Servers will get attacked, any internet facing box will get attacked. The goal is to minimize exposure, close unused ports, stop all unnecessary daemons/program, run a firewall etc... You want your site to be an unattractive target, or not worth "their" time and effort. Similar ideology of protecting your life/home/car from any criminal or thief. They are looking for quick easy targets, or targets with the most "payout/risk-reward".
|