| |
Enforce
no-executable/no-suid operations on /tmp & /var/tmp
Enforce no-executable/no-suid operations on shared memory
tmpfs
mod_dosevasive installation with custom settings
mod_security installation with custom directive settings
and snort-based filter-rules
Common Security Permissions
Official System Software Updates
Increased System Logging
Backdoor Inspection
WhoCompiled - Check for compiler usage
Update Apache
disable php functions (phpinfo, system, include, chown,
chmod, exec, mail, passthru, etc...)
Root Access Notification
Disable Telnet and other insecure services
Force the use of SSH protocol 2
Mask apache server & services version numbers
Set an SSH Legal Message
Daily server maintenance, adding users, compiling software,
etc...
and more... |