4 ms·
A) since you have a relationship with Rackspace, why not rackspace cloud? B) Unless this is a multi user system with the most likely vector of attack is your a
by yourabi 17y ago
A) since you have a relationship with Rackspace, why not rackspace cloud?
B) Unless this is a multi user system with the most likely vector of attack is your application itself not system level.
Having said that here are some common tips: run ssh on a nonstandard port, Restrict who can log in via ssh (PermitRootLogin no) and only allow a few people remote access (AllowUsers foo bar) install a firewall (iptables) that blocks all ports except the ones you need publicly available (probably 80, 443).
It is worth taking the time to learn the basics. This is not something you want to outsource to elance.
- pmjoyce 17y agoI'm more than willing to learn the basics - my fear is that the basics simply aren't good enough. I can be confident in the things I have done but being unaware of thing I should be doing and not is what would keep me awake. I totally agree that most vulnerable attack vector is the app itself but that, I feel, I have control over. This is why I thought I'd hand this part over to a professional. If Elance is not the place to go does anyone know of any reputable companies or individuals who would be able to offer a service like this? Surely I'm not the only non systems administrator that has faced this issue - or is it as simple as following the steps outlined above and that's generally enough? The reason I don't want to go with Rackspace is that I've been having intermittent problems with them on Rackspace Sites for a few months. I know their Cloud product is not the same but my experience of their support and the fact that the technical issues haven't been ironed out in a few months hasn't given me a warm and cozy feeling.
- unperson 17y agoRunning ssh on a nonstandard port does NOT make ssh more secure. A better step would be setting up something like fail2ban. There is nothing wrong with outsourcing this to someone who knows what they are doing.