Reply
Really Optimizing my server
Old 06-30-2006, 11:11 PM Really Optimizing my server
sitedesigner's Avatar
Junior Talker

Posts: 1
Trades: 0
So I am relatively familiar with web servers, but I wanted to know something.

What are all of the optimizations that I should ask my server administrator to do, in order to really make it very well secured?

Thanks
sitedesigner is offline
Reply With Quote
View Public Profile
 
 
When You Register, These Ads Go Away!
Old 07-01-2006, 09:55 AM
Skilled Talker

Latest Blog Post:
My Daily Schedule - I Am Back.
Posts: 79
Trades: 1
Make sure you set a root mySQL password.

Also, to prevent DOS attacks:

- Install APF firewall.
- Install BFD (Brute Force detection).

Very easy to install within minutes and will shield your server against DOS attacks.
__________________
Reliable Web Hosting$1 Lifetime Textlinks
Gareth is offline
Reply With Quote
View Public Profile Visit Gareth's homepage!
 
Old 07-01-2006, 01:44 PM
Loves Learning!

Posts: 437
Trades: 0
Quote:
Originally Posted by Gareth View Post
Make sure you set a root mySQL password.

Also, to prevent DOS attacks:

- Install APF firewall.
- Install BFD (Brute Force detection).

Very easy to install within minutes and will shield your server against DOS attacks.
Can you link few of the recommended one's?
Muhammad Haris is offline
Reply With Quote
View Public Profile Visit Muhammad Haris's homepage!
 
Old 07-01-2006, 02:03 PM
sitedesigner's Avatar
Junior Talker

Posts: 1
Trades: 0
Thank you Gareth. A couple links would really help
sitedesigner is offline
Reply With Quote
View Public Profile
 
Old 07-01-2006, 02:37 PM
sitedesigner's Avatar
Junior Talker

Posts: 1
Trades: 0
Oh! Thank you so very much. maybe some others could get some more good ideas up on here. Who wouldn't want to have the BEST server uptime anywhere?

:-D
sitedesigner is offline
Reply With Quote
View Public Profile
 
Old 07-01-2006, 06:29 PM
$100 - $999 Monthly

Posts: 36
Trades: 1
The only website that I have really used is:

www.eth0.us

..and some other one that I can't remember :\
imported_punkstar is offline
Reply With Quote
View Public Profile
 
Old 07-04-2006, 06:37 PM
$1,000 - $4,999 Monthly

Posts: 96
Trades: 0
Few things you can do:

Scan for rootkits and kernel-level rootkits, trojan, hiden ports, /dev directory, system, binaries, files permission and ifconfig/ifs.
Scan for superuser accounts and accounts with no password
Compile PHP to the Latest version
Compiler / Fetch app. limiting. (limits access to compilers)
Host.conf & Sysctl Hardening (spoof protection and basic ddos protection)
Installation and Configuration of APF - (Advanced Policy Firewall) (restricts access to unneeded ports)
Install BFD - (Brute Force Detection)
Install Mod_Security with massive custom rules
Installation of Security Updates by OS/Control panel Vendor
LibSafe Installation (software level attack buffer. Prevents buffer overflow attacks)
Noexec, Nosuid Temporary Directories (noexec directories such as /tmp, /var/tmp, /dev/shm)
Php Open_Basedir Tweak
Remove Unnecessary Software
Secure Kernel Default
Secure Ports
Secure Services
Secure Root Login
Secure Sshd Port
Secure DNS
Secure Ftp Server
Update Kernel & Limit Kernel Capabilities
Update Installed Softwares
Update Cpanel to the Latest Stable Version (For CPanel)
ClamAV + ExiScan Installation (email virus/spam scanning)
Install Exim Dictionary Attack
Install Forge Helo To Protect From Using The Server For Spamming
Installation and Configuration of Razor and SARE To Integrate with SpamAssassin
RBL/DNSBL Thru Exim with RBL Whitelist, Blocklist & Bypass integrated with abuseat.org, spamcop.net, spamhaus.org, ordb.org and njabl.org to protect against spamming
CHkrootkit notification (checks for possible rootkits on the server.)
Installation and Configuration of Tripwire
Install SIM ( restarts downed services & delete logs in /var/log automatically )
Install PRM ( Process Resource Monitor ) to monitor processes and kill overloading in the server
Install SPRI ( System Priority ) to control server load
Install EAccelerator
Install ZendOptimizer
Install MRTG (optional)
Install Cacti (optional)
Install Root Login Notification
Install MyTOP
Optimize Apache
Optimize MySQL
Optimize PHP
Logwatch Installation and Configuration (Sends a detailed daily report of server events based on logs)


