Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Linux server hardened with CSF and SELinux
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Linux server hardened with CSF and SELinux

If I harden my server with csf and something like SELinux, change the default ssh port, then how secure is it? Can I use it as a production server without other protection?

The reason I ask this is that, I don't have enough money to rent servers from providers like rackspace or liquidweb. I've used two "Full managed" server providers, they have very good reputations on the Web, however, recently I find that they usually can't resolve the questions I submitted, instead, they add new problems to the server, or take hours to find the problem and cause the server can't work during that time, some tech support is just a "cPanel user" or "script user", he don't know more than me, and usually perform testing on my server, as if it's not a production server, it's a test machine, now I'd prefer to solve the problem myself, if I can't, then I will ask questions on the Web, because submit a support ticket may leading to a worse result.

Comments

  • TheLinuxBugTheLinuxBug Member
    edited July 2015

    @jack_298 sounds like a step in the right direction but I can't say that it will 100% secure without anything else. For example, if your running a cPanel server I would highly suggest purchasing CXS (made by the same people as CSF) which constantly watches your server for the upload of malware and viruses and can automatically quarantine the files to prevent hacking. There are likely some other things you could do as well to help secure your server.

    It also sounds like you have been purchasing LET end managed services, because a real managed provider where your paying at least $100.00/month for management should be able to handle any of the management needs you have and be able to install any products you need. Expecting a LET range host to do this for you for like $10-$20 month is expecting way to much in my opinion. Those types of managed accounts are really for complete noobs who just want to host a site on cPanel and need someone to hold their hand through the setup process.

    I would suggest you find a different host with real management services if you need additional help. If you are looking for such a host and need some suggestions feel free to PM me.

    my 2 cents.

    Cheers!

    Thanked by 1Jack_298
  • Thank you, I've hardened the application myself( I've checked every line of my applications recently, and moved the wordpress site to another server to isolate it ), even if somebody uploaded a malware, it won't be executed.

    Believe it or not, both servers take more than $200/month, they usually can't answer my questions instantly, and have to search on Google and perform testing on my server:(

    Actually I switched to a new provider recently, but it's not better than the old one.

    @TheLinuxBug said:
    jack_298 sounds like a step in the right direction but I can't say that it will 100% secure without anything else. For example, if your running a cPanel server I would highly suggest purchasing CXS (made by the same people as CSF) which constantly watches your server for the upload of malware and viruses and can automatically quarantine the files to prevent hacking. There are likely some other things you could do as well to help secure your server.

    It also sounds like you have been purchasing LET end managed services, because a real managed provider where your paying at least $100.00/month for management should be able to handle any of the management needs you have and be able to install any products you need. Expecting a LET range host to do this for you for like $10-$20 month is expecting way to much in my opinion. Those types of managed accounts are really for complete noobs who just want to host a site on cPanel and need someone to hold their hand through the setup process.

    I would suggest you find a different host with real management services if you need additional help. If you are looking for such a host and need some suggestions feel free to PM me.

    my 2 cents.

    Cheers!

  • FritzFritz Veteran
    edited July 2015

    I suggest to use experience providers from here for managed cpanel since you have good budget. For example, @Francisco from BuyVM or @Ernie from HVH.

    Thanked by 1Francisco
  • Thank you, but they can't match my requirement. My server is a dedicated one and has two Xeon CPUs, hardware RAID SSD drives, and 64GB+ RAM.

    @Fritz said:
    I suggest to use experience providers from here for managed cpanel since you have good budget. For example, Francisco from BuyVM or Ernie from HVH.

  • if you want to harden your server, suhosin should be installed as well but unfortunately, certain legit scripts will also not be able to run

Sign In or Register to comment.