4 ms·
There have been a number of good app-specific recommendations below, but I think there are some more general things to keep in mind, too: #1: Keep your system
by rcoder 19y ago
There have been a number of good app-specific recommendations below, but I think there are some more general things to keep in mind, too:
#1: Keep your system up-to-date. Your most likely entry vector is a perfectly legitimate service like Apache or OpenSSH (or even worse, some PHP application) being cracked 'cause you never installed a critical security patch.
#2: Run different services as different users. There's no reason for your Mongrel listeners, cron jobs, reverse proxy, and god knows what else to run as the same user. Basic uid/gid partitioning is at the core of good POSIX security.
#3: Never, ever trust a public web application or server with total access to your data. Use your database server's access controls to limit admin-level access, and consider running your load balancer, public applications, and admin tools on separate hosts.
#4: Find ways to prevent password storage, entry, and checking on your application servers. Read up on and understand Kerberos, even if you aren't going to use it: it's the industry standard for an authentication system that doesn't require clients to expose their password to servers.