hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : VPS Hosting : What security is needed on a VPS hosting a single personal site ?
Reply

VPS Hosting Virtual private server discussion and vps hosting solutions. Review VPS hosting providers and offer advice on virtual web hosting solutions. If your service is unavailable, please click here.
Forum Jump

What security is needed on a VPS hosting a single personal site ?

Reply Post New Thread In VPS Hosting Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 02-24-2008, 12:40 AM
deodeep deodeep is offline
Newbie
 
Join Date: Aug 2006
Posts: 5

What security is needed on a VPS hosting a single personal site ?


Hello everyone,

My personal blog has been getting quite a few hits recently, for a shared hosting environment to hold it. It runs Wordpress 2.3 and a customized theme. I use Gmail and hence the server's Email is not used.

Now, I plan to buy a VPS ( preferably a slice ) and am planning to move my site onto it. I'll be frank with you, I've never worked on a VPS before. So for the first week or two, I want to spend time customizing the VPS environment and securing it. Mine will be the only site hosted on it and a Control Panel, if any installed, will be Plesk.

I was going through the VPS Tutorials section of the site and really liked the tutorial on securing your VPS.
Now, I'd like to know what amount of security would be needed for my VPS ? What all should I be implementing to make sure my VPS is secure ?
Some tips / advices would be really appreciated.

Remember, I'll be hosting only my blog. I'll require FTP, SSH, PhpMyAdmin and Awstats running, other than the obvious services.

Could someone here guide me in the right way ?

Thanks and Regards,

Deep Deo.

Reply With Quote


Sponsored Links
  #2  
Old 02-24-2008, 12:59 AM
MegaByteHosting MegaByteHosting is offline
Web Hosting Guru
 
Join Date: Sep 2005
Posts: 273
change ssh port to none standard port. Install pureftp. Keep you scripts upto date. Shut off mail service. Secure PHP as much as possible. This would be a good start I guess.

Reply With Quote
  #3  
Old 02-24-2008, 01:30 AM
minipro minipro is offline
WHT Addict
 
Join Date: Jun 2006
Posts: 164
Have you considered going for a shared hosting a/c in someone else's VPS? How many hits do you get a day?

You can even go for a managed VPS rather than break your head over securing, updating, etc.

Reply With Quote
Sponsored Links
  #4  
Old 02-24-2008, 01:35 AM
deodeep deodeep is offline
Newbie
 
Join Date: Aug 2006
Posts: 5
@hsphereclub:
Thanks. You've answered the "what to do" part and I appreciate that. But could you, if possible answer the "how-to" part too ?

@minipro:
I did give it a thought. But I've always wanted to handle a VPS myself and learn new things. And well, for everything, there's always a first time. With Slice's backup solutions, I could very well restore the image if I mess up
Managed VPS are a tad costly.. though.

Thanks

Reply With Quote
  #5  
Old 02-24-2008, 01:46 AM
MegaByteHosting MegaByteHosting is offline
Web Hosting Guru
 
Join Date: Sep 2005
Posts: 273
Quote:
Originally Posted by deodeep View Post
@hsphereclub:
Thanks. You've answered the "what to do" part and I appreciate that. But could you, if possible answer the "how-to" part too ?

@minipro:
I did give it a thought. But I've always wanted to handle a VPS myself and learn new things. And well, for everything, there's always a first time. With Slice's backup solutions, I could very well restore the image if I mess up
Managed VPS are a tad costly.. though.

Thanks
I cant really help out much until you specify an OS and Control Panel.

Reply With Quote
  #6  
Old 02-24-2008, 01:46 AM
RossMAN RossMAN is offline
Grand Nagus
 
Join Date: Dec 2002
Location: Ferenginar
Posts: 4,102
Which VPS providers are you considering? Some offer semi or fully managed services.

Others might harden and secure your VPS for a one time fee.

Reply With Quote
  #7  
Old 02-24-2008, 01:47 AM
deodeep deodeep is offline
Newbie
 
Join Date: Aug 2006
Posts: 5
Oh. I plan to use Debian 4.0 along with Plesk 1 domain.

Reply With Quote
  #8  
Old 02-24-2008, 01:51 AM
MegaByteHosting MegaByteHosting is offline
Web Hosting Guru
 
Join Date: Sep 2005
Posts: 273
You might find it easier and more secure to go with something like webmin for a control panel. Its easy to install and doesn't use much resources.

