Hey,
I was just wondering how people secured their Linux webservers? Typically what I'd do is:
- Change SSH port to something obscure
- Install some sort of firewall and only allow public services through
- Turn off server signatures on Apache/Lighttpd
- Install RKHunter/Chkrootkit
- Setup e-mail on SSH login
- Keep the OS and services up to date
- Install suPHP
- Install mod_security
- Disable rare/dangerous PHP functions
- Secure /tmp with noexec & nosuid
Anymore people would recommend?







Reply With Quote


