LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-21-2015, 03:12 PM   #1
siaswar
Member
 
Registered: Aug 2009
Distribution: xubuntu
Posts: 39

Rep: Reputation: 16
Smile I need everything for security


I am using linux for 5 years. In these 5 years I was just a normal user but learn many things. I am a web developer. There is a guy owning a website. Unfortunately his site is under attack continuously (last day 3000 Gb ddos ) . He asked me for help. I suggest him to migrate his site from windows server to linux. I can help with site application security.
Now I need to learn all about linux security.
suggest me good books and tutorials. and how I practice security.
I need whole package
 
Old 04-21-2015, 03:41 PM   #2
joe_2000
Senior Member
 
Registered: Jul 2012
Location: Aachen, Germany
Distribution: Void, Debian
Posts: 1,016

Rep: Reputation: 308Reputation: 308Reputation: 308Reputation: 308
I don't mean to be negative, but what makes you think that "site application security" or a migration to Linux will solve this problem?

Depending on how much of a problem downtime is for that site owner he should really get support from someone who is experienced with this kind of issue, and that's probably exactly what you should be recommending.
He might also want to invest in ddos mitigation infrastructure, but this is more a financial problem than anything you'd likely be able to help him with...

That said, I find the Arch wiki site on security pretty good, but it's not going to help with ddos attacks.

You are more likely to find anything useful regarding that if you search with terms such as "apache hardening" or "apache security". Just did it and e.g. this this article came up. It also has a section (mod_evasive) that talks about ddos.

Good luck
 
Old 04-21-2015, 04:00 PM   #3
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Need some advice from Linux SysAdmins: where is the best place to start?
Security References
 
Old 05-01-2015, 09:08 PM   #4
metaschima
Senior Member
 
Registered: Dec 2013
Distribution: Slackware
Posts: 1,982

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
Indeed the OS he is using for the servers has little bearing on the effectiveness of the DDOS attack (except in the case of ancient unpatched OS). First read about DDOS:
https://en.wikipedia.org/wiki/Denial-of-service_attack

In general, if you have handled DDOS attacks in the past, then you can offer your services. If you have not, then get someone who has. Although some DDOS attacks can be easily fixed by reconfiguring the firewall, others are highly adaptive and will take an expert to keep at bay.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: The week in security: DDoS rising in Australia, US warns on IoT security LXer Syndicated Linux News 0 02-02-2015 12:02 AM
LXer: GCHQ grants security clearance to Samsung's Knox mobe security LXer Syndicated Linux News 0 05-17-2014 03:00 AM
[Security Questions] Last Login, how good is this feature for security breach info? t3gah Linux - Security 2 06-14-2005 01:02 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration