{"id":62,"date":"2009-10-28T16:08:37","date_gmt":"2009-10-28T21:08:37","guid":{"rendered":"http:\/\/www.serverpronto.com\/spu\/?p=62"},"modified":"2018-09-04T21:42:57","modified_gmt":"2018-09-05T02:42:57","slug":"basic-tips-for-better-linux-security","status":"publish","type":"post","link":"https:\/\/www.serverpronto.com\/spu\/2009\/10\/basic-tips-for-better-linux-security\/","title":{"rendered":"Basic Tips for Better Linux Security"},"content":{"rendered":"<p>With more Linux options than any other dedicated host, ServerPronto receives lots of questions regarding best practices for Linux security. Below are 9 basic tips to help you keep your server a bit more secure than the standard install. These were written for the Red Hat edition specifically, but the concepts are similar across most Linux platforms.<\/p>\n<p><!--more--><\/p>\n<h5><strong>Change the port ssh listens on.<\/strong><\/h5>\n<p>Edit the ssh configuration file.<br \/>\nnano \/etc\/ssh\/sshd_config<br \/>\nLocate the line \u00e2\u20ac\u0153Port 22\u00e2\u20ac\u009d.<br \/>\nComment out this line by adding a \u00e2\u20ac\u0153#\u00e2\u20ac\u009d before it. (Good practice when modifying any file)<br \/>\nInsert a new line below it \u00e2\u20ac\u0153Port ####\u00e2\u20ac\u009d (Replace #### with a number between 1024 and 65535).<br \/>\nSave the file with \u00e2\u20ac\u0153ctrl+o\u00e2\u20ac\u009d and exit the editor with \u00e2\u20ac\u0153ctrl+x\u00e2\u20ac\u009d.<br \/>\n#### is the port sshd will listen on after the next restart of sshd.<\/p>\n<h5><strong>Restrict ssh access to accounts which are not root.<\/strong><\/h5>\n<p>Edit the ssh configuration file.<br \/>\nnano \/etc\/ssh\/sshd_config<br \/>\nLocate the line \u00e2\u20ac\u0153PermitRootLogin yes\u00e2\u20ac\u009d.<br \/>\nComment out this line by adding a \u00e2\u20ac\u0153#\u00e2\u20ac\u009d before it. (Good practice when modifying any file)<br \/>\nInsert a new line below it \u00e2\u20ac\u0153PermitRootLogin no\u00e2\u20ac\u009d.<br \/>\nSave the file with \u00e2\u20ac\u0153ctrl+o\u00e2\u20ac\u009d and exit the editor with \u00e2\u20ac\u0153ctrl+x\u00e2\u20ac\u009d.<\/p>\n<h5><strong>Create an alternate user account.<\/strong><\/h5>\n<p>Use the adduser command to create a new user with ssh access.<br \/>\n\u00e2\u20ac\u0153adduser \u00e2\u20ac\u201cG wheel ?????\u00e2\u20ac\u009d (Replace ????? with a username 5 or more characters long).<br \/>\nSet the password for the user.<br \/>\n\u00e2\u20ac\u0153passwd ?????\u00e2\u20ac\u009d follow prompts to set the password.<\/p>\n<p><strong>Open new ssh port in the firewall.<\/strong><br \/>\nEdit the iptables configuration file.<br \/>\nnano \/etc\/sysconfig\/iptables<br \/>\nLocate the line which contains \u00e2\u20ac\u0153&#8211;dport 22\u00e2\u20ac\u009d.<br \/>\nComment out this line by adding a \u00e2\u20ac\u0153#\u00e2\u20ac\u009d before it. (Good practice when modifying any file)<br \/>\nInsert a new line below it exactly the same except replace \u00e2\u20ac\u015322\u00e2\u20ac\u009d with the number you replaced #### with.<br \/>\nSave the file with \u00e2\u20ac\u0153ctrl+o\u00e2\u20ac\u009d and exit the editor with \u00e2\u20ac\u0153ctrl+x\u00e2\u20ac\u009d.<\/p>\n<h5><strong>Make new user accounts easier to use.<\/strong><\/h5>\n<p>Import a functional profile for all users with ssh access.<br \/>\nCreate a file \u00e2\u20ac\u0153nano \/etc\/environment-common\u00e2\u20ac\u009d<br \/>\nAdd the text \u00e2\u20ac\u0153${EXPORT}PATH${EQ}\/bin:\/usr\/bin:\/sbin:\/usr\/sbin:\/usr\/local\/bin:\u00e2\u20ac\u009d to the new file without the \u00e2\u20ac\u0153s.<br \/>\nSave the file with \u00e2\u20ac\u0153ctrl+o\u00e2\u20ac\u009d and exit the editor with \u00e2\u20ac\u0153ctrl+x\u00e2\u20ac\u009d.<br \/>\nOpen the profile file \u00e2\u20ac\u0153nano \/etc\/profile\u00e2\u20ac\u009d<br \/>\nAdd the text \u00e2\u20ac\u0153EQ=&#8217;=&#8217; EXPORT=&#8221;export &#8221; . \/etc\/environment-common\u00e2\u20ac\u009d at the end of the file.