{"id":6386,"date":"2014-06-20T13:52:09","date_gmt":"2014-06-20T08:22:09","guid":{"rendered":"http:\/\/blog.resellerclub.com\/?p=6386"},"modified":"2025-02-27T11:50:02","modified_gmt":"2025-02-27T11:50:02","slug":"8-simple-ways-to-secure-your-linux-servers","status":"publish","type":"post","link":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/","title":{"rendered":"8 simple ways to secure your Linux Servers"},"content":{"rendered":"<p><a href=\"\/blog\/wp-content\/uploads\/2014\/06\/blog-banner1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6389\" src=\"\/blog\/wp-content\/uploads\/2014\/06\/blog-banner1-300x117.png\" alt=\"8 simple ways to secure your Linux Servers\" width=\"474\" height=\"185\" \/><\/a><\/p>\n<p>At <a href=\"http:\/\/www.resellerclub.com\" target=\"_blank\" rel=\"noopener\">ResellerClub<\/a>, our primary objective has always been to provide you with powerful, secure and robust hosting solutions. While for product such as <a href=\"http:\/\/www.resellerclub.com\/products\/linux-shared-hosting\" target=\"_blank\" rel=\"noopener\">Shared Hosting<\/a>, we take utmost care to ensure maximum server level security and redundancy, products such as <a href=\"http:\/\/www.resellerclub.com\/products\/dedicated-server-hosting\" target=\"_blank\" rel=\"noopener\">Dedicated Servers<\/a> and <a href=\"http:\/\/www.resellerclub.com\/products\/vps-hosting\" target=\"_blank\" rel=\"noopener\">VPS<\/a>, we can ensure network level security while the OS level control lies in your hands.<\/p>\n<p>Let\u2019s start by first understanding the basic concepts of a web server. A web server, simply put is a computer host configured and connected to the internet, for serving web pages on user requests. Since web servers are open to public access and often contain critical information, it is important to shield them from hackers.<\/p>\n<p>Although Linux based Operating Systems are relatively more secure and include inbuilt security mechanisms like SELINUX when compared to the others,\u00a0a small vulnerability or bug can give a hacker easy access to your system. Keeping this in mind, we\u2019ve put together a comprehensive set of steps that you can take to mitigate the risk of getting hacked.<\/p>\n<ol>\n<li><strong>Always stay up to date<\/strong><\/li>\n<\/ol>\n<p>A great way to ensure maximum server security at all times is to keep your system up to date with the latest bug fixes or the latest version of your Operating System. A good way to keep track of update announcements is to sign up for email alerts. CentOS \u00a0and Ubuntu have a security mailing list where all security and vulnerability fixes are discussed and released.<\/p>\n<ol start=\"2\">\n<li><strong>Verify Permissions<\/strong><\/li>\n<\/ol>\n<p>It is essential to review permission settings to ensure that a server remains secure. There are certain files such as the \u201c\/etc\/passwd\u201d, \u201c\/etc\/shadow\u201d, \u201c\/etc\/group\u201d and \u201c\/etc\/gshadow\u201cfiles<strong> that <\/strong>contain critical user, password and group information. These files have a greater chance of being subjected to malicious attacks.<\/p>\n<p>Several utilities also require read access to the passwd \ufb01le to function properly, however read access to the shadow file will allow malicious attacks against system passwords, and should never be enabled and should never be enabled.<\/p>\n<p>Below are the default permissions and owners that should be set for these files. <strong>\u00a0<\/strong><\/p>\n<p># cd \/etc<\/p>\n<p># chown root:root passwd shadow group gshadow<\/p>\n<p># chmod 644 passwd group<\/p>\n<p># chmod 400 shadow gshadow<\/p>\n<ol start=\"3\">\n<li><strong>Find unauthorized World Writable files<\/strong><\/li>\n<\/ol>\n<p>The following command discovers and prints any world-writable \ufb01les in local partitions. Run it once for each local partition<\/p>\n<p># find \/tmp -xdev -type f -perm -0002 -print<\/p>\n<p>If this command produces any output, \ufb01x each reported \ufb01le file using the command:<\/p>\n<p># chmod o-w file<\/p>\n<p>Data in world writable \ufb01les can be modi\ufb01ed by any user on the system. In almost all circumstances, \ufb01les can be con\ufb01gured using a combination of user and group permissions to support whatever legitimate access is needed without the risk caused by world-writable \ufb01les.<\/p>\n<p>It is generally a good idea to remove global (other) write access to a \ufb01le when it is discovered. However, it is always advisable to check relevant documentation for applications before making changes. Also, monitor for recurring world-writable \ufb01les, as these may be symptoms of a miscon\ufb01gured application or user account.<\/p>\n<ol start=\"4\">\n<li><strong>Set the sticky bit on World Writable directories<\/strong><\/li>\n<\/ol>\n<p>Setting the sticky bit prevents users from removing each other\u2019s \ufb01les. \u00a0When a sticky-bit is set on a directory, only the owner of a given \ufb01le is given the right to remove it from the directory. Without the sticky bit, any user with write access to a directory can remove any \ufb01le from it.<\/p>\n<p>Use the following command to discover\u00a0and print any world writable files that do not have their sticky bits set.<\/p>\n<p># find \/tmp -xdev -type d \\( -perm -0002 -a ! -perm -1000 \\) -print<\/p>\n<p>If this command produces any output, \ufb01x each reported directory \/dir using the command:<\/p>\n<p># chmod +t \/dir<\/p>\n<p>In cases where there is no reason for a directory to be world writable, a better solution is to remove that permission rather than to set the sticky bit.