Magento Forum

   
How Can We Secure the server? 
 
jonas73
Sr. Member
 
Total Posts:  97
Joined:  2009-04-24
 

Hi Guys,

We have a linux server and would like it secured as much as possibel.

We have suphp, mod_security, rkhunter, CSF.

What else we can do? We don’t mind paying for it.

I’ve heard that there is a software around which ckecks the source code of website page by page if there is any change sends an email. Do you know which software or website?

Regards

 
Magento Community Magento Community
Magento Community
Magento Community
 
SimpleHelixcom
Enthusiast
 
Avatar
Total Posts:  906
Joined:  2007-08-31
Huntsville, AL
 

GlobalSign offers a new service that will handle this for you, named Armorize HackAlert:

http://www.globalsign.com/support/ordering-guides/Hackalert_FAQ_V1.pdf

If you have a GlobalSign-branded SSL, you can opt in for free.

 
Magento Community Magento Community
Magento Community
Magento Community
 
sareeta
Jr. Member
 
Total Posts:  3
Joined:  2011-04-26
 

Check your log files regularly to see what types of attacks are being run against your server. /var/log/auth or /var/log/auth.log is a typical place to find attempted logins:
Jan 18 10:48:46 ns003 sshd[23829]: Illegal user rosa from ::ffff:58.29.238.252
Jan 18 10:48:49 ns003 sshd[23833]: Illegal user rosemarie from ::ffff:58.29.238.252
Jan 18 10:48:51 ns003 sshd[23838]: Illegal user ruth from ::ffff:58.29.238.252
Jan 18 10:48:54 ns003 sshd[23840]: Illegal user sabine from ::ffff:58.29.238.252
Jan 18 10:48:57 ns003 sshd[23845]: Illegal user sandra from ::ffff:58.29.238.252

Regularly upgrade your operating system to add security fixes. On Debian: apt-get upgrade

Monitor news on vulnerabilities at http://www.securityfocus.com/ and related websites.

Try installing grsecurity and/or SELinux and/or AppArmour and/or PaX.

apartment building insurance

 
Magento Community Magento Community
Magento Community
Magento Community
Magento Community
Magento Community
    Back to top