Security Basics mailing list archives

RE: securing linux webserver?


From: "Smith, Ryan" <Ryan.Smith () MWAA com>
Date: Tue, 1 Mar 2005 09:22:47 -0500

 
Hi Kurt

Here is link to basic linux hardening:
http://www.tldp.org/HOWTO/Security-Quickstart-HOWTO/index.html
Kind of dated but still relavent. Also included is an Apache 2.0
hardening HOWTO.
http://www.securityfocus.com/infocus/1786

Ryan
-----Original Message-----
From: Kurt Leum [mailto:sarinshadow () yahoo com] 
Sent: Sunday, February 27, 2005 9:04 PM
To: security-basics () securityfocus com
Subject: securing linux webserver?

sorry to be so noob,

A friend of mine set up a webserver:
http://www.globalgamesearch.com
problem is, he and I have no idea how to go about securing it; he
started with SuSE Linux 9.1 with Apache 2.0, PHP 4.3.1, and MySQL out of
the box and put it up.

about half an hour ago, an intruder broke in, replaced SSHD with a back
door, and pretty much screwed the system up.

We're going to reinstall the system with minimal programs, extremely
secure permissions and a basic firewall, but beyond that we have no clue
what to do. 
Can anyone here please help me out on this? 
Thanks in advance for any help.


                
__________________________________
Do you Yahoo!? 
Yahoo! Mail - Find what you need with new enhanced search.
http://info.mail.yahoo.com/mail_250


Current thread: