Chapter 5. Server Security
55
5.6.5. Use TCP Wrappers To Control Access
You can use TCP wrappers to control access to either FTP daemon as outlined in Section 5.1.1.
5.6.6. Use
xinetd
To Control the Load
You can use
xinetd
to control the amount of resources the FTP server consumes and to limit the
effects of denial of service attacks. See Section 5.1.2 for more on how to do this.
5.7. Securing Sendmail
Sendmail is a Mail Transport Agent (MTA) that uses the Simple Mail Transport Protocol (SMTP)
to deliver electronic messages between other MTAs and to email clients or delivery agents. Although
many MTAs are capable of encrypting traffic between one another, most do not, so sending email over
any public networks is considered an inherently insecure form of communication.
For more in formation about how email works and an overview of common configuration
settings, see the chapter titled Email in the Official Red Hat Linux Reference Guide. This section
assumes a basic knowledge of how to generate a valid
/etc/mail/sendmail.cf
by editing the
/etc/mail/sendmail.mc
and running the
m4
command as explained in the Official Red Hat Linux
Reference Guide.
It is recommended that anyone planning to implement a Sendmail server address the following issues.
5.7.1. Limiting Denial of Service Attack
Because of the nature of email, a determined attacker can flood the server with mail fairly easily and
cause a denial of service. By setting limits to the following directives to
/etc/mail/sendmail.mc
the effectiveness of such attacks will be limited limited.
  confCONNECTION_RATE_THROTTLE
  The number of connections the server can receive per
second. By default, Sendmail does not limit the number of connections. If a limit is set and reached,
further connections are delayed.
  confMAX_DAEMON_CHILDREN
  The maximum number of child processes that can be spawned
by the server. By defaultt, Sendmail does not assign a limit to the number of child processes. If a
limit is set and reached, further connections are delayed.
  confMIN_FREE_BLOCKS
  The minimum number of free blacks which must be available for the
server to accept mail. The default is 100 blocks.
  confMAX_HEADERS_LENGTH
  The maximum acceptable size (in bytes) for a message header.
  confMAX_MESSAGE_SIZE
  The maximum acceptable size (in bytes) for any one message.
5.7.2. NFS and Sendmail
Never put the mail spool directory,
/var/spool/mail/
, on an NFS shared volume.
Because NFS does not maintain control over user and group IDs, two or more users can have the same
UID and therefore recieve and read each other's mail.






footer




 

 

 

 

 Home | About Us | Network | Services | Support | FAQ | Control Panel | Order Online | Sitemap | Contact

web hosting comparison

 

Our partners: PHP: Hypertext Preprocessor Best Web Hosting Java Web Hosting Inexpensive Web Hosting  Jsp Web Hosting

Cheapest Web Hosting Jsp Hosting Cheap Hosting

Visionwebhosting.net Business web hosting division of Web Design Plus. All rights reserved