Keeping cPanel/WHM Secure

Discussion in 'Security' started by kiran(HM), Jun 28, 2009.

Thread Status:
Not open for further replies.
  1. #1
    These are items inside of WHM/Cpanel that should be changed to secure your server.

    Goto Server Setup =>> Tweak Settings
    Check the following items...

    Under Domains
    Prevent users from parking/adding on common internet domains. (ie hotmail.com, aol.com)

    Under Mail
    Attempt to prevent pop3 connection floods
    Default catch-all/default address behavior for new accounts - blackhole

    Under System
    Use jailshell as the default shell for all new accounts and modified accounts

    Goto Server Setup =>> Tweak Security
    Enable php open_basedir Protection
    Enable mod_userdir Protection
    Disabled Compilers for unprivileged users.

    Goto Server Setup =>> Manage Wheel Group Users
    Remove all users except for root and your main account from the wheel group.

    Goto Server Setup =>> Shell Fork Bomb Protection
    Enable Shell Fork Bomb/Memory Protection

    When setting up Feature Limits for resellers in Resellers =>> Reseller Center, under Privileges always disable Allow Creation of Packages with Shell Access and enable Never allow creation of accounts with shell access; under Root Access disable All Features.

    Goto Service Configuration =>> FTP Configuration
    Disable Anonymous FTP

    Goto Account Functions =>> Manage Shell Access
    Disable Shell Access for all users (except yourself)

    Goto Mysql =>> MySQL Root Password
    Change root password for MySQL

    Go to Security and run Quick Security Scan and Scan for Trojan Horses often. The following and similar items are not Trojans:

    /sbin/depmod
    /sbin/insmod
    /sbin/insmod.static
    /sbin/modinfo
    /sbin/modprobe
    /sbin/rmmod

    These are some basic steps that should be taken to ensure the safety and security of your cPanel/WHM server.
     
    kiran(HM), Jun 28, 2009 IP
  2. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Thanks, many users ask for a quick guide of this.
     
    SSANZ, Jun 28, 2009 IP
  3. coffear

    coffear Member

    Messages:
    31
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    43
    #3
    I personally also use ConfigServer as well which helps secure the server as well as giving you an easy to view list of things that can help secure the server.

    http://www.configserver.com/
     
    coffear, Jun 28, 2009 IP
  4. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #4
    +1 Great Script, many of my clients use this also.
     
    SSANZ, Jun 28, 2009 IP
  5. kiran(HM)

    kiran(HM) Banned

    Messages:
    68
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I'm using configserver.com script too protect my server.
     
    kiran(HM), Jul 1, 2009 IP
Thread Status:
Not open for further replies.