Also you could start out with installing APF firewall and brute force detect for ssh logins. I think this forum is not a great place to discuss your security setup if you know what I mean.

Reply With Quote
  #9  
Old 02-24-2008, 01:53 AM
RossMAN RossMAN is offline
Grand Nagus
 
Join Date: Dec 2002
Location: Ferenginar
Posts: 4,102
Quote:
Originally Posted by deodeep View Post
@hsphereclub:
Managed VPS are a tad costly.. though.
Have you searched the VPS Hosting Offers forum?

SliceHost.com 256slice $20/mo
10GB/100GB/unmanaged

ZipServers.com VPS Plan 1 $29.95/mo
10GB/250GB/Plesk/Managed

For an extra $9.95 you receive an additional 150GB bandwidth, Plesk control panel and managed.

Reply With Quote
  #10  
Old 02-24-2008, 08:18 AM
deodeep deodeep is offline
Newbie
 
Join Date: Aug 2006
Posts: 5
I have tried webmin on my home server. Didn't really like it.
Also, I'll read about those things. I haven't specified an URL yet

@RossMAN
Well, I am just going to host one site on the VPS. I am particularly looking forward to buying a VPS and not something like (mt) because I want to learn things myself. I hope you understand
Hence, it doesn't make sense to me to add even those $10 extra for something which I won't need. Ofcouse, if I _do_ plan to host multiple sites and think of reselling, I have your advice on my mind and surely know where to look. Thanks

Reply With Quote
  #11  
Old 02-24-2008, 08:57 AM
Vinayak_Sharma Vinayak_Sharma is offline
Always Learning...
 
Join Date: Aug 2002
Location: Bharat
Posts: 4,571
Deep its better get a semi managed VPS from a provider where you get HyperVM to control your VPS and you also get LxAdmin for free along with it. LxAdmin is another control panel and it is one of the lightest control panel.

Now as of security, whether you are using this VPS for single personal site or multiple sites, security should be as tight as possible, secured updated OS, firewall, services not required should be closed, secured VAR and temp folders, non standard SSH port, un used ports should be closed there is lot to it and its not one time, security audit should be done on regular basis.

And yes upto date Wordpress script, or any other script that you use or going to use.

__________________
Vinsar.Net - Quality Web Hosting at Economical Price on USA, UK & Italian Servers
Offering domains, shared, reseller & VPS hosting.
Reliable Domain Reseller Account Resell Domains with Confidence

Reply With Quote
  #12  
Old 02-24-2008, 09:09 AM
Vinayak_Sharma Vinayak_Sharma is offline
Always Learning...
 
Join Date: Aug 2002
Location: Bharat
Posts: 4,571
Quote:
Originally Posted by hsphereclub View Post
Shut off mail service
I will not recommend shutting off mail service, you need it for root's mails, moreover many applications will be sending you daily reports alerts etc from the server, so you need the service to run.

But yes you can configure your system to either close SMTP for outer world or you can configure it to relay mails only for local users.

I am not very much familiar with wordpress, but I think it also uses/needs mail service to send out mail, but yes if wordpress has the feature to use SMTP for outgoing mails, you can use google's SMTP.

__________________
Vinsar.Net - Quality Web Hosting at Economical Price on USA, UK & Italian Servers
Offering domains, shared, reseller & VPS hosting.
Reliable Domain Reseller Account Resell Domains with Confidence

Reply With Quote
  #13  
Old 02-24-2008, 12:41 PM
deodeep deodeep is offline
Newbie
 
Join Date: Aug 2006
Posts: 5
Thank you Vinsar.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Security and Optimization Provider Incapsula Launches Web Host Affiliate Program, cPanel Plugin Web Hosting News 2012-10-23 10:19:03
Cloud Security Firm Dome9 Adds Group-Based Firewall Policy Management Function Web Hosting News 2012-01-25 12:41:56
Web Host Mabuhay Hosting Offers SiteLock Security Services Web Hosting News 2011-12-07 20:52:17
Web Host Secure Cloud Space Introduces Security-Focused Hosting Services Web Hosting News 2011-09-22 15:41:27
UK Web Host UKFast Report Shows Credit Card Info Can be Found Via Google Search Web Hosting News 2011-07-22 20:16:14


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?