<\/p>\n<ol start=\"5\">\n<li><strong>Enable ExecShield<\/strong><\/li>\n<\/ol>\n<p>ExecShield helps in\u00a0reducing the risk of worm or other automated remote attacks. It comprises a number of kernel features to provide protection against bu\ufb00er over\ufb02ows. These features include random placement of the stack and other memory regions and special handling of text bu\ufb00ers.<\/p>\n<p>To ensure ExecShield (including random placement of virtual memory regions) is activated at boot, add or correct the following settings in \/etc\/sysctl.conf:<\/p>\n<p>#kernel.exec-shield = 1<\/p>\n<p>#kernel.randomize_va_space = 1<\/p>\n<ol start=\"6\">\n<li><strong>Con\ufb01gure Sudo to improve auditing of Root access<\/strong><strong>C<\/strong><\/li>\n<\/ol>\n<p>The sudo command allows \ufb01ne-grained control through which users can execute commands using other accounts. The primary bene\ufb01t associated with the configuration of sudo is that it provides an audit trail of every command run by a privileged user. It is possible for a malicious administrator to circumvent this restriction, but, if there is an established procedure that all root commands are run using sudo, then it is easy for an auditor to detect unusual behavior when this procedure is not followed.<\/p>\n<ol start=\"7\">\n<li><strong>Set Strict password requirements<\/strong><\/li>\n<\/ol>\n<p>Setting more stringent password requirements can be an additional measure taken to step up server security.<\/p>\n<p>User passwords should be strengthened with the PAM module which can be configured to require at least one uppercase character, lowercase character, digit, and other(special) character,<\/p>\n<p>You can modify your password by following the steps listed below:<\/p>\n<ul>\n<li>Locate the following line in \/etc\/pam.d\/system-auth:<\/li>\n<\/ul>\n<ul>\n<li>#password requisite pam_cracklib.so try_first_pass retry=3<\/li>\n<\/ul>\n<ul>\n<li>and then alter it to read (placing the text on one line):<\/li>\n<\/ul>\n<ul>\n<li>#password required pam_cracklib.so try_first_pass retry=3 minlen=14 \\dcredit=-1 ucredit=-1 ocredit=-1 lcredit=-1<\/li>\n<\/ul>\n<p>You may also modify the arguments to ensure compliance with your organization\u2019s security policy. Note that the password quality requirements are not enforced for the root account<\/p>\n<ol start=\"8\">\n<li><strong>Install LFD and Config Server Firewall<\/strong><\/li>\n<\/ol>\n<p>ConfigServer.com has created a script which by default blocks all ports and provides you the opportunity to allow usage of only those ports on which you have applications running.<\/p>\n<p>Download and install these scripts from <a href=\"https:\/\/configserver.com\" target=\"_blank\" rel=\"noopener\">configserver.com<\/a><\/p>\n<p>Open the config server conf file \/etc\/csf\/csf.conf and modify the below lines to your requirements<\/p>\n<p># Allow incoming TCP ports<br \/>\nTCP_IN = &#8220;22,80&#8221;<\/p>\n<p># Allow outgoing TCP ports<br \/>\nTCP_OUT = &#8220;22,25,80&#8221;<\/p>\n<p>In the example I have allowed port 22 for ssh, port 80 for http and only outgoing for port 25 since I do not want any other server or client using my server for sending emails.<\/p>\n<p>Also modify the below line to your email address.<\/p>\n<p>#LF_ALERT_TO = your email address<\/p>\n<p>Along with the firewall, LFD will also be installed. LFD is a daemon which scans log files and blocks IP addresses trying to brute force your server.<\/p>\n<p>You can whitelist your IP address in \/etc\/csf\/csf.ignore. Please use caution while executing the above commands and if possible test changes on a demo server.<\/p>\n<p>In addition to the above mentioned security measures, we will soon be introducing\u00a0<a href=\"https:\/\/www.sitelock.com\/\" target=\"_blank\" rel=\"noopener\">SiteLock<\/a>\u00a0&#8211; a powerful, cloud-based, website protection service that works as an early detection alarm for common online threats like malware injections, bot attacks etc. Stay tuned to our blog for more details.<\/p>\n<p>We hope you found this article useful. Feel free to start a conversation about your take on this post in the comments below. We would love to know your take on this topic!<\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground:  !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 100% !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>At ResellerClub, our primary objective has always been to provide you with powerful, secure and robust hosting solutions. While for product such as Shared Hosting, we take utmost care to ensure maximum server level security and redundancy, products such as Dedicated Servers and VPS, we can ensure network level security while the OS level control<\/p>\n","protected":false},"author":37,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[995],"tags":[709,712,281,711,710,707,708],"hashtags":[],"class_list":{"0":"post-6386","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-hosting","7":"tag-domain-security","8":"tag-firewall","9":"tag-linux","10":"tag-operating-system","11":"tag-os","12":"tag-sitelock","13":"tag-website-security"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>8 simple ways to secure your Linux Servers<\/title>\n<meta name=\"description\" content=\"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"8 simple ways to secure your Linux Servers\" \/>\n<meta property=\"og:description\" content=\"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/\" \/>\n<meta property=\"og:site_name\" content=\"ResellerClub Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=100005889763273\" \/>\n<meta property=\"article:published_time\" content=\"2014-06-20T08:22:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-27T11:50:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2014\/06\/blog-banner1-300x117.