{"id":819,"date":"2014-09-02T07:36:25","date_gmt":"2014-09-02T12:36:25","guid":{"rendered":"http:\/\/www.serverpronto.com\/spu\/?p=819"},"modified":"2018-07-26T10:57:04","modified_gmt":"2018-07-26T15:57:04","slug":"tips-to-improve-your-linux-servers-security","status":"publish","type":"post","link":"https:\/\/www.serverpronto.com\/spu\/2014\/09\/tips-to-improve-your-linux-servers-security\/","title":{"rendered":"Tips to Improve Your Linux Server\u00c2\u00b4s Security"},"content":{"rendered":"<p><em>Bless Linux and bless the people that think this article is about a member of Peanuts. Though, where Linus van Pelt has a security blanket, you have to provide your own blanket when dealing with a Linux server. Here are seven brief security tips.<\/em><br \/>\n<!--more--><\/p>\n<h2>1. Use SELinux<\/h2>\n<p>This is the Security-Enhanced Linux and it is a compulsory access control security mechanism. When you disable SELinux, you remove a further security system for your server (which is bad). Set your server to \u00e2\u20ac\u0153Enforcing\u00e2\u20ac\u009d and ignore the programs and websites that tell you to set it to \u00e2\u20ac\u0153Permissive\u00e2\u20ac\u009d or \u00e2\u20ac\u0153Disabled.\u00e2\u20ac\u009d There is a \u00e2\u20ac\u02dcsestatus\u00e2\u20ac\u02dc command you can use to check the status of your SELinux.<\/p>\n<h2>2. You should use SSH<\/h2>\n<p>This is Secure Shell, which is a protocol that is going to use encryption technology when communicating with the server. You really shouldn\u00e2\u20ac\u2122t log directly as root unless you have to. Maybe you should disable root login.<\/p>\n<h2>3. Disk partitions help obtain higher data security<\/h2>\n<p>You can separate and group information in the same way you separate sauces at a buffet. If someone drips salad dressing into the shrimp cocktail then only the shrimp cocktail needs to be changed and not the relish, mayonnaise, etc.<\/p>\n<h2>4. Keep your system updated<\/h2>\n<p>This is one of the most obvious security notions, and it isn\u00e2\u20ac\u2122t as if people do not know, they just put it off. It\u00e2\u20ac\u2122s inconvenient and auto-update programs are never 100% reliable. Maybe you should set up a quarterly update session that reminds you to tinker with your server and update it where any auto-updates have failed.<\/p>\n<h2>5. Packages cause vulnerabilities<\/h2>\n<p>Have you ever seen those articles that tell you not to download apps for your phone if you are not going to use them or only use them once? The same may be true for server security. You should find and remove unwanted services in order to minimize the amount of vulnerability on your server.<\/p>\n<h2>6. View your listening network ports<\/h2>\n<p>You can use the \u00e2\u20ac\u02dcnetstat\u00e2\u20ac\u02dc networking command and see all the open ports and all the associated programs, and you can use \u00e2\u20ac\u02dcchkconfig\u00e2\u20ac\u02dc to disable all the unwanted network services from your Linux server.<\/p>\n<h2>7. Physical security is important<\/h2>\n<p>Restricting physical access to the server with something as simple as a password is going to help quite a bit. Supervising your own servers and checking who visits, who accesses it and why is important too.<\/p>\n<p>&nbsp;<\/p>\n<p>Photo cred: Flickr \/ <a href=\"http:\/\/www.flickr.com\/photos\/muehlinghaus\/\">muehlinghaus<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bless Linux and bless the people that think this article is about a member of Peanuts. Though, where Linus van Pelt has a security blanket, you have to provide your own blanket when dealing with a Linux server. Here are seven brief security tips.<\/p>\n","protected":false},"author":9,"featured_media":820,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[9,86],"tags":[123,17,112,27,43,22,18],"class_list":["post-819","post","type-post","status-publish","format-image","has-post-thumbnail","category-dedicated-server-security","category-server-security","tag-cloud","tag-dedicated-server","tag-hosting","tag-linux","tag-linux-security","tag-server","tag-web-hosting","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/819","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/comments?post=819"}],"version-history":[{"count":3,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/819\/revisions"}],"predecessor-version":[{"id":2482,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/819\/revisions\/2482"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media\/820"}],"wp:attachment":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media?parent=819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/categories?post=819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/tags?post=819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}