LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-22-2012, 09:45 AM   #1
praveen_rajus_linuxforum
LQ Newbie
 
Registered: Feb 2012
Location: Delhi
Posts: 1

Rep: Reputation: Disabled
Lightbulb How to secure web server installed on rhel 5 so that no one can do beck door entry ?


How to secure web server installed on rhel 5 so that no one can do beck door entry ?
 
Old 02-22-2012, 09:52 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
You can't generically guard against that, otherwise it would never be possible in the first place. There's always the option of a new exploit being discovered that is not protected against.

if you google for "apache hardening guide" there are many many useful guides to follow
 
1 members found this post helpful.
Old 02-22-2012, 12:00 PM   #3
Tinkster
Moderator
 
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928
Moved: This thread is more suitable in <Linux-Security> and has been moved accordingly to help your thread/question get the exposure it deserves.

Last edited by unSpawn; 02-22-2012 at 05:29 PM. Reason: //wikipedia.org/wiki/The_Golden_Rule
 
Old 02-22-2012, 05:48 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by praveen_rajus_linuxforum View Post
How to secure web server installed on rhel 5 so that no one can do beck door entry ?
In short: choose the right OS (RHEL requires licensing to be kept up to date: also see Centos, Scientific Linux), ensure you update when updates are released (and this includes anything running in your web stack), install only what you need now, harden the OS including accounts (shell, aging, password strength, SSH pubkey auth), do not disable Selinux, apply access restrictions (limit access to only expose what needs to be exposed) and enable auditing to alert you on any anomalies and act on alerts.

[EDIT]What I'm trying to convey is that prevention is important.[/EDIT]


As for hardening your OS:
- http://www.nsa.gov/ia/_files/os/redh...guide-i731.pdf
- http://www.nsa.gov/ia/_files/os/redh...phlet-i731.pdf
- http://people.redhat.com/sgrubb/file...ning-rhel5.pdf
- http://nvd.nist.gov/scap/content/sty...5-document.htm

Test it:
- http://benchmarks.cisecurity.org/too...ark_v1.1.2.pdf
- GNU/Tiger (locally),
- OpenVAS (or nessusd) remotely,

Learn from common errors:
- https://www.owasp.org/index.php/CWE/...tware_Security
- http://www.sans.org/top25-software-errors/
- https://www.owasp.org/index.php/Cate...op_Ten_Project (http://resources.infosecinstitute.co...s-and-tactics/)

...and if you admin the machine act like an administrator. Know what you do and why you do it. See the http://rkhunter.wiki.sourceforge.net/SECREF?f=print for more.

Last edited by unSpawn; 02-23-2012 at 02:24 AM. Reason: //Add emphasis
 
Old 02-23-2012, 06:32 PM   #5
raymor
Member
 
Registered: Nov 2005
Posts: 59

Rep: Reputation: 20
There is some good advice in this thread. Understand too that there are books on that topic that are over 1,000 pages long. Until you've read 1,000 pages and implemented the techniques, remember that the two page guide you use may make your system slightly more secure, but it's no no way actually secure. If it really matters, get hands on help from someone who HAS read the 1,000 books, or even better someone who wrote the book.

unSpawn said "do not disable selinux" and I want to echo that. Also, one of the popular well known control panels by default enables something called suexec. The people who wrote suexec in the first place strongly want that you shouldn't even consider using it if you don't fully understand it. The documentation warns repeatedly of how dangerous it can be. That's the authors talking about the dangers of their own software. They are not wrong - php + suexec = I can crack it every time. So disable suexec unless you're sure that you REALLY understand it's implications.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to secure my web server lqchangba Linux - Security 1 04-22-2007 10:34 AM
Apache Help (Secure Web Server) carlg Linux - Networking 1 10-19-2004 07:46 PM
Linux server as a web door. Kaildathmar Linux - Networking 3 10-04-2003 03:28 PM
Secure web server under RH9 Spydr Linux - Software 0 09-18-2003 11:31 PM
Secure web server sanjibgupta Linux - Newbie 1 08-27-2003 07:05 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration