Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Web Hosting Forum


You are currently viewing our Web Hosting Forum as a guest. Please register to participate.
Login



Closed Thread
Web Hosting Company - Secure it!
Old 05-18-2008, 07:22 PM Web Hosting Company - Secure it!
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,517
Name: Andrei
Location: Canada
Trades: 6
Well, as some of you may know, I recently opened up a thread asking about the security of a web hosting company, and an overall server. I decided to do a bit of research, and have actually run into a few useful tips. As I learn, I will be updating this thread, in hopes of sharing acquired knowledge.

Passwords
Make sure that you do not use the same password in any one of your scripts, servers, administrative areas, or even Support sessions. If the same password is used, the whole business could easily be hijacked, through the identification of only one password.

Email Support/ Conversations
Verify all clients, and ask them to identify themselves. Unless they do so, do not carry out any of their requests. This is to ensure that client accounts are not compromised.

If a client provides a false bit of information, make sure you email them back, and ask them to correct it. Also, you may need to ask for passwords or other bits of personal information. This is to ensure that the "hacker" does not run a simple whois scan on the domain, and use the information they get to identify themselves as the rightful owner of the account.

Firewall
Firewalls could be used to block incoming and outgoing attacks. When your server is compromised, which willl happen on most occasions, the hacker will upload iles in roder to set up a daemon or their own service. To prevent this, a firewall with both egress and ingress could be adapted.

Also, software firewalls could be used in order to diminish the pesky monthly fee addon. However, on a very busy server, where CPU and System memory is valuable, a hardware firewall could be adapted.

Backups
Everyone knows what it feels like to lose hours, or even hundreds of hours, of work. Do this for yourself, and more importantly, for your clients. It is up to you to backup client data. If a hacker does take control, who knows what they could do. A backup is always in place.

Home Directory
log into putty and go ahead and run the following commands
Code:
chmod 755 /home
Or
Code:
 
CD /
chmod 755 home
PHP
In many cases, PHP can be very risky. All php scripts should be tested for vulnrabilities, while the php installation itself should be used to block out common attacks.
Code:
 open off
safe_mode = On
safe_mode_gid = Off
open_basedir = directory 
safe_mode_exec_dir = directory 
expose_php = Off
register_globals = Off
display_errors =Off
log_errors = On
error_log = yourfile
enable_dl off
allow_url_open off
Apache
mod_security - a filter that can watch all requests to see if they match a rule and react by logging or denying the request.

suEXEC - http://httpd.apache.org/docs/1.3/suexec.html - This should explain it.

DDoS
mod_evasive is an evasive maneuvers module for Apache to provide evasive action in the event of an HTTP DoS or DDoS attack or brute force attack. It is also designed to be a detection and network management tool, and can be easily configured to talk to ipchains, firewalls, routers, and etcetera. mod_evasive presently reports abuses via email and syslog facilities.

Know your Server
Make sure that you know everything about your server, and that you are not left in the dark about anything. Checkout processes and familiarize yourself with them. This will ensure that you notice any silent processes installed by a potential hacker. Also, this may help you identify viruses, and potent resource consumers.

Familiarizing yourself with your server also allows you to recognize slower speeds, CPU usage, and an increase in Bandwdith usage, which could all be signs of a haccking attempt, DDoS, or a Brute Force.
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Last edited by andrei155; 05-18-2008 at 08:46 PM..
andrei155 is offline
View Public Profile Visit andrei155's homepage!
 
 
Register now for full access!
Old 05-18-2008, 07:50 PM Re: Web Hosting Company - Secure it!
Super Talker

Latest Blog Post:
Moon Cakes and Hosting
Posts: 131
Trades: 0
Another thing is for remote access, enable the firewall such that only your IP can access, have seen a lot of brute force attacks on SSH and Remote Desktop Protocol. Also best to change the ports of these two.
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
wisdomtool is offline
View Public Profile Visit wisdomtool's homepage!
 
