Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-24, 12:46:09

Author Topic: Suggestions for securing vps welcome  (Read 3515 times)

0 Members and 1 Guest are viewing this topic.

Offline befree22

  • Valuable Member
  • *
  • Posts: 95
  • Karma: +0/-1
    • View Profile
Suggestions for securing vps welcome
« on: 2014-03-12, 04:40:29 »
I have a Centos 6 vps with Nginx and Kloxo-MR installed.

I'm doing lots of research to harden my vps from hacker attacks and ddos attacks.

Right now, I have CSF Firewall installed and I'll install rkhunter. Since chkrootkit is similar to rkhunter, I want only rkhunter installed.   

Still, since I've experienced malicious hacker attacks, I'm diligently looking to find the best solutions to prevent another attack.

FYI: The malicious hacker used Wordpress vulnerabilities documented on this forum so I installed Bruteprotect Wordfence and BWS.

For hardening the vps, I've been reading about https://www.rfxn.com/projects/brute-force-detection/ and OSSEC and OpenVAS. OSSEC is a detection tool and OpenVAS is a vulnerability management tool. I'm leaning toward BFD.

I want to avoid installing redundant security tools and too many tools that may overwhelm the vps or cause incompatibility with Nginx and Kloxo-MR which did occur. 

Please share your suggestions on how you secure your vps and what you think about the above security tools.
« Last Edit: 2014-03-12, 04:50:36 by befree22 »

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: Suggestions for securing vps welcome
« Reply #1 on: 2014-03-12, 04:51:42 »
KloxoMR,  default port changed.  All passwords strong (meaning at least 10 chars, upper lowercase, atleasr one number and one symbol) CSF firewall.  Spamdyke 5.0 and recipient reject.

No other tools neccessary.  CSF is a very good firewall, and will do many things, go through the etc/csf/csf.conf and read all about settings.

ALWAYS use encrypted connections to your server.  Never use FTP.  Use sftp, or ftps.  Never get mail without tls/ssl.  Always use port 7777 (or what you have it configured to) ssl on KloxoMR panel.

« Last Edit: 2014-03-12, 04:54:26 by chrisf »
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline amudy17

  • Senior Member
  • *
  • Posts: 246
  • Karma: +0/-1
    • View Profile
    • Alamudy
Free, Fast and Secure CP => Kloxo-MR
Daily News Update => Click here to see website!

Offline komvis

  • Newbie
  • Posts: 36
  • Karma: +0/-0
    • View Profile
Re: Suggestions for securing vps welcome
« Reply #3 on: 2014-03-12, 07:15:57 »
yeah..good tutorial by chrisf..

Offline befree22

  • Valuable Member
  • *
  • Posts: 95
  • Karma: +0/-1
    • View Profile
Re: Suggestions for securing vps welcome
« Reply #4 on: 2014-03-12, 14:40:31 »
KloxoMR,  default port changed.  All passwords strong (meaning at least 10 chars, upper lowercase, atleasr one number and one symbol) CSF firewall.  Spamdyke 5.0 and recipient reject.

No other tools neccessary.  CSF is a very good firewall, and will do many things, go through the etc/csf/csf.conf and read all about settings.

ALWAYS use encrypted connections to your server.  Never use FTP.  Use sftp, or ftps.  Never get mail without tls/ssl.  Always use port 7777 (or what you have it configured to) ssl on KloxoMR panel.



Port 7777 used on Kloxo-MR panel. I do use strong passwords from http://strongpasswordgenerator.com/.
CSF Firewall installed per Chris's forum post instructions.

I will research Spamdyke 5.0 and recipient reject. I'll also research  sftp, or ftps and setup mail with tls/ssl. If you have any instructions or good Youtube videos on this, please post here.


Offline befree22

  • Valuable Member
  • *
  • Posts: 95
  • Karma: +0/-1
    • View Profile
Re: Suggestions for securing vps welcome
« Reply #5 on: 2014-03-15, 00:06:06 »
1. Spamdyke 5.0. OK, I have Spamdyke enabled in Kloxo-MR > admin > Server Mail Settings. See attached settings.
I reinstalled Kloxo-MR on March 3rd. How do I know if I have Spamdyke 5.0 installed?

2. Reject recipient. I'm reading http://www.spamdyke.org/documentation/README.html#REJECTING_RECIPIENTS and it supports recipient reject. Is there a way to activate reject recipient in Kloxo-MR admin > Spamdyke or do I need to make changes to qmail files referenced in the above link?

3. Are there instructions to setup mail with tls/ssl for Kloxo-MR?

FYI: I watched a video about sftp or ftps and will apply this secure connection soon.

 


Top 4 Global Search Engines:    Google    Bing    Baidu    Yahoo
Click Here

Page created in 0.063 seconds with 22 queries.

web stats analysis