LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-27-2010, 12:11 PM   #16
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608

There's additional measures you could think about. They don't do anything for you in terms of actively restricting access though but they're important enough to not leave out.
- The first one is active auditing. The reason I'm listing it is that some people behave better knowing they're watched. Depending on your distribution (in essence: a kernel with SELinux or GRSecurity enabled) you could 0) run the 'auditd' package and set rules (not that hard) that log who accesses what. Without SELinux or GRSecurity you could still run 1) Samhain to check for signs of tampering (changed user authentication or system configuration files) and 2) 'rootsh' to log complete user shell sessions. The dependency would be 0) a remote server these admins have no access to to which you can send syslogs so any activity leading up to any sabotage is safe from tampering and 1) regularly running an auditing tool like SEC or Logwatch to alert you of anomalies or unwanted behaviour.
- The second one is using ACLs (acl.bestbits.at). Placing these admin users in a non-root group and granting them access to the /var/www area may give them enough rights to edit things while still allowing the web server to read and execute content and keeping your admin users from requiring root rights except through specific sudo commands.
- Finally you should have a good (remote!) backup policy in place for the most crucial areas that allows you (or the VPS provider) to restore the system without too much loss should things torun belly up regardless of the cause.
 
Old 11-29-2010, 06:36 AM   #17
Joe of Loath
Member
 
Registered: Dec 2009
Location: Bristol, UK
Distribution: Ubuntu, Debian, Arch.
Posts: 152

Original Poster
Rep: Reputation: 28
XD is an emoticon, I use too many >.> (There we go again...)

I shall post it when I get back from school, the firewall doesn't let SSH through.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
backdoor hacks yonnieboy Linux - Security 27 02-13-2010 04:27 AM
Yet another backdoor for IE.... r_jensen11 General 11 06-29-2004 11:31 AM
/home/backdoor glyn_walters Linux - Security 6 05-15-2003 11:29 AM
backdoor im1crazyassmofo Linux - General 3 01-16-2003 06:54 PM
SSH 2 as a backdoor? help me fenris@bu Linux - Security 3 05-24-2001 12:12 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 12:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration