• Privacy Policy
  • Disclaimer
  • Sitemap
  • contact

netlabinfo

share for better life

  • Home
  • UBUNTU
  • GUIDE
  • DEBIAN
  • SECURITY
  • CENTOS
  • TIPS
  • CISCO
Home » SECURITY » HARDENING SERVER TIPS

HARDENING SERVER TIPS

netlabinfo
Add Comment
SECURITY
Saturday, July 16, 2016
hardening server is a proces securing server. this is an important thing to do remembering how many server is attacked by  hackers. we can't just rely on firewall configuration on the os that has setting defaultly, we have to setting manually if we want to optimize security on our server. this is some step that can be used to securing your server optimaly

1.       Set bios for disable booting and connect from external device (usb, cd/dvd, etc)

2.       Protect bios, GRUB loader, and login with strong password. Remember don't use easy password(admin, admin123, secret123, etc), combine your password with alphabet, number and character. this will protect you from dictionary attack

3.       Separate your partition, make sure sytem file, third party packet installation and private data is configured seperately. it will help you to secure your data, in case if any disaster happens, just the data on that partition will be damaged while data in other partition is survived. 

4.       Check listening network port with
netstat -tulpn
or
lsof -l -n -P 
close port which does not necesary.

5.       Minimize your service and your package. find your unwanted service or package with command
sysv-rc-conf --list | grep '3:on'
after that disable it using 
sysv-rc-conf servicename off

use RPM manager such as apt-get or yum for list all available and remove unwanted package

6.       Use iptables for managing packets, you can type it on "/etc/rc.local" after that type command
/etc/init.d/rc.local start
to start the iptables rule.
 make sure you type it before "exit 0"

7.       Review log regulary 
/var/log/message – Where whole system logs or current activity logs are available.
/var/log/auth.log – Authentication logs.
/var/log/kern.log – Kernel logs.
/var/log/cron.log – Crond logs (cron job).
/var/log/maillog – Mail server logs.
/var/log/boot.log – System boot log.
/var/log/mysqld.log – MySQL database server log file.
/var/log/secure – Authentication log.
/var/log/utmp or /var/log/wtmp : Login records file.
/var/log/yum.log: Yum log files.

8.       Back up your important data

9.       Keep update your system for minimize vulnerability on your system

10.   Install firewall like honeypot, portsentry, csf or anything. but remember, don't over install firewall to much, it will take effect on your system.

11.   Enable Security-Enhanced Linux (SELinux). SELinux is security mecanhism provided in the kernel. use command
sestatus
if it is disabled use

setenforce enforcing
Tweet
HARDENING SERVER TIPS Title : HARDENING SERVER TIPS
Description : hardening server is a proces securing server. this is an important thing to do remembering how many server is attacked by  hackers. we...
Rating : 5

0 Response to "HARDENING SERVER TIPS"

← Newer Post Home
Subscribe to: Post Comments (Atom)

FOLLOW US

POPULAR POST

  • BASIC NMAP COMMAND FOR NETWORK ADMINISTRATOR
    Nmap is an open source that usually used by network administrator or pentester to scanning network for security and maintenance purpose. ...
  • CONFIGURE AUTHORITATIVE DNS SERVER (MASTER + SLAVE) WITH BIND ON DEBIAN
    DNS server is very usefull when we access any website on the internet. The usability is providing an correct ip address of website or ho...
  • HARDENING SERVER TIPS
    hardening server is a proces securing server. this is an important thing to do remembering how many server is attacked by  hackers. we...
  • CONFIGURE BRIDGED NETWORK ON VMWARE
    VMware is a powerful software that provide you an virtualization enviroment, Usually VMware used for education purpose, so you can try ma...
  • FTP COMMAND LIST WITH TIPS HOW TO USE IT EFFECTIVELY
    ftp is an network protocol that handle transfer data between computer  and use client server architecture. Usually many people connec...
  • INSTALL LAMP IN UBUNTU SERVER 16.04
    LAMP is a open sources packet software that use for building a powerfull web server.  lamp is consist of LINUX operating system, apache w...
  • CONFIGURE MULTIPLE IP ADDRESS WITH VIRTUAL NETWORK INTERFACE ON CENTOS
    Configure multiple ip address on a single NIC is possible with virtual network interfaces. as the name sugest, the ip is configured virt...

Blog Archive

  • ►  2017 (2)
    • ►  February (1)
    • ►  January (1)
  • ▼  2016 (5)
    • ►  December (1)
    • ►  November (2)
    • ▼  July (2)
      • INSTALL LAMP IN UBUNTU SERVER 16.04
      • HARDENING SERVER TIPS

Labels

  • CENTOS
  • COMMAND
  • DEBIAN
  • GUIDE
  • SECURITY
  • TIPS
  • UBUNTU

Blog Archive

  • ►  2017 (2)
    • ►  February (1)
    • ►  January (1)
  • ▼  2016 (5)
    • ►  December (1)
    • ►  November (2)
    • ▼  July (2)
      • INSTALL LAMP IN UBUNTU SERVER 16.04
      • HARDENING SERVER TIPS
Back to top!
Copyright 2014 netlabinfo - All Rights Reserved Design by Ciri seo - Powered by Blogger