Gentoo Archives: gentoo-hardened

From: Kevin Chadwick <ma1l1ists@××××××××.uk>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm...
Date: Mon, 12 Dec 2011 14:07:55
Message-Id: 20111212140825.73b06f80.ma1l1ists@yahoo.co.uk
In Reply to: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm... by Kevin Chadwick
1 On Mon, 12 Dec 2011 13:38:00 +0000
2 Kevin Chadwick wrote:
3
4 > Hard to recall but I'll try to list them
5 > somewhere as they come to me now.
6
7
8 Here's one example that's just come to me and that I configured but
9 never put in production. I acquired a free and supposedly good Cisco
10 router. I configured it and disabled the web server router
11 advertisements and all the other stuff it spits out by default that I
12 had no need for. Later an exploit in those very communications,
13 gratifying but no risk avoidance. Cisco have also had exploits in ipv6
14 and in other cheaper devices, default web root passwords etc..
15
16 Unless you need the performance I really wouldn't go near Cisco any
17 more. My cousin uses sonicwall, atleast one model uses assembly to speed
18 it up, which I'd look at in that case. Cisco's Senderbase use some dumb
19 mail reputation rules too, probably because I think it's a middle man
20 without the whole picture.

Replies

Subject Author
Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm... "Javier Juan Martínez Cabezón" <tazok.id0@×××××.com>