Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Website and Server Administration Forum


You are currently viewing our Website and Server Administration Forum as a guest. Please register to participate.
Login



Reply
Old 05-08-2008, 09:08 PM Security
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,514
Name: Andrei
Location: Canada
Trades: 6
Out of curiosity, and my own benefit, I would really like to know what all the server admins are doing to protect their servers from outside attacks and possible threats.

In other words, what are you guys doing to protect your servers.

I feel a growing paranoia, that as long as I continue to grow(my compnay) more and more enemies will arise, whom are out to get me, and bring us into the ground. I don't know if this is a shared paranoia.
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
Reply With Quote
View Public Profile Visit andrei155's homepage!
 
 
Register now for full access!
Old 05-08-2008, 10:21 PM Re: Security
tamar's Avatar
Webmaster Talker

Posts: 507
Name: Tamar Weinberg
Location: New York
Trades: 0
Typically, I've used:

1. mod_security
2. mod_evasive
3. SSHblack
4. PortSentry
__________________

Please login or register to view this content. Registration is FREE
tamar is offline
Reply With Quote
View Public Profile Visit tamar's homepage!
 
Old 05-08-2008, 10:32 PM Re: Security
Junior Talker

Posts: 4
Trades: 0
ensure that any externally accessible applications on your servers are free of known exploits, subscribe to the app's news feed (to watch for security updates), and make sure they're patched regularily.
papastreets is offline
Reply With Quote
View Public Profile
 
Old 05-11-2008, 09:31 AM Re: Security
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,514
Name: Andrei
Location: Canada
Trades: 6
What doe portSentry do. I haven't come across that yet.

I can guess *-)
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
Reply With Quote
View Public Profile Visit andrei155's homepage!
 
Old 05-13-2008, 02:58 PM Re: Security
romes's Avatar
Extreme Talker

Posts: 159
Name: Romes
Location: IL
Trades: 0
If your really willing to protect your self, it is a good idea to find someone who knows servers really well, and have them join your team. I currently have 5 server techs who monitor my servers around the clock. My techs know what to protect. I've had my share of hackers, but nothing to serious. But again, it is a good idea to get someone who knows what their doing to help you out a bit.

Just my 2 cents
__________________

Please login or register to view this content. Registration is FREE
| A blog about everything!
News, Gaming, Technology, Videos, Jokes, Hosting, Entertainment, and Much More!

Please login or register to view this content. Registration is FREE
romes is offline
Reply With Quote
View Public Profile Visit romes's homepage!
 
Old 05-13-2008, 04:27 PM Re: Security
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,514
Name: Andrei
Location: Canada
Trades: 6
I do currently have a few people. Not as many as you though. However, being the owner of the server, I'd like to know every aspect of it. I'm not they type of guy who can just let others do something for me. I like to get involved, and know what's going on.

This is why I raised the question . Thanks for your advice tho. It really would have been helpful.
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
Reply With Quote
View Public Profile Visit andrei155's homepage!
 
Old 05-13-2008, 05:31 PM Re: Security
Skilled Talker

Posts: 59
Name: Dan
Trades: 0
A few key pointers off the top of my head

1) Don't give up any information about your server software or platform. Change favicons, default server headers, default error messages etc.

2) Limit access to known admin ports such as web based server admin ports, ssh, ftp etc. Lock them down to specific ip addresses. Something like IPFilter is good for this.

3) If you use any open source blogging or similar apps change the default file locations especially to admin folders.

4) Ensure all forms thouroughly clean and validate any user input.

5) Ensure you have a strict password policy and learn about username/password enumeration to prevent brute forcing.

6) Don't allow directory listings.

7) Don't use predictable directory names such as "admin".