More or less cut and paste from one of the server hardening companies I've used in the past.
Payton is offline
Reply With Quote
View Public Profile
 
Old 07-04-2006, 06:42 PM
Junior Talker

Posts: 70
Trades: 1
Quote:
Originally Posted by Payton View Post
Few things you can do:

Scan for rootkits and kernel-level rootkits, trojan, hiden ports, /dev directory, system, binaries, files permission and ifconfig/ifs.
Scan for superuser accounts and accounts with no password
Compile PHP to the Latest version
Compiler / Fetch app. limiting. (limits access to compilers)
Host.conf & Sysctl Hardening (spoof protection and basic ddos protection)
Installation and Configuration of APF - (Advanced Policy Firewall) (restricts access to unneeded ports)
Install BFD - (Brute Force Detection)
Install Mod_Security with massive custom rules
Installation of Security Updates by OS/Control panel Vendor
LibSafe Installation (software level attack buffer. Prevents buffer overflow attacks)
Noexec, Nosuid Temporary Directories (noexec directories such as /tmp, /var/tmp, /dev/shm)
Php Open_Basedir Tweak
Remove Unnecessary Software
Secure Kernel Default
Secure Ports
Secure Services
Secure Root Login
Secure Sshd Port
Secure DNS
Secure Ftp Server
Update Kernel & Limit Kernel Capabilities
Update Installed Softwares
Update Cpanel to the Latest Stable Version (For CPanel)
ClamAV + ExiScan Installation (email virus/spam scanning)
Install Exim Dictionary Attack
Install Forge Helo To Protect From Using The Server For Spamming
Installation and Configuration of Razor and SARE To Integrate with SpamAssassin
RBL/DNSBL Thru Exim with RBL Whitelist, Blocklist & Bypass integrated with abuseat.org, spamcop.net, spamhaus.org, ordb.org and njabl.org to protect against spamming
CHkrootkit notification (checks for possible rootkits on the server.)
Installation and Configuration of Tripwire
Install SIM ( restarts downed services & delete logs in /var/log automatically )
Install PRM ( Process Resource Monitor ) to monitor processes and kill overloading in the server
Install SPRI ( System Priority ) to control server load
Install EAccelerator
Install ZendOptimizer
Install MRTG (optional)
Install Cacti (optional)
Install Root Login Notification
Install MyTOP
Optimize Apache
Optimize MySQL
Optimize PHP
Logwatch Installation and Configuration (Sends a detailed daily report of server events based on logs)


More or less cut and paste from one of the server hardening companies I've used in the past.
Great list i do or have done alot of these on my own production box .. as i run 2 linux boxes at my office.. great list
__________________
|- AdminRevo - Admin Assist Forum
|- ListMeHere - Free Link Directory
|- TNI - Techology Forum
LeNNY is offline
Reply With Quote
View Public Profile
 
Old 07-06-2006, 09:25 AM
Zachery's Avatar
$1,000 - $4,999 Monthly

Posts: 30
Trades: 0
Securing and optmizing a server are two unrelated things at times. Hardening the server is one good thing, but if you overharden you can lose some preformance benifits.
Zachery is offline
Reply With Quote
View Public Profile
 
Old 07-07-2006, 03:27 PM
$100 - $999 Monthly

Posts: 284
Trades: 1
I found that out when I installed Mod_Security. It was causing me all sorts of problems on a few of my dynamic sites. I finally gave up and turned it off.
__________________
Atomm
Gamers Radio: New and Improved Ad Blending!
Advertisepedia Internet Marketing Blog
Atomm is offline
Reply With Quote
View Public Profile Visit Atomm's homepage!
 
Reply     « Reply to Really Optimizing my server
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML

 



Page generated in 0.15946 seconds with 13 queries