There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Tag Cloud
audio bios blue screen boot bsod computer connection crash dcom dell driver drivers email error excel firefox freeze google hard drive hardware hijackthis internet keyboard laptop logon logs off malware motherboard network networking problem ram recovery redirect router screen slow software sound trojan usb userinit.exe virus vista wifi windows windows 7 windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Operating Systems > Linux and Unix >
Need help securing a linux web server running CentOS 4. Urgent.

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
bkatz540's Avatar
Senior Member with 273 posts.
 
Join Date: Oct 2003
Location: USA (Virginia)
Experience: Intermediate
27-Apr-2007, 09:38 PM #1
Exclamation Need help securing a linux web server running CentOS 4. Urgent.
Okay, well first off I run a webhosting company with a friend. Our uptimes have not been great until we moved to a dedicated server running CentOS recently. Unfortunately, shortly after the server got set up, all the accounts got transferred, and everything appeared to be working smoothly, our site was hacked by a random person. We cannot afford to have another week of downtime (the hacker deleted all accounts, we had to get our hosting company to reset the server), as we have already lost many customers from this. :\

I'm trying to take steps to completely secure the server, and this is what i've done so far:
-open_basedir restriction enabled
-updated all system software
-changed root password, thinking about disabling root completely?

I have access to root shell, so if you know anything I can do please tell.
I believe the site was hacked using an exploit, as I am not keylogged and I doubt anyone bruteforced us as I would have noticed the traffic. Is there anything else I can do to secure the server?

Again, it's running CentOS 4.

Thanks,
Ben
lotuseclat79's Avatar
Distinguished Member with 15,726 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
28-Apr-2007, 11:24 AM #2
Hi bkatz540,

Checkout: 10 things you should do to a new Linux PC before exposing it to the Internet here.

Pay specific attention to shutting down unnecessary services, and try not to use a root account unless you have the server shutdown for maintenance, and the Internet service offline (if possible - makes it easier for crackers to get root access).

You should think of a layered security strategy, such as having a hardware firewall router in front of your server facing the Internet - and don't forget to change the default mfgrs password as that is a known attack vector for crackers - and install and configure the router by reading the Installation manual from the mfgr.

For CentOS 4 security updates (I don't know how up-to-date this is): here.

CenOS security Guide (from Red Hat) here (free download).

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction
between a mere artisan or specialist and a real seeker after truth. - Einstein 1944
Imagination is more important than knowledge. - Einstein
Closed Thread Bookmark and Share   techguy.org/567435

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 10:24 AM.
Copyright © 1996 - 2010 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2010, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.