Locking down a linux box

Where is a good place to find a kind of check list for locking down vulnerabilities on a linux box. Things like version 1.2 of foo has a problem upgrade to 1.21. Also a good list of ports to block.

Thanks,
Jeff

 

 

 

 

Top