Linux Security
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   Web Development Archives Mailing Lists Linux Security

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Web Development Archives Sponsor:
  #1  
Old July 3rd, 2008, 12:00 PM
Florin Iliescu
Guest
Dev Archives Newbie (0 - 499 posts)
 
Posts: n/a  
Time spent in forums:
Reputation Power:
Hardening CentOS

Helo,

Can anybody help me with some procedures to secure a CS server? I am going to use it for receiving files over Internet with SFTP.

Thank you,

Florin

Reply With Quote
  #2  
Old July 4th, 2008, 12:09 PM
Jure Krasovic
Guest
Dev Archives Newbie (0 - 499 posts)
 
Posts: n/a  
Time spent in forums:
Reputation Power:
Hardening CentOS

Florin Iliescu pravi:
Helo,
>

Can anybody help me with some procedures to secure a CS server? I am going to use it for receiving files over Internet with SFTP.
>

Thank you,
>

Florin
>
>


>


Hello Florin,

if I were you what I would do is:
1. Close all ports from outside except port 22 with iptables,
2. establish ssh key + user name and password authentication,
3. if you know from which IP's connections are coming then use
tcpwrappers (/etc/hosts.allow + /etc/hosts.deny) to allow sftp
connection from specific ip addresses,
4. Sftp use the same port than ssh. Actually it is subsystem of ssh so
users will be allowed to login to your system (will have shell on your
machine),
5. system should be up to date all the time,
6. IDS/IPS

These are just some thinks I would consider.

I hope it helps a little.

Best regards!

Jure

Reply With Quote
  #3  
Old July 4th, 2008, 12:09 PM
Mario Spinthiras
Guest
Dev Archives Newbie (0 - 499 posts)
 
Posts: n/a  
Time spent in forums:
Reputation Power:
Hardening CentOS

If this is behind a firewall then block all other ports on the
firewall. If not then I would suggest IPTABLES for you. Also check for
any services running that you do not need and disable them. In
addition to those basics , run your SFTP daemon as a local user to
avoid exposing a service under root to the Internet. If your external
users that will be using the service are fixed IP machines then allow
only those machines.

I would also suggest an IDS such as snort for example. things to
account for are services this machine offers to more than one network.
If you have other services being offered to your internal LAN for
example then you might want to bind each service to it's corresponding
network address to avoid external users for example , using your
internal services.

Could you tell me more about your setup and the machine?

Regards,
Mario

Reply With Quote
Reply

Viewing: Web Development Archives Mailing Lists Linux Security > Hardening CentOS


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway
Stay green...Green IT