{"id":940,"date":"2015-05-15T21:50:56","date_gmt":"2015-05-16T02:50:56","guid":{"rendered":"http:\/\/www.serverpronto.com\/spu\/?p=940"},"modified":"2018-07-19T10:32:17","modified_gmt":"2018-07-19T15:32:17","slug":"protect-your-server-from-hackers","status":"publish","type":"post","link":"https:\/\/www.serverpronto.com\/spu\/2015\/05\/protect-your-server-from-hackers\/","title":{"rendered":"Protect Your Server from Hackers"},"content":{"rendered":"<p>It seems like at least once a month now a big story breaks about a company getting hacked and all the damage that this did. For this reason, it\u00e2\u20ac\u2122s important you take precautions with your computer by using security software and working from within a firewall whenever possible. However, if you think your computer is a target, consider the treasure trove a server represents. Fortunately, with the following methods, you should have a better chance of keeping yours safe from hackers.<!--more--><\/p>\n<h2>Understand Network Flow<\/h2>\n<p>If you understand the regular network flow your server is supposed to receive and send\u00e2\u20ac\u201din terms of requests\u00e2\u20ac\u201dthen you should be able to allow and check them (requests\/content inspection). At the same time, you should also be able to deny other traffic via a firewall.<\/p>\n<p>An effective network isolation measure like this will be successful in reducing the risk of an intrusion burrowing into your production network or some kind of malware spreading, amongst other things.<\/p>\n<h2>Separate Your DMZ and LAN<\/h2>\n<p>Your demilitarized zone (DMZ) is supposed to provide a buffer space between the private network your company uses and the public network outside. This way, anyone on the outside is prevented from obtaining direct access to any server hosting company data.<\/p>\n<p>For this reason, it\u00e2\u20ac\u2122s essential that your DMZ isn\u00e2\u20ac\u2122t able to connect directly to your local-area network (LAN). Firewalls should guarantee this, but always double check to be sure (and test regularly to be certain this hasn\u00e2\u20ac\u2122t changed).<\/p>\n<h2>Make Sure No One Can Request Your Web Server Directly<\/h2>\n<p>Obviously, you don\u00e2\u20ac\u2122t want someone being able to just pull up your web server at will. That doesn\u00e2\u20ac\u2122t take any type of hacker-like intelligence to try either. However, there should be no less than three security filtering layers present for filtering your web server so this can\u00e2\u20ac\u2122t happen.<\/p>\n<p>Ideally, the three layers you\u00e2\u20ac\u2122ll use will be:<\/p>\n<ul>\n<li>Firewall for accepting protocols and sources<\/li>\n<li>NIPS (Network Intrusion Protection System) for detecting and blocking suspicious network requests<\/li>\n<li>WAF (Web Application Firewall) for application-oriented security<\/li>\n<\/ul>\n<h2>Clients Shouldn\u00e2\u20ac\u2122t Be Able to Request Your Server<\/h2>\n<p>While it might seem nice to give clients this level of access, you\u00e2\u20ac\u2122re exposing a pretty big vulnerability by doing so. The decision to allow clients to request your server will definitely facilitate attacks if a hacker decides to make you a target.<\/p>\n<p>Utilize a reverse proxy at the front-end of your web server. Not only will this help with better load balancing, but it will also make your job easy in terms of managing legitimate network flow.<\/p>\n<h2>Audit Hosted Code Regularly<\/h2>\n<p>It\u00e2\u20ac\u2122s sad to say, but you can\u00e2\u20ac\u2122t even trust hosted code with your server\u00e2\u20ac\u2122s security. Hackers are great about finding vulnerabilities within the code and exploiting it for their purposes. That\u00e2\u20ac\u2122s why you need to audit hosted code regularly. Obviously, you also want to update any and all software as necessary too.<\/p>\n<h2>Stay Aware of New Threats<\/h2>\n<p>Like we mentioned at the beginning, hacker attacks regularly make the news throughout the year. Always keep tabs on what\u00e2\u20ac\u2122s happening with their cyber attacks, so you can prepare and respond accordingly.<\/p>\n<p>As you already know, hackers are a very serious threat and they love going after servers. That\u00e2\u20ac\u2122s why, when you decide on dedicated servers, ServerPronto should be your first choice. We\u00e2\u20ac\u2122ve become well known for providing servers to companies just like yours, including top-of-the-line security features.<\/p>\n<p><a href=\"https:\/\/www.serverpronto.com\">ServerPronto<\/a> offers the best affordable and secure hosting service in all dedicated server packages.<\/p>\n<p>Source: http:\/\/social.technet.microsoft.com\/wiki\/contents\/articles\/13974.security-best-practices-to-protect-internet-facing-web-servers.aspx<\/p>\n<p>Photo cred: Flickr \/\u00c2\u00a0<a href=\"https:\/\/www.flickr.com\/photos\/brianklug\/\">brianklug<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It seems like at least once a month now a big story breaks about a company getting hacked and all the damage that this did. For this reason, it\u00e2\u20ac\u2122s important you take precautions with your computer by using security software and working from within a firewall whenever possible. However, if you think your computer is<\/p>\n","protected":false},"author":9,"featured_media":941,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[75],"tags":[123,17,115,112,42,22,18],"class_list":["post-940","post","type-post","status-publish","format-image","has-post-thumbnail","category-it-support","tag-cloud","tag-dedicated-server","tag-hackers","tag-hosting","tag-security","tag-server","tag-web-hosting","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/940","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/comments?post=940"}],"version-history":[{"count":3,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/940\/revisions"}],"predecessor-version":[{"id":2419,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/940\/revisions\/2419"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media\/941"}],"wp:attachment":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media?parent=940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/categories?post=940"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/tags?post=940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}