Need VPS Hardening, Will Pay

Discussion in 'Security' started by nickcmp, Apr 24, 2008.

  1. #1
    Hi,

    I have just bought a VPS, (cpanel).

    I will be hosting some people, NO doubt, these people will be careless and put my server at risk, I know that sounds stupid (Why am I hosting them, type of thing). I just need it secured, firewalled, php tweaked, wing wanged buzzed whatever.

    I can manage dedicated servers, not VPS, I need someone who is experienced with VPS and has a good iTrader.

    Needs to be hardened

    Name your price
    No more than $30, as I can just pay PSM to do it for that and they'll do unlimited tickets included.


    Thanks!
    I'd rather not have advice on how to do it, as I don't have time to actually do it myself, I'm a designer not a linux wizard =]
     
    nickcmp, Apr 24, 2008 IP
  2. olddocks

    olddocks Notable Member

    Messages:
    3,275
    Likes Received:
    165
    Best Answers:
    0
    Trophy Points:
    215
    #2
    just install CSF firewall for Cpanel. Once this is done half of the work is done! see this

    Other things include

    1. Change the SSH port and disable root login.
    2. Install Clam Antivirus
    3. Install RKhunter
    4. Install mod-security

    These are the main work you need to do.
     
    olddocks, Apr 24, 2008 IP
  3. bucasia

    bucasia Peon

    Messages:
    50
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Hi,

    I could sort that out for you.

    Have a look here - http://sysadminman.net/services.html under "Initial server setup..."

    Regards - Matt
     
    bucasia, Apr 24, 2008 IP
  4. nickcmp

    nickcmp Peon

    Messages:
    549
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #4
    I need CSF, but as far as I'm aware it doesn't work well on VPS. And you need someone experienced to config it for vps, plus there is a lot more needed. I need the /tmp secured for example.

    Thanks bucasia but $30 is quite steep, I'll see what other offers I get first
     
    nickcmp, Apr 24, 2008 IP
  5. bucasia

    bucasia Peon

    Messages:
    50
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #5
    No problem.

    You can certainly have problems with iptables in general on a VPS depending how the host has set things up. It needs the relevant modules available in the kernel (ip_conntrack etc...)
     
    bucasia, Apr 24, 2008 IP
  6. nickcmp

    nickcmp Peon

    Messages:
    549
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #6
    & what if it isn't an available module, what are my options then?
     
    nickcmp, Apr 24, 2008 IP
  7. bucasia

    bucasia Peon

    Messages:
    50
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Best plan is to talk to your VPS provider.

    I've had mixed luck with this - 2 installed the moduels, 1 wouldn't and 1 is still thinking about it :)

    Matt
     
    bucasia, Apr 24, 2008 IP
  8. edenCC

    edenCC Member

    Messages:
    63
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #8
    if you are running linux, I can do that for you!
     
    edenCC, May 2, 2008 IP
  9. uski

    uski Peon

    Messages:
    94
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #9
    It's not what you want to hear but you're not going to get a serious security professional secure a server for $30.
    There are several hours worth of work and the wage is not $8/hour for such guys. It's more like $80/hour if not even more.

    Best bet = do it yourself by reading howtos on internet.
     
    uski, May 2, 2008 IP
  10. qualityhostings

    qualityhostings Well-Known Member

    Messages:
    1,764
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    105
    #10
    Hello nick
    As far as I know , CSF wont work well on VPS. or it may need some config change. I tried to install 2 times and vps went offline :(

    As for securing /tmp , just run /scripts/securetmp

    You can ask me if you have any doubts regarding cPanel/linux ssh commands :)

    Vivek
     
    qualityhostings, May 7, 2008 IP
  11. 007c

    007c Peon

    Messages:
    611
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #11
    After that just install tripwire and fail2ban ;)
     
    007c, May 8, 2008 IP
  12. craigedmonds

    craigedmonds Notable Member

    Messages:
    705
    Likes Received:
    134
    Best Answers:
    0
    Trophy Points:
    235
    #12
    craigedmonds, May 14, 2008 IP