Old 05-18-2008, 08:54 PM Re: Web Hosting Company - Secure it!
Banned

Posts: 143
Name: Blake
Location: Cuyahoga falls,Ohio
Trades: -2
Very Nice Article Andrei
blktallos is offline
View Public Profile Visit blktallos's homepage!
 
Old 05-19-2008, 09:41 AM Re: Web Hosting Company - Secure it!
Ultra Talker

Posts: 260
Name: Duncan
Trades: 0
Nice read, very useful, thanks a lot.
Jeyce is offline
View Public Profile
 
Old 05-19-2008, 08:22 PM Re: Web Hosting Company - Secure it!
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,517
Name: Andrei
Location: Canada
Trades: 6
Hey, no problem. As long as I learn more, I'll continue to update the thread. I'm sort of rewriting what little knowledge I acquire. It'll help me remember it better, and also help everyone else too .
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
View Public Profile Visit andrei155's homepage!
 
Old 05-19-2008, 11:26 PM Re: Web Hosting Company - Secure it!
Defies a Status

Posts: 2,071
Name: carl
Location: UK
Trades: 0
Thanks for sharing...interesting read.
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
bakerc is offline
View Public Profile Visit bakerc's homepage!
 
Old 05-20-2008, 08:56 AM Re: Web Hosting Company - Secure it!
~ServerPoint~'s Avatar
Defies a Status

Posts: 1,687
Name: Travis
Trades: 0
HM... You are quite good... Do you have a such hobby?
__________________
ServerPoint.com - a true hosting company since 1998
Web Hosting, colocation,
Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
~ServerPoint~ is offline
View Public Profile
 
Old 05-20-2008, 05:16 PM Re: Web Hosting Company - Secure it!
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,517
Name: Andrei
Location: Canada
Trades: 6
Quote:
Originally Posted by ~ServerPoint~ View Post
HM... You are quite good... Do you have a such hobby?
For security? I wouldn't say so, just trying to maintain my business in a safe manner. Although I have a few people running the security bit, I decided to take the initiative and find out what really goes on, just so i'm never left in the blue.
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
View Public Profile Visit andrei155's homepage!
 
Old 05-21-2008, 07:46 AM Re: Web Hosting Company - Secure it!
Average Talker

Posts: 20
Trades: 0
Very useful article. What about security for a windows box?
__________________
Find
Please login or register to view this content. Registration is FREE
here.
With this
Please login or register to view this content. Registration is FREE
you get a free domain name, hosting, e-commerce and more.
stfrancis is offline
View Public Profile
 
Old 05-22-2008, 05:11 PM Re: Web Hosting Company - Secure it!
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,517
Name: Andrei
Location: Canada
Trades: 6
I'll be adding that shortly.
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
View Public Profile Visit andrei155's homepage!
 
Old 05-23-2008, 02:42 AM Re: Web Hosting Company - Secure it!
Extreme Talker

Posts: 194
Trades: 0
Good read for hosts, looking forward to read your Windows article.
timbre is offline
View Public Profile
 
Old 05-23-2008, 04:32 AM Re: Web Hosting Company - Secure it!
~ServerPoint~'s Avatar
Defies a Status

Posts: 1,687
Name: Travis
Trades: 0
That is really good initiative. I think that you will be good expert soon...
__________________
ServerPoint.com - a true hosting company since 1998
Web Hosting, colocation,
Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
~ServerPoint~ is offline
View Public Profile
 
Old 05-24-2008, 11:47 PM Re: Web Hosting Company - Secure it!
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,517
Name: Andrei
Location: Canada
Trades: 6
thank you serverpoint. I'm hoping too .

Sorry I haven't had time to update this. This thread is more or less notes of what I read. I'm learning as you are!

BTW, thanks for the sticky! - I checked like 4 times, couldn't believe my eyes.

Thanks again
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Last edited by andrei155; 05-24-2008 at 11:49 PM..
andrei155 is offline
View Public Profile Visit andrei155's homepage!
 
