Loading...
Flash Player 9 (or above) is needed to view slideshows. We have detected that you do not have it on your computer.To install it, go here
GNU/Linux, Server Web, dan Keamanan
Presented in Seminar Web {H,C}racking
Universitas Atma Jaya Yogyakarta
14 April 2007
333 views | comments | 0 favorites | 0 downloads | 0 embeds (Stats)
More Info
This slideshow is Public
Total Views: 333 on Slideshare: 333 from embeds: 0
Slideshow Transcript
- Slide 1: GNU/Linux, Server Web, dan
Keamanan
Seminar Web {H,C}racking
Sabtu, 14 April 2007
Universitas Atma Jaya Yogyakarta
- Slide 2: Name : Iwan Setiawan
Nick : stwn
Age : 22 < age < 32
Status: single
E-mail: stwn@duniasemu.org
- Slide 3: Linux, GNU/Linux dan PLBOS*
* Perangkat Lunak Bebas dan Open Source
- Slide 5: to explain what Linux is, you have to
explain what an operating system is
...
think about an operating system is that you
have never ever supposed to see it, nobody
really use operating system. people use
programs.
(Linus Torvalds, RevolutionOS film)
- Slide 6: Linux adalah sebuah kernel
kernel = sistem operasi
Hasil proyek hobi seorang mahasiswa
Linus Torvalds
Finlandia, 1991
GNU GPL
- Slide 8: Hirarki Pengembang Kernel Linux
- Slide 10: Linux di Perangkat Jaringan
file:///home/kuliax/web/New%20Folder/AT2005548492_files/mercury_ensemble2-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/newisys-na1400-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/infrant_readyNAS-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/infrant_readynas_1100-nv-plus-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/fingergear_bio_cos_blue-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/dlink_dsl-g604t-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/sputnik_case-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/cyberguard_sg300.gif
file:///home/kuliax/web/New%20Folder/AT2005548492_files/thing_magic_m4_rfid_reader-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/cspi_fastcluster_200p-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/ssv_igw-100-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/ecutel_nxgx00-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/sofaware-safeoffice-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2005548492_files/coraid_1U_sata_raid_etherdrive_angle-thm.jpg
- Slide 11: Linux di Ponsel
- Slide 12: Linux di Robot
- Slide 13: Linux di ...
file:///home/kuliax/web/New%20Folder/AT2478437967_files/st_jude_medical_merlin_system-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/tomtom_go-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/volvo_ITS4mobility-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/ibmwatch-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/netpos-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/netcam-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/orion_multisystems_ds-96-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/ibm-watchpad-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/intrinsyc_parking_station-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/super8-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/umts-testcar-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/quorum_mainunit-thm.jpg
file:///home/kuliax/web/New%20Folder/AT2478437967_files/personal-server-thm.gif
file:///home/kuliax/web/New%20Folder/AT2478437967_files/naviflash_dashboard-thm.jpg
- Slide 14: Penggunaan Linux
✔ Server
✔ Desktop PC
✔ Network and Wireless Devices
✔ Jam
✔ Ponsel
✔ Super Computer
✔ Robot
✔ Perangkat Berkendaraan
✔ ...
- Slide 15: GNU/Linux?
GNU Project's Programs+
Kernel Linux
- Slide 16: Proyek GNU
Didirikan oleh Richard M Stallman, 1984
Gerakan Free Software atau Perangkat Lunak Bebas
Sistem operasi lengkap bergaya UNIX yang bebas
bagi masyarakat
free speech, not free drink
- Slide 17: Empat (4) kebebasan
0. untuk menjalankan program untuk tujuan apapun
1. kebebasan untuk mempelajari bagaimana program bekerja
dan mengadaptasikannya sesuai dengan kebutuhan
2. kebebasan untuk mendistribusikan kembali agar kita
bisa membantu tetangga, teman, dan orang lain
3. kebebasan untuk memperbaiki atau meningkatkan program
dan merilisnya ke publik. komunitas mendapatkan
manfaat/imbal balik
- Slide 18: FSF: GPL, LGPL, FDL
Free Software Foundation (FSF), General Public License (GPL),
Lesser General Public License (LGPL), Free Documentation License (FDL)
- Slide 19: Open Source
cara atau metode pengembangan perangkat lunak
dengan kebebasan membaca, mendistribusikan, dan
memodifikasi kode sumber
- Slide 20: Open Source Initiative (OSI)
Uji Kelayakan:
IBM Public License, New BSD License,
Mozilla Public License, Python License,
...