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Leonard Gonsalves\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/\",\"name\":\"ResellerClub Blog\",\"description\":\"Web Hosting &amp; Domains\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"\/blog\/wp-content\/uploads\/2014\/06\/blog-banner1-300x117.png\",\"contentUrl\":\"\/blog\/wp-content\/uploads\/2014\/06\/blog-banner1-300x117.png\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#webpage\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/\",\"name\":\"8 simple ways to secure your Linux Servers\",\"isPartOf\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#primaryimage\"},\"datePublished\":\"2014-06-20T08:22:09+00:00\",\"dateModified\":\"2025-02-27T11:50:02+00:00\",\"author\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/7802fd99e7d56815741236e29b39fcd0\"},\"description\":\"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!\",\"breadcrumb\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.resellerclub.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"8 simple ways to secure your Linux Servers\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/7802fd99e7d56815741236e29b39fcd0\",\"name\":\"Leonard Gonsalves\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/212b06edc915aa36020342276df4def83ce71ec30c1af601b3f1240ce9bb8c08?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/212b06edc915aa36020342276df4def83ce71ec30c1af601b3f1240ce9bb8c08?s=96&d=mm&r=g\",\"caption\":\"Leonard Gonsalves\"},\"url\":\"https:\/\/www.resellerclub.com\/blog\/author\/leonard-g\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"8 simple ways to secure your Linux Servers","description":"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/","og_locale":"en_US","og_type":"article","og_title":"8 simple ways to secure your Linux Servers","og_description":"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!","og_url":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/","og_site_name":"ResellerClub Blog","article_publisher":"https:\/\/www.facebook.com\/profile.php?id=100005889763273","article_published_time":"2014-06-20T08:22:09+00:00","article_modified_time":"2025-02-27T11:50:02+00:00","og_image":[{"url":"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2014\/06\/blog-banner1-300x117.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Leonard Gonsalves","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.resellerclub.com\/blog\/#website","url":"https:\/\/www.resellerclub.com\/blog\/","name":"ResellerClub Blog","description":"Web Hosting &amp; Domains","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#primaryimage","inLanguage":"en-US","url":"\/blog\/wp-content\/uploads\/2014\/06\/blog-banner1-300x117.png","contentUrl":"\/blog\/wp-content\/uploads\/2014\/06\/blog-banner1-300x117.png"},{"@type":"WebPage","@id":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#webpage","url":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/","name":"8 simple ways to secure your Linux Servers","isPartOf":{"@id":"https:\/\/www.resellerclub.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#primaryimage"},"datePublished":"2014-06-20T08:22:09+00:00","dateModified":"2025-02-27T11:50:02+00:00","author":{"@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/7802fd99e7d56815741236e29b39fcd0"},"description":"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!","breadcrumb":{"@id":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.resellerclub.com\/blog\/8-simple-ways-to-secure-your-linux-servers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.resellerclub.com\/blog\/"},{"@type":"ListItem","position":2,"name":"8 simple ways to secure your Linux Servers"}]},{"@type":"Person","@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/7802fd99e7d56815741236e29b39fcd0","name":"Leonard Gonsalves","image":{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/212b06edc915aa36020342276df4def83ce71ec30c1af601b3f1240ce9bb8c08?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/212b06edc915aa36020342276df4def83ce71ec30c1af601b3f1240ce9bb8c08?s=96&d=mm&r=g","caption":"Leonard Gonsalves"},"url":"https:\/\/www.resellerclub.com\/blog\/author\/leonard-g\/"}]}},"_links":{"self":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/6386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/comments?post=6386"}],"version-history":[{"count":8,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/6386\/revisions"}],"predecessor-version":[{"id":35681,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/6386\/revisions\/35681"}],"wp:attachment":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/media?parent=6386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/categories?post=6386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/tags?post=6386"},{"taxonomy":"hashtags","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/hashtags?post=6386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}