| |
The following is a list
of software and modifications that will be
installed
to secure, optimize and harden your server security.
The
following software is not resource intensive,
therefore you should not see any noticeable decrease
in performance.
We will install CHKRootKit, which
is a program that looks for known signatures in
trojaned system
binaries, it basically detects if your system will be compomised.
We will install Rootkit Hunter, which
is a scanning tool to find most types of exploits
(backdoors,
suspicious files, md5 hash comparisons, and is
over 99% accurate in detecting such exploits. We
will scan your system with the Rootkit Hunter to
make sure thatthat your system is clean.
APF Firewall will be installed and configured
to only allow traffic on the ports that are used.
In addition, we will configure the Anti-DOS
function in APF. This additional module helps mitigate
and prevent certain types of DOS (denial of service)
attacks to your server. A daily cron will be inserted
to flush the firewall deny list. This prevents
common problems associated with the deny list growing
so huge, such as hanging upon bootup, slow down
in server performance, etc.
BFD (Brute Force Detection) will be installed.
This program works real time in conjunction with
APF firewall to block any IP Addresses of users
that fail authentication more than 3 times in 10
minutes.
Logwatch will be installed. This program parses
through your server’s logs and reports to
you via e-mail on a daily basis with tabulated
information.
SIM (System Integrity Monitor) will
be installed. This software checks all services
24*7 and restarts them if they are down. An e-mail
is dispatched if a downed service is detected and
restarted.
Apache (HTTPD) web server will be optimized and
secured.
MySQL Server will be optimized to perform at it’s
best under the most common and standard environments.
System Configuration File host.conf will
be secured and hardened to prevent DNS lookup poisoning and
also provide protection against spoofs.
System Configuration File nsswitch.conf
will be secured and hardened. We have also optimized it
to perform DNS lookups more efficiently.
System Configuration File sysctl.conf will
be secured and hardened to help prevent the TCP/IP
stack from syn-flood attacks. It will also configured
to prevet various other network abuses.
All of your vulnerable directories (/tmp,
/var/tmp, /dev/shm and /usr/local/apache/proxy)
will be
reviewed and cleaned.
/tmp and /var/tmp will be hardened and secured
to prevent the execution of malicious scripts.
The old archived logs files that will be rotated
located in /var/log will be removed to free up
space in the /var partition/directory.
MyTOP will be installed. This is an administrative
console based tool for monitoring MySQL threads/processes
and performance.
We will setup a root login notification
script and logger. This will send an e-mail to ‘root’ everytime
someone logs into your server as root. Also, it
will keep track of all logins in a history file
located in /var/log/rootlogins
SPRI will be installed. This program changes
the priority of different processes in accordance
to their level of importance. You should see at
least a 5-20% decrease in the average load level
of your server on average.
We will disable the Mchat, Cgiecho, Cgiemail,
Guestbook, Counter and Formmails from CPanel’s
system wide cgi-sys directory. The are
the most commonly exploited scripts since they
are in the
same location on every CPanel server in the world.
If any of your users are using any of those programs,
they will no longer work. If you want us to re-enable
them, just let us know.
Unused programs will be disabled from the
OS of your server. This reduces the chance of being
compromised through software exploits on old or
deprecated programs.
MultiTail will be installed and gives you
the ability to tail (view realtime activity) multiple
log files simultaneously.
PHPSysInfo will be installed. This
is a GUI (graphical user interface) to your server’s
vital statistics. You can view it by going to http://0.0.0.0:2086/phpsysinfo-dev/index.php
Replace 0.0.0.0 with your own server’s IP
Address. You will have to enter your root login
information to gain access as it is protected under
your root WHM login.
Telnet will be disabled to prevent insecure
transmissions of data and passwords, SSH must be used instead
of Telnet, and functions the same way.
SSH will be hardened by restricting the SSH Protocol
to SSH 2. SSH will function the same way, just
more secure.
Fileman (Filemanager developed by gossamer-threads.com) will
be installed into WHM with root level permissions.
This allows system root files to be edited in an
emergency situation when SSH is not accessible.
You can access Fileman by going to http://0.0.0.0:2086/fileman/fileman.cgi.
Replace 0.0.0.0 with your own server’s IP
Address. You will have to enter your root login
information to gain access as it is protected under
your root WHM login. This simulates SSH access,
treat it as such, do not use it unless you are
familiar with SSH. Moreover,
do not execute any commands you are not fluent
with. As with SSH, damage can be done if Fileman
is not used properly. If you are unfamiliar with
SSH, do NOT use this program. It should be left
in case of such an emergency.
Shell Fork Bomb/Memory Hog Protection will
be enabled. Fork Bomb/Memory Hog protection will prevent
users logged into a shell (ssh/telnet) from using
up all the resources on the server and causing
a crash.
Background Process Killer will be enabled to kill
any of the following which are commonly recognized
bad processes: BitchX, bnc, eggdrop, generic-sniffers,
guardservices, ircd, psyBNC, ptlink and related
services.
A warning message will be created for the
SSH login welcome screen. Any user that logs into your
server via SSH, will see a message stating SSH
is for authorized users only, and any unauthorized
access will be reported to the law enforcement
authorities.
Your FTP server software will be upgraded and
secured.
We will run a simulated basic password
scan hack attempt, the results will be emailed
to ‘root’ and a copy of the results
will be saved on your server at /root/security/passwordscanner.output
* IMPORTANT * PLEASE READ * IMPORTANT *
Can we guarantee your system will now be hacker
proof?
No, nobody can! It is near impossible to make a
server 100% hacker proof. Our security
hardening procedures will make your system hacker resistant and more secure and
efficient. If you would like any other security
software installed not listed here or if you have
questions please email dataword@comcast.net.
Security
Hardening only $27.95
Server Management & Security
only $49.95 per month
|