Mengacu pada:
The Open Source Definition
- Slide 21: Unix/Linux Design
Berawal dari lingkungan server
dan jaringan
Standar POSIX
Relatif aman
Relatif stabil
Relatif handal/reliable
Manageable
- Slide 22: Perkembangan Unix/Linux
Dari lingkungan server dan jaringan sampai
sekarang ke lingkungan desktop dan
perangkat di sekitar kita
Mewarisi semua kemampuan dan fitur dari
“pendahulunya”
- Slide 23: Linux di lingkungan
jaringan
“Internet is Unix”
Servers: mail, DNS, ftp, router, proxy,
firewall, application, ...
Statistik menunjukkan semakin banyak
perusahaan yang menggantikan server
Windows dengan server Linux
HP, IBM, Oracle mendukung Linux pada produk
perangkat keras dan lunak
- Slide 24: Server Web
- Slide 25: Salah satu proyek Apache Software Foundation
(apache.org)
Cukup tahan banting, kelas enterprise, extensible
Digunakan kurang lebih 58,62% server di dunia
berdasarkan survei Netcraft (netcraft.com) April 2007
Mendukung modul dan fitur yang cukup banyak
Dikembangkan oleh banyak orang di dunia
License: Apache License 2.0 (Open Source Certified)
Mendukung varian Unix termasuk Linux, tersedia untuk
platform Windows
- Slide 27: lighttpd
✔ Ringan
✔ Mendukung PHP
✔ Dukungan mod* relatif kurang
dibandingkan apache http
server
✔ Survei netcraft: 1,27%
✔ Versi terakhir 1.5.0r1691
✔ Lisensi: BSD
- Slide 28: Web Server lain?
- Slide 29: Yankee Group/Sunbelt
2006 Server Reliability
Survey Results
All of the major server operating system
platforms have achieved a high degree of
reliability, though Unixbased servers still
record the least amount of annual downtime.
- Slide 30: Linux vs.Windows:
Total Cost of Ownership (TCO) Survey
(Yankee Group)
The survey emphasized that businesses continue to
expand the ways in which they utilize Linux. Over
50% of corporations now utilize Linux for a variety
of functions including: Web server, Email server
and specialized application server.
Perhaps the most startling survey revelation was
the fact that over 50% of the respondents said they
had performed a thorough TCO analysis. But when
asked to calculate their specific Linux and Windows
capital expenditure and maintenance costs, 75% on
average, could not answer explicit questions.
- Slide 31: Security Issues Survey
Software Security Summit Conference
(La Jolla, California, BZ Research polled 6,344 software
development managers)
Lingkup Server:
Some 58% rated Windows Server very insecure or insecure versus
13% for Linux. Sun Solaris fared best, with only 6% rating the
operating system very insecure or insecure.
On the positive side, some 74% of respondents rated Linux
secure or very secure versus only 38% for Windows Server. Sun
Solaris was rated secure or very secure by 66%.
Lingkup Aplikasi:
Asked about the security of operating systems against
applicationrelated hacks and exploits, Windows Server was
again rated least secure. Some 58% of respondents rated Windows
Server as very insecure or insecure versus 18% for Linux. On
the other hand, Linux was deemed secure or very secure by 66%
of respondents versus only 30% for Windows Server.
- Slide 32: Perbandingan Keamanan
Open Source vs Proprietary
Perbandingan keamanan open source dan proprietary pada delapan
kategori:
open source was the clear winner in four of the categories:
desktop/ client operating systems (44% to 17%); Web servers
(43% to 14%); server operating systems (38% to 22%); and
components and libraries (34% to 18%).
- Slide 33: file:///home/kuliax/web/security_lrg.jpg
- Slide 34: Hacker dan Cracker
- Slide 35: Hacker
...most having to do with technical adeptness
and a delight in solving problems
and overcoming limits.
Eric Steven Raymond (ESR) dalam “How To Become A Hacker”
- Slide 36: Hacking
Software, Hardware,...
- Slide 37: Cracker
These are people (mainly adolescent males)
who get a kick out of breaking into
computers and phreaking the phone system.
Eric Steven Raymond (ESR) dalam “How To Become A Hacker”
One who breaks security on a system.
From Jargon File
- Slide 38: Cracking
Software: Serial Number, Trial,
Customizing , ...
Sistem: Vulnerability scanning,
penetration, Denial of Service (DoS)
Attack, ...
- Slide 39: Hacker vs Cracker
The basic difference is this: hackers build
things, crackers break them.
ESR dalam “How to Become A Hacker”
- Slide 40: Serangan Tercatat
Digital Attacks: 2213541
Attacks On Hold: 1948
(zoneh.org)