论文部分内容阅读
eWEEK实验室用两台Linux服务器主机——Apache 1.3.12和Bind 8.2.2 patch level 5分别供应外部Web和域名系统服务器。我们非常关注这些服务器的安全问题,因为它们是可以被外部接触到的。我们审查了用户账号和密码口令、正在运行的程序、文件许可证、操作系统完整性、程序管理访问权、系统纪录以及安装的软件等。发现,即便以用户身份(Alexander Lazic和Lluis Mora攻击MiniVend前端应用软件时获得的账号)访问运行在Linux系统上的Akopia公司的MiniVend应用,黑客也不能得到根目
eWEEK Labs uses two Linux server hosts, Apache 1.3.12 and Bind 8.2.2 patch level 5, to supply external Web and Domain Name System servers, respectively. We are very concerned about the security of these servers, because they are externally accessible. We reviewed user account and password passwords, running programs, file licenses, operating system integrity, program management access, system logging, and installed software. Found that even if Akopia’s MiniVend application running on Linux was accessed as a user (an account obtained when Alexander Lazic and Lluis Mora attacked the MiniVend front-end application), hackers could not get the root