The Bastille Hardening program "locks down" an operating system, proactively configuring the system for increased security and decreasing its susceptibility to compromise.
lockdown-ubuntu.sh - a simple script to secure Ubuntu a bit more than the default installation. This should work with Ubuntu 6.06 (Dapper) and 6.10 (Edgy)
Do you have a 'broken' web application that let's hackers upload files to /tmp and execute them? Here is how to prevent programs uploaded to /tmp from running.