[comp.unix.admin] novice sys admin: security?

link@stew.ssl.berkeley.edu (Richard Link) (04/25/91)

Hi,

I'm a computational physicist who has been sheltered from delving too
deeply into UNIX by resident (and much appreciated) gurus at Berkeley.

I came from a VAX/VMS environment, and learned enough UNIX to develop
and run FORTRAN programs (but not use make files or SCSS), and have
a working relationship with vi and troff. That's about it.
No C (or any) shell or C, even now. Grep, sometimes. Awk, never.

All of a sudden, I'm thrust back into a VMS environment, having long
since forgotten (and several versions later) the VMS operating system.
And, much to the wails of laughter from the said Berkeley gurus,
I've even come to like UNIX.

Now I find myself a UNIX Trojan Horse in a VMS shop. Just me and my
SparcStation IPC (207+670 Meg HD's, 36 Meg RAM, floppy + tape drives)
sitting on my desk.

I am root. Now what?

The day after I got the IPC, I:
- installed Sun FORTRAN 1.3.1
- installed Sun DosWindows (MS-DOS emulator)
- installed ArborText Tex
- installed IDL
- installed device drivers
- configured the IPC as a node on our local TCP/IP net
- got TCP/IP mail working between the IPC and the VMS and MS-DOS systems
- created user accounts

* they all work!

The following week, we bought a new HP LaserJet III printer, and I:
- set up the IPC as a TCP/IP network printer server
  (the only printer that prints Wordperfect extended character sets)
  (two other accessible printers on the net with different hosts)

* this works too!

To finally get to the point:
We are in the process of getting an Internet connection.
What do I need to know about security, and where do I find out about it?

Any advice or pointers will be appreciated.
No companies or other commercial solicitations please!

-------------------------------------------------------------------------
Richard Link, Senior Physicist
Computational Physics, Inc.
P.O. Box 788
Annandale, VA 22003