completely with minimal loss of confidential data and money, with minimal inconvenience to one's customers and employees, and with minimal publicity. This is considered one of the unique features of this book.

On March 30, 2000, 350 "hackers" from around the world gathered in Israel for a conference. Organizers there said that they were able to break into 28 percent of Israeli computers that they tried and that this percentage was typical worldwide. This was with the permission of the computers' owners, who were convinced that their computers were invulnerable. The quoted statistics were not broken down by operating system type. Both John Draper ("Captain Crunch") and Kevin Mitnick were there.

The book is designed to be used by the veteran of many years of Linux and UNIX experience, as well as the new SysAdmin. It does assume that the reader is somewhat knowledgeable in system administration; Prentice Hall has other fine books to help people hone their SysAdmin skills. There are many useful details here, both for the person with a single Linux box at home and for those supporting multinational corporations and large government agencies with very large networks comprised of multiple types of operating systems.


Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 

 

Customer Reviews

45 Reviews
5 star:
 (35)
4 star:
 (3)
3 star:
 (6)
2 star:
 (1)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.6 out of 5 stars (45 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most helpful customer reviews

5.0 out of 5 stars Simple, concise, easy to read, Dec 23 2003
This review is from: Real World Linux Security (Paperback)
Bob Toxen came out with a valuable book which is easy to comprehend, and can be implemented immediately into production systems. His examples are clear and direct to the point, which makes reading and understanding a breeze.

Whether you've been working with internet security or just starting, this book is a must have!

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


5.0 out of 5 stars The best on the subject; practical and thorough, Dec 8 2003
By 
Douglas Merritt "Professional WildEyed Visionary" (San Jose, CA United States) - See all my reviews
(REAL NAME)   
This review is from: Real World Linux Security (Paperback)
Real World Linux Security (2nd ed.) far exceeded my already-high
expectations, having known the author and his expertise for a
long time. Computer security is one of my secondary fields of
expertise, as is Linux, yet I learned a lot from this book that
I had previously overlooked -- and it helped me repair a system
that crackers had attacked.

Bob writes in a very readable way that manages to be simultaneously
entertaining and informative, a very rare combination.

He clearly realizes that a lot of readers will be in a hurry,
looking for advice when there's already trouble brewing, so
he starts with a very terse overview, going immediately to
chapter 2 "Quick Fixes for Common Problems. Chapters 4 and 5
cover the most commonly attacked subsystems and how they're
attacked.

That's already book-length; over 250 pages. It goes on
to Advanced Security Issues, Security Policies, Case Studies
(wherein I'm mentioned :-) scanning and monitoring your
system, regaining control, repairing damage, and much much
more than I can mention in the max 1000 words here.

Extremely extensive, and both the table of contents and index
are well done, something important to me for quick reference.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


5.0 out of 5 stars Security that works!, Sep 21 2003
By A Customer
This review is from: Real World Linux Security (Paperback)
This book is at the top of my list when it comes to Linux security books. It
has more information on securing Linux than any other I've read. And when I
say Linux, I mean Linux not the plethora of applications and servers that run
on Linux. Granted, it touches on some of the more "standard" servers, like
Apache, Sendmail, and Samba. But the majority of the book is dedicated to
securing Linux, servers, and applications in general. So, if you are looking
for a book to tell you how to lock-down ProFTPD, this isn't it. Because of
this limited scope, unlike other Linux security books that try to cover
everything imaginable, it manages to cover the topic thoroughly.

The book starts off with "quick fixes" and then moves on to more advanced
security issues. This is done so that you can get your system relatively
secure as soon as possible, and deal with securing some of the more obscure
and complex things in a progressive nature. It deals with just about

everything from making your users choose hard to crack passwords, to defining
a written security policy, to collecting information about break-ins and
getting law enforcement involved. This is a real well rounded and robust
book.

Two things make this an awesome addition to any Linux user or administrator's
collection. First, the author knows Linux inside and out. I was quite
surprised to see security solutions that include kernel modifications as an
option. In addition to his knowledge of Linux, the author has a very jovial
writing style that you seldom find in books of a technical nature. I felt no
need to force myself to read this book, because the author's writing style
was engaging kept my attention. Second, the author (and Prentice Hall)
included a CD with the book that contains software that the author wrote or
modified (to extend its functionality and/or usefulness). The CD itself is
worth the price of the book alone.

This book is a good buy and I would recommend picking up a copy of this book
if you are running Linux in a business or home environment.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
Want to see more reviews on this item?
 Go to Amazon.com to see all 47 reviews  4.6 out of 5 stars 
 
 
Most recent customer reviews











Only search this product's reviews



Listmania!

Create a Listmania! list

Look for similar items by category


Look for similar items by subject


Feedback


Amazon.ca Privacy Statement Amazon.ca Shipping Information Amazon.ca Returns & Exchanges