<br \/>\nSave the file with \u00e2\u20ac\u0153ctrl+o\u00e2\u20ac\u009d and exit the editor with \u00e2\u20ac\u0153ctrl+x\u00e2\u20ac\u009d.<\/p>\n<h5><strong>Test user account.<\/strong><\/h5>\n<p>Using your ssh client open a new connection to the server on port 22.<br \/>\nLog in with the user you created.<br \/>\nCheck superuser access by typing \u00e2\u20ac\u0153su\u00e2\u20ac\u009d and entering the root password for the server.<br \/>\nType \u00e2\u20ac\u0153exit\u00e2\u20ac\u009d twice to log off of this test session.<\/p>\n<h5><strong>Restart changed services.<\/strong><\/h5>\n<p>\u00e2\u20ac\u0153\/etc\/init.d\/sshd restart\u00e2\u20ac\u009d<br \/>\n\u00e2\u20ac\u0153\/etc\/init.d\/iptables restart\u00e2\u20ac\u009d<\/p>\n<h5><strong>Test new settings.<\/strong><\/h5>\n<p>Using your ssh client open a new connection to the server on port ####.<br \/>\nLog in with the user you created.<br \/>\nCheck superuser access by typing \u00e2\u20ac\u0153su\u00e2\u20ac\u009d and entering the root password for the server.<br \/>\nSwitch to the original session logged on as root.<br \/>\nType \u00e2\u20ac\u0153exit\u00e2\u20ac\u009d to log off of this session.<\/p>\n<h5><strong>Optional sudo (Superuser) settings.<\/strong><\/h5>\n<p>Use \u00e2\u20ac\u0153visudo\u00e2\u20ac\u009d to remove the comment from the line \u00e2\u20ac\u0153%wheel ALL=(ALL) NOPASSWD: ALL\u00e2\u20ac\u009d<br \/>\nType \u00e2\u20ac\u0153:wq\u00e2\u20ac\u009d to save and exit this program.<\/p>\n<h5><strong>Other helpful tips.<\/strong><\/h5>\n<ul>\n<li>Ensure all password meet strong password requirements.<\/li>\n<li>http:\/\/www.microsoft.com\/protect\/fraud\/passwords\/checker.aspx<\/li>\n<li>Never disable the software firewall.<\/li>\n<li>Change user account passwords on receipt of server details.<\/li>\n<li>Do not run a mail server daemon unless you intend to configure it for internal use.<\/li>\n<li>Disable all daemons and software packages you do not intend to use.<\/li>\n<\/ul>\n<p>ServerPronto offers affordable and secure<a href=\"https:\/\/www.serverpronto.com\/dedicated\"> dedicated servers<\/a> and<a href=\"https:\/\/www.serverpronto.com\/cloud\"> cloud<\/a> hosting service\u00c2\u00a0<span style=\"font-size: 14px; letter-spacing: 0px;\">packages.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With more Linux options than any other dedicated host, ServerPronto receives lots of questions regarding best practices for Linux security. Below are 9 basic tips to help you keep your server a bit more secure than the standard install. These were written for the Red Hat edition specifically, but the concepts are similar across most<\/p>\n","protected":false},"author":2,"featured_media":1716,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[123,340,112,27,43,42,22,18],"class_list":["post-62","post","type-post","status-publish","format-standard","has-post-thumbnail","category-dedicated-server-security","tag-cloud","tag-dedicated-serber","tag-hosting","tag-linux","tag-linux-security","tag-security","tag-server","tag-web-hosting"],"_links":{"self":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/62","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/comments?post=62"}],"version-history":[{"count":4,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/62\/revisions"}],"predecessor-version":[{"id":2763,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/62\/revisions\/2763"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media\/1716"}],"wp:attachment":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media?parent=62"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/categories?post=62"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/tags?post=62"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}