5 ms·
I wouldn't suggest cron'ing apt-get update, it may break something while you're not there. Better to do a manual update once a month or so and do a quick test
by poutine 17y ago
I wouldn't suggest cron'ing apt-get update, it may break something while you're not there. Better to do a manual update once a month or so and do a quick test afterwards. Ideally you'd do this on a identical non-production QA machine, but if you're only a one box sorta guy then you can likely get away with no issues.
Of course, security issues these days are more often the result of misconfiguration but if you're doing something simple like a single box with a localhost only MySQL, Apache/Nginx and Rails/Python/PHP or the like then it's pretty straight forward. Don't really even need a firewall.
What I would suggest is locking down SSH to not allow root login and to require key authentication and deny password auth. So much automated SSH password guessing bot spam out there.
- fortes 17y agoThanks for the info. Are exploits rare enough these days that updating once a month good enough for a well-configured machine? (If so, that's great -- I was worried about taking a vacation :))
- poutine 17y agoDepends on your risk profile, but in general if you update once a month you're probably ahead of 95% of the servers out there.
- wizard_2 17y agoI don't agree - I try to do security patches every few days, and major upgrades when I have time to test them. The hard part is keeping tabs on what servers need them. I have 7 or 8 vm's and when they're not involved in a project they're easy to forget about.
- slig 17y agoSetting up UFW on ubuntu is so simple that I really don't see why not use a firewall.
- andrewvc 17y agoOddly enough, from the command line, I don't get the point of UFW, straight iptables is much easier for me. I mean, if you understand the concepts of iptables, UFW is just an alternate but by no means easier way of manimpulating iptables.
- slig 17y agoAgreed. UFW is just simple to copy/paste commands from tutorials on how to set up your own server.
- gtani 17y agoBrute forcing: http://news.ycombinator.com/item?id=1025520 http://news.ycombinator.com/item?id=1025520 I think a new admin needs to read up on locking down ports in iptables, Bastille, snort, filesystem fingerprinting and some checklists: http://www.mnxsolutions.com/blog/apache/securing-your-server.html http://www.mnxsolutions.com/blog/apache/securing-your-server... http://blog.dhananjaynene.com/2009/10/configuring-a-secure-ubuntu-linux-virtual-private-server/ http://blog.dhananjaynene.com/2009/10/configuring-a-secure-u...
- larrywright 17y agoI always run ssh on a really high port, which does a decent enough job of keeping the password guessing bots.