hosted by liquidweb


Go Back   Web Hosting Talk : Advertising Forums : Employment Offers & Requests : Systems Management Requests : One time server hardening (because I'm lazy...)
Reply

Systems Management Requests Server management forum where you can request help in IIS, Apache, SQL and much more, request them here. If you seek server management or other management services, request them here.
Forum Jump

One time server hardening (because I'm lazy...)

Reply Post New Thread In Systems Management Requests Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 11-27-2007, 03:25 AM
CiscoMike CiscoMike is offline
Sec, DC and Virtual Architect
 
Join Date: Nov 2005
Location: Denver, CO
Posts: 728

One time server hardening (because I'm lazy...)


I'd like to have my server locked down and I *could* do this but I'm lazy and have Cisco work that doesn't give me enough time.

dual core Xeon system (3060)
2GB of RAM
2x 250GB HDs (not in RAID)
CentOS 5 64bit edition, Apache 2.2.6, PHP 5.2.5, MySQL 5.0.45
APF 0.96.1 and BFD 0.9 installed
Zend (3.28 I think) installed
Exim at version 3.48, SpamAssassin at 3.23, ClamAV at 0.97.1 (I think...)
DirectAdmin 1.3.11 (which affects httpd, php, mysql, exim, dovecot, proftpd and others)

Concerns:
OpenSSL at 0.9.8B-<something> which is the CentOS flavor. Would strongly prefer 0.9.8G mainline.
OpenSSH at 4.3p7 and like OpenSSL, would like the mainline version of 4.7p1 if possible
Kernel is out of date (doesn't need to be GRSec, but would rather have GRSec)
I'd LOVE to have Suhosin installed. I've failed twice. I clearly suck.

The long list of items I'd want done:
Get Mod_Security installed and working for Apache 2.2
Installation of eAccelerator (and making it work w/ Zend and Suhosin)
Installation of LibSafe
Limit access to select system binaries
Limit Compiler and Fetch Utilities Access to Root Only
Installation of Process Resource Monitor
Correct permissions on select system directories
Installation of rootkit checking utility (rootkit Hunter and chkrootkit)
Removal of insecure packages and unnecessary software
Disable unused & potentially vulnerable services
Default system users removal
Implement increased logging functions
Harden system shared memory
Harden temporary system directories
Tune/harden the IP Stack via sysctl variables
Harden host.conf
Recursive DNS removal
Install SPRI and tune it for a LAMP install
Optimize and harden MySQL (I've already disabled networking, removed temp, changed root password, etc...I'm sure I missed something)
(insert important things I've missed here)

Gotchas:
I'm using "custombuild" version of apache for DirectAdmin which means the php.ini (might be now after Zend) and httpd.conf are not in their usual places (I did an updatedb earlier so you can locate them) when compared to a plain jane LAMP install.


Things I'm not too keen on:
SIM - it's ok but way too chatty and I have other programs that monitor individual service availability
mod_evasive - too prone to false positives, especially in forum environments. Too often I've DOS'sed myself with it even though it's only a 10 second ban, it's pretty annoying. I would not be amused to find this loaded.


Let me know if the above is workable and what the anticipated costs will be (like for updating OpenSSL and OpenSSH, which will require a rebuild of custombuild in the directadmin folder..../usr/local/directadmin/custombuild/build all d...at a minimum after the OpenSSL upgrade ). PM me if you feel you can do this. I'm not looking for the lowest price, I'm looking for someone who can do this right, do it the first time and do it w/o mucking everything up in the process and hopefully complete it within a respectable timeframe. I'd prefer someone with heavy experience doing this and not from someone looking to learn on the job. Paypal or well known escrow service required.


Last edited by CiscoMike; 11-27-2007 at 03:37 AM. Reason: Added MySQL
Reply With Quote
Sponsored Links
  #2  
Old 11-27-2007, 05:28 AM
david510 david510 is offline
Web Hosting Master
 
Join Date: Oct 2004
Location: Kerala, India
Posts: 4,617
CiscoMike,

Sent you details....

__________________
David | www.cliffsupport.com
Affordable Server Management Solutions sales AT cliffsupport DOT com
iWebManager | Access WHM from iPhone and Android

Reply With Quote
  #3  
Old 11-27-2007, 08:27 AM
kotique kotique is offline
Newbie
 
Join Date: Jan 2005
Location: Chisinau, Moldova
Posts: 10
Wow. First time on WHT I see an employer who knows what he wants.

Reply With Quote
Sponsored Links
  #4  
Old 11-27-2007, 11:57 AM
CiscoMike CiscoMike is offline
Sec, DC and Virtual Architect
 
Join Date: Nov 2005
Location: Denver, CO
Posts: 728
Quote:
Originally Posted by kotique View Post
Wow. First time on WHT I see an employer who knows what he wants.
As my title says, I can do all this myself I'm just too busy/lazy to spend the 7-8 or so hours it would take me (others it'll take 2 or 3 at most) to do everything and I'm 99% sure I'd forget something. Heck, I'm sure I forgot something above.

Also, there will be the occasional on-going work with this since the previous company I worked with didn't disappear but seems to have dropped off the map...which sucks.

Reply With Quote
  #5  
Old 11-27-2007, 12:17 PM
DynamicSpecialist DynamicSpecialist is offline
Newbie
 
Join Date: Nov 2007
Location: Austin Texas
Posts: 5
CiscoMike,

Everything that you are asking for should be able to be completed within 2-4 hours depending on the complications arising from your custom builds. Please contact me via sales@dynamicspecialists.com or hit me up on AIM: johnzulim and we can discuss further. I could potentially begin working on this tonight.

Regards,
John Zulim
Dynamic Specialists

Reply With Quote
  #6  
Old 11-27-2007, 03:31 PM
Sys Admin Sys Admin is offline
WHT Addict
 
Join Date: Apr 2007
Posts: 132
Hi

We do provide this service & We can do this for you.

Please check our services at: http://www.Attacker.net ( for Full details & prices)

*Features*:

-It's our hobby,study and it's our work too. all of our team members have a BS in CS+1 IT certificate at least.

-We use our OWN custom apps & scripts to secure & administer our customer's servers.

-We have enough knowledge to resolve any problem related to servers & security.

- If we cant or unable to fix your server's issue, we will REFUND the money to you.

If you have any question, don't hesitate to contact us at: sales@attacker.net or MSN: expert@attacker.net

Thanks

__________________
Attacker.NET IT Security Consulting Group
Server Management | Security Hardening | Ethical Hacking/Pen-Testing.
Certified Information Security Professionals
E-mail: sales@attacker.net | http://attacker.net

Reply With Quote
  #7  
Old 11-27-2007, 08:09 PM
CiscoMike CiscoMike is offline
Sec, DC and Virtual Architect
 
Join Date: Nov 2005
Location: Denver, CO
Posts: 728
Thank you to everyone who responded, especially those that didn't give the cookie cutter reply via PM. I've chosen a partner for this and will give them a go.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Host 1&1 Internet Adds Server Restoration Tool for Virtual Machines Web Hosting News 2012-11-07 15:45:16
Noise Filter: Windows Server 2012 Hits General Release, Pushes Cloud OS Notion Web Hosting News 2012-09-04 15:47:38
Orpheum Hosting Offers CloudFlare Security and Performance Service Web Hosting News 2012-06-01 16:02:49
Canadian Web Hosting Launches VMware-Based Cloud Services Web Hosting News 2011-10-24 17:02:04
Web Host QualiSpace Launches Managed Servers Web Hosting News 2011-10-14 17:07:58


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?