8) Be paranoid.
__________________

Please login or register to view this content. Registration is FREE

Nuts to that I just want to
Please login or register to view this content. Registration is FREE
Monkey Do is offline
Reply With Quote
View Public Profile
 
Old 05-13-2008, 05:44 PM Re: Security
VirtuosiMedia's Avatar
Web Design Made Simple

Posts: 1,228
Trades: 0
Quote:
Originally Posted by Monkey Do View Post
8) Be paranoid.
Just because I'm paranoid doesn't mean someone isn't out to get me.
VirtuosiMedia is offline
Reply With Quote
View Public Profile Visit VirtuosiMedia's homepage!
 
Old 05-14-2008, 05:10 PM Re: Security
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,514
Name: Andrei
Location: Canada
Trades: 6
Thanks for the info Monkey . Appreciate it.
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
Reply With Quote
View Public Profile Visit andrei155's homepage!
 
Old 05-28-2008, 12:53 PM Re: Security
Junior Talker

Posts: 3
Trades: 0
Complex passwords, firewall, and brute force blocking is the minimum I would recommend.
__________________

Please login or register to view this content. Registration is FREE
- Premium Website Hosting :: SHARED - RESELLER - DEDICATED
ds_andrew is offline
Reply With Quote
View Public Profile
 
Old 05-29-2008, 09:20 PM Re: Security
Marc's Avatar
Super Talker

Posts: 109
Location: EastCoast United States
Trades: 0
IDS Sensor and Checkpoint
__________________

Please login or register to view this content. Registration is FREE
Marc is offline
Reply With Quote
View Public Profile Visit Marc's homepage!
 
Old 05-29-2008, 11:43 PM Re: Security
upstarter's Avatar
Average Talker

Posts: 26
Name: Starr Horne
Trades: 0
All of our servers have 2 nics in them, one on a private network and one exposed to the public. Services like SSH are accessable only through the private network (which I can access with my local machine using a VPN).

It's pretty nice, because it means the only ports that the world can see are 80 and 443. Everything else is hidden.
__________________
my company:
Please login or register to view this content. Registration is FREE


my blog:
Please login or register to view this content. Registration is FREE
upstarter is offline
Reply With Quote
View Public Profile Visit upstarter's homepage!
 
Old 05-30-2008, 04:31 PM Re: Security
Skilled Talker

Posts: 60
Trades: 0
Quote:
Originally Posted by Monkey Do View Post
7) Don't use predictable directory names such as "admin".
Although I have used/installed Wordpress on a site before it has been some considerable time since I last used it myself. A couple days ago I installed Wordpress 2.5.1 in a subdirectory of a new project I am involved with.

I changed the wordpress directory name because I prefer another name. No posts have been made on the blog yet. I have only customized a theme for the blog so far.

I am pretty sure I read, some years ago, when I first used Wordpress, that changing directory names, etcetera, from defaults could cause problems when you backup Wordpress and when you do other "maintenance" tasks.

I would like to follow your advice and definitely change the Wordpress "admin" name(s) and, possibly, the "admin" directory, but I really need to avoid causing myself problems associated with making such changes.

If such name changing is still a problem I figure that changing the "admin" name might manifest it.

Is anyone aware of such Wordpress issues?

Incidentally, IF changing the "admin" name does not cause problems should I have changed its name before I uploaded and "activated" the wordpress blog or does it not matter?

Change the name of mysite.com/wp-admin/*admin.php*, mysite.com/*wp-admin*/, mysite.com/*wp-login.php*/ or all three?

mysite.com/wp-login.php/ appears to redirect to mysite.com/wp-admin/




Last edited by 052808; 05-30-2008 at 05:01 PM..
052808 is offline
Reply With Quote
View Public Profile
 
Old 06-10-2008, 09:58 PM Re: Security
Banned

Posts: 19
Trades: 0
Use a the klingon dictionary for passwords.
imported_bmr is offline
Reply With Quote
View Public Profile
 
Old 08-05-2008, 06:34 AM Re: Security
Junior Talker

Posts: 1
Name: NoName
Trades: 0
Try "Ssentry.com" <- this is my small "child", still beta... I want to finish works into two weeks.
null is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to Security
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.95708 seconds with 12 queries