con que cuentan los Servidores dedicados y vps ?

Posted on Mayo 31, 2008
Filed Under serverdopolis |

Preliminary Security configuration

Secure /tmp (noexec, nosuid, nodev )
mod_security
phpSueXec
Secured /root/.my.cnf
Remove the /dev/shm entry from the fstab
Unmount /dev/shm set permissions to 755
Block all outgoing connections to port 22 using iptables
Latest Secure Stable kernel
APF firewall basic install
C and C++ compilers are disabled. Many canned exploits require a working c on the system
Linux Environment Security:
Root-only permissions on binaries, path traversal, immutable bit on rpm, shell scripts
Linux Socket Monitor
designed to track changes to Network sockets and Unix domain sockets

Pre-compiled Apache / Php settings

Imagemagick
GD
GD2
Zend
Curl w/SSL
MySQL 4.xx
php 4.xx

Initial setup

Hostname configuration
DNS ns1/ns2 setup
Incremental backups daily, weekly, monthly (servers with dual drives)
Secure root password set
Awstats, Webstats configured
ntsysv configured

Comments

Leave a Reply