D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Security considerations on internet facing VPS server

 

The problem with rkhunter or chkrootkit is that they can be fooled by a compromised system.  Ideally they should be run when booting from a different device to usual
Although I have had "success" with chkrootkit, if that's the right word
Tripwire is a quite good tool at this level of defense
The aim is to stop the attacks before they get to this stage.  If rkhunter finds anything then the only course of action is to reinstall the entire system
There are plenty of guides for "hardening" but I'm sure you understand the basics: don't run anything you don't have to, tightly control access, review all logs regularly

On 22 June 2010 09:38, Rob Beard <rob@xxxxxxxxxxxxx> wrote:
Hi folks,

I've been asked by a friend of mine to setup his VPS server so he can stream Shoutcast streams for his online radio station.

Basically he had a server before hosted with a different VPS and something went wrong and things were deleted.  I'm not sure if it was someone falling out with him and deleting everything off the server, the VPS having a problem or someone breaking into the server and doing naughty things.

Anyway this new VPS server is with 1&1, so far it's got a basic install of CentOS 5 with the Plesk Control Panel.  I have asked him if he'd mind if I replaced this with Ubuntu or Debian which I'm more familiar with (which are other OS options that 1&1 offer).

One of my concerns though is securing the server as it's got a direct connection to the internet.  I wondered if anyone had any experiences of packages like Rootkit Hunter or Chkrootkit with Portsentry (I've done a quick search online and these came up as options).

Basically I'm wondering how exactly I should go about installing such packages and if one is favoured over the other?

I presume that things like Rootkit hunter should be installed on a fresh system?

Ta,

Rob

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html