Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Basics: RE: securing linux webserver?

RE: securing linux webserver?

From: Smith, Ryan <Ryan.Smith_at_MWAA.com>
Date: Tue, 1 Mar 2005 09:22:47 -0500

 
Hi Kurt

Here is link to basic linux hardening:
http://www.tldp.org/HOWTO/Security-Quickstart-HOWTO/index.html
Kind of dated but still relavent. Also included is an Apache 2.0
hardening HOWTO.
http://www.securityfocus.com/infocus/1786

Ryan
-----Original Message-----
From: Kurt Leum [mailto:sarinshadow_at_yahoo.com]
Sent: Sunday, February 27, 2005 9:04 PM
To: security-basics_at_securityfocus.com
Subject: securing linux webserver?

sorry to be so noob,

A friend of mine set up a webserver:
http://www.globalgamesearch.com
problem is, he and I have no idea how to go about securing it; he
started with SuSE Linux 9.1 with Apache 2.0, PHP 4.3.1, and MySQL out of
the box and put it up.

about half an hour ago, an intruder broke in, replaced SSHD with a back
door, and pretty much screwed the system up.

We're going to reinstall the system with minimal programs, extremely
secure permissions and a basic firewall, but beyond that we have no clue
what to do.
Can anyone here please help me out on this?
Thanks in advance for any help.

                
__________________________________
Do you Yahoo!?
Yahoo! Mail - Find what you need with new enhanced search.
http://info.mail.yahoo.com/mail_250
Received on Mar 01 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]