Old 08-10-2008, 10:40 AM Re: Web Hosting Company - Secure it!
Junior Talker

Posts: 2
Trades: 0
Good article!
I would like to also recommend mod_ipconnlimit. With this apache mod you can limit the connection from the same IP. In many cases the mod_evasive not enough.
getforum.org is offline
View Public Profile
 
Old 08-13-2008, 05:39 AM Re: Web Hosting Company - Secure it!
damien_ls's Avatar
Layershift

Posts: 474
Name: Damien
Trades: 0
With regard to passwords you definitely need to consider the complexity of them - mixed case, special characters, length, frequency you change etc. A good option on linux boxes is to use SSH keys instead as they're more secure... although downside is obviously the key is stored on your machine so potentially as weak as your own PC security is.

A compromise in this issue is to setup an SSH gateway where you have a complex password (that you change frequently) used to login from your PC to the SSH gateway. From there you connect to the server in question using SSH keys.

What's the benefit? Well you can log actions by all users using the gateway for a start... good for audit purposes on a team etc. but also security is easier to manage for the gateway because it has one specific purpose: one reason your desktop is less secure is that you use it for a wide range of things, with various software installed - means a greater possible attack surface which may be vulnerable/exploited etc.

I wonder if you could kindly explain the details behind the "Home Directory" section? Sounds like something very specific to your own setup and therefore seems dangerous to recommend others simply run those commands - may not be appropriate for them. Please tell us the general principle behind the action

As for mod_security... depends... the idea is good but it can be unduely restrictive. As with most things security related, there is a trade-off between security and functionality/freedom of use.
__________________

Please login or register to view this content. Registration is FREE
:: DDS & Dedicated, UK & USA-based
Please login or register to view this content. Registration is FREE
, Reseller & Shared Hosting
Experienced Parallels Platinum Partners (Plesk since 2001, Virtuozzo since 2003)
damien_ls is offline
View Public Profile
 
Old 09-05-2008, 04:30 PM Re: Web Hosting Company - Secure it!
arudis's Avatar
Extreme Talker

Latest Blog Post:
Staff Positions Open
Posts: 198
Name: Henry
Location: Brooklyn
Trades: 0
Nice work andrei helps out alot
__________________

Please login or register to view this content. Registration is FREE
arudis is offline
View Public Profile Visit arudis's homepage!
 
Old 12-18-2008, 05:16 AM Re: Web Hosting Company - Secure it!
opensourcer's Avatar
Average Talker

Posts: 16
Trades: 0
You might also want to keep up to date with security patches for the OS and the applications you are running.

For ssh access, a few strategies could be (depending on your setup), use ssh key, disable root login, limit access by IP, change default port
opensourcer is offline
View Public Profile Visit opensourcer's homepage!
 
Old 12-21-2008, 09:58 PM Re: Web Hosting Company - Secure it!
Novice Talker

Posts: 5
Trades: 0
Thanks for sharing!
__________________

Please login or register to view this content. Registration is FREE
springsunny is offline
View Public Profile
 
Old 02-12-2009, 05:53 PM Re: Web Hosting Company - Secure it!
Average Talker

Posts: 22
Trades: 0
tnx for info
nackgr is offline
View Public Profile
 
Old 02-19-2009, 01:42 PM Re: Web Hosting Company - Secure it!
MarbleHost.com's Avatar
Experienced Talker

Posts: 42
Trades: 0
Safe mode on/off - it is an interesting question. For security reasons it is always better to set up the safe mode off. But many free PHP scripts which clients download from sites like Host Scripts require safe mode on. And clients want to run these scripts
__________________

Please login or register to view this content. Registration is FREE

Reliable
Please login or register to view this content. Registration is FREE
provided since 2005

Please login or register to view this content. Registration is FREE
- build your website right now
MarbleHost.com is offline
View Public Profile Visit MarbleHost.com's homepage!
 
Closed Thread     « Reply to Web Hosting Company - Secure it!

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.67476 seconds with 11 queries