Go Back   Defender Hosting Forums > PowerVPS Virtual Private Servers > Linux VPS - Security and Tuning

Linux VPS - Security and Tuning Security and Tuning Discussion for Linux Virtual Private Servers based on Virtuozzo by SWsoft

Reply
 
Thread Tools Display Modes

  #1  
Old 06-19-2005, 03:01 PM
KARanden's Avatar
KARanden KARanden is offline
Member
 
Join Date: Jun 2005
Location: Norway
Posts: 79
KARanden is on a distinguished road
Send a message via AIM to KARanden
Question Necessary steps to secure my new VPS?

Hi

As I wrote in my "introduction" in "the lounge", I consider myself new to VPS and to manage a server with root access.

I assume that PowerVPS has done the steps they say in the top post in this forum?

And I have followed most of the suggestions from webhostgear in their newbie cPanel guide Here.
(Many good "how to's at that place.)

Is there anything else I MUST do to secure my VPS as best as I can?

Any help and suggestions is welcome

But, please remember "baby steps" explaining what I need to do, please.
I'm a quick learner, but to be pointed in the right direction helps very much.

Thanks
__________________
Kjell Arne

From the other side of the "pond"
Norway
Reply With Quote

  #2  
Old 06-21-2005, 01:05 PM
sewmyheadon
Guest
 
Posts: n/a
Default

Kjell - check out this thread:
http://forums.deftechgroup.com/showt...ght=secure+vps
Reply With Quote

  #3  
Old 06-21-2005, 01:37 PM
KARanden's Avatar
KARanden KARanden is offline
Member
 
Join Date: Jun 2005
Location: Norway
Posts: 79
KARanden is on a distinguished road
Send a message via AIM to KARanden
Default

Hi Eric

Quote:
Originally Posted by sewmyheadon
I was refering to that thread in my first post.

What I was asking, if there is any other steps users here does beside what is mentioned in the thread you refering to.
__________________
Kjell Arne

From the other side of the "pond"
Norway
Reply With Quote

  #4  
Old 06-21-2005, 02:04 PM
sewmyheadon
Guest
 
Posts: n/a
Default

Sorry Kjell - missed that - I'm just a follower, so I haven't really done anything else except what was suggested here.
Reply With Quote

  #5  
Old 06-21-2005, 07:50 PM
capnqwest
Guest
 
Posts: n/a
Default

A couple of things that aren't in the aformentioned thread but are good practices include:

1) checking the "Last Login" time/date/location information every time you login as root. If you normally login from, say, a Comcast IP and yet see something like modempool.latvia.eu, then you should be concerned.

2) Make a habit of regularly reviewing /var/log/ secure to look for many failed password attempts or other potentially dangerous information. If you have a question about an alert, Google is your best friend.
Reply With Quote

  #6  
Old 06-22-2005, 08:57 AM
KARanden's Avatar
KARanden KARanden is offline
Member
 
Join Date: Jun 2005
Location: Norway
Posts: 79
KARanden is on a distinguished road
Send a message via AIM to KARanden
Default

Quote:
Originally Posted by capnqwest
A couple of things that aren't in the aformentioned thread but are good practices include:

1) checking the "Last Login" time/date/location information every time you login as root. If you normally login from, say, a Comcast IP and yet see something like modempool.latvia.eu, then you should be concerned.

2) Make a habit of regularly reviewing /var/log/ secure to look for many failed password attempts or other potentially dangerous information. If you have a question about an alert, Google is your best friend.
Thanks, good tips

Sorry, but you say "time/date/location", I can't find any directory with this name when I'm loged in with SSH?
Or do you mean I can see this somewhere else?
__________________
Kjell Arne

From the other side of the "pond"
Norway
Reply With Quote

  #7  
Old 06-22-2005, 09:02 AM
danweber
Guest
 
Posts: n/a
Default

the command "last" will show you recent logins to the system. Of course this information could have been wiped by an intruder but it's worth a look.
Reply With Quote

  #8  
Old 06-22-2005, 05:18 PM
Robert's Avatar
Robert Robert is offline
Staff
 
Join Date: Mar 2005
Posts: 974
Robert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud ofRobert has much to be proud of
Default

If you want to see if anyone is logged in at the same time as you in SSH, you can use "who" or "w" to see IPs of those connections as well.
__________________
Rob Yates
Senior Systems Administrator
PowerVPS / Defender Hosting
Defender Technologies Group, LLC.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows VPS Launch details charles Windows VPS - General 22 12-04-2006 07:29 PM
Server Down rts2271 Linux VPS - General 5 11-02-2006 06:14 AM
Steps to Secure a cPanel Server Starchild Linux VPS - cPanel 4 09-01-2005 09:41 PM
Windows VPS Beta Testing Begins! TomK Windows VPS - General 7 03-04-2005 12:32 AM



All times are GMT -4. The time now is 04:21 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Defender Technologies Group, LLC 2006