One way to close software holes (Abyss web server) is to
Sunday, December 9th, 2007One way to close software holes is to remove all programs you don t need. You can always add them later, if necessary. How exactly you do this taskdepends on the package-management scheme your distribution runs: Fedora:You can use yum at the command line or gyum s Remove tab(see Chapter 12). Knoppix:You run it off CD, so it s hard to remove anything! Linspire:Open the CLICK and Run client (Chapter 12), click the MyProducts tab, select the program you want to remove from the list, andthen click Uninstall Selected. Mandrake:From the main menu, choose System.Configuration. Packaging.Remove Software. In the dialog box, check the boxes for theprograms you want to remove. When you re ready to proceed, clickRemove. SuSE:Choose System.YaST.Software.Install And Remove Software. Locate the program you want to remove (see Chapter 12). Installed soft- ware has a checkmark next to it. Click the mark until it becomes a trashcan and then click Accept. Xandros:Open the Xandros Networks client as discussed in Chapter 12. Choose Installed Applications, browse to the program you want toremove, and click the Remove link. If it turns out that, as a result of dependencies, you lose other software thatyou want to keep, make sure to cancel the removal. Introducing SELinuxSELinux, or Security-Enhanced Linux (www.nsa.gov/selinux/index.cfm) was developed by the National Security Agency (NSA) in the United States toadd a new level of security on top of what s already available in Linux. To useSELinux in your distribution: Fedora:Open the firewall control tool (see the section Controlling andadjusting your firewall, earlier in this chapter) and click the SELinuxtab. If you want to just see what SELinux woulddo, check the Enabledcheck box (if it isn t already checked). If you want to enforce the policiesyou ve created, check the Enforcing Current check box. To completelydeactivate it (which will probably speed up your boot time), make surethat both boxes are unchecked. My best advice for playing with thisadvanced feature is to go and read the site mentioned at the beginningof this section and then the Fedora-specific FAQ at http://people.redhat.com/kwade/fedora-docs/selinux-faq-en/. Knoppix:Not available. 274Part III:Getting Up to Speed with Linux