6 ms·
Securing your Linux web server
- gmemstr 9y agoNo mention of restricting access to keypairs and removing access via password login? This is the #1 thing I do with all servers I deploy.
- vinceguidry 9y agoAt the top of the article it's mentioned that the blog post is an excerpt from a book.
- Sir_Cmpwn 9y agoI have a little checklist I use to cover the basics: https://drewdevault.com/new-server.html https://drewdevault.com/new-server.html
- brianjking 9y agoChanging the default SSH port is a great idea too.
- KeybInterrupt 9y agoYeah, it is security through obscurity, I do it anyway on my Internet facing systems because then I don't have to bother with most automated SSH Scanners.
- rodolphoarruda 9y agoI'm a generalist project manager. When you say "Disable password login via ssh", what is going to be the login method from this point onwards? Via a personal certificate? Tks
- Sir_Cmpwn 9y ago~/.ssh/authorized_keys, which is basically personal certificates.
- zmyrgel 9y agoOr just use actual SSH certificates instead of public keys so you don't need to have authorized_keys file at all.
- brobinson 9y agoYou should be using public key authentication: https://www.digitalocean.com/community/tutorials/how-to-set-up-ssh-keys--2 https://www.digitalocean.com/community/tutorials/how-to-set-... If you insist on using passwords, make sure you at least install something like fail2ban or denyhosts to block the compromised machines which are hammering your server trying to guess passwords. Clients can see which authentication methods are allowed so they know which machines to attack (i.e., yours, if you allow passwords).
- MertsA 9y agoOr for something even cleaner than a program trying to parse plaintext logs you can use a PAM module. https://wiki.archlinux.org/index.php/Pam_abl https://wiki.archlinux.org/index.php/Pam_abl
- adfskjldsjfk 9y agoHow would you compare it with fail2ban?
- deleted 9y ago[deleted]
- AFNobody 9y agoI suggest you setup an account on Github and then create a SSH key with a passphrase: https://help.github.com/articles/generating-a-new-ssh-key-and-adding-it-to-the-ssh-agent/ https://help.github.com/articles/generating-a-new-ssh-key-an... https://help.github.com/articles/testing-your-ssh-connection/ https://help.github.com/articles/testing-your-ssh-connection... SSH Keys are substantially more secure than passwords.
- newbear 9y agoThe general advice I've seen is to not host your own server. But I think it would be a great learning experience. If you cover the basics, is your server still extremely vulnerable?
- madez 9y agoWho is giving the advice to not host your own server? My advice is to do host your own server.
- peterwwillis 9y agoYep, you should definitely host your own server. And build your own Linux distro. And your own computer. Then weave your own cloth, sew your own clothes, cobble your own shoes. Build a car. Buy some land. Build a house. Move to the country. Raise chickens. Till and sow land. Get off the grid. Abandon the modern world. It's perfectly possible to drive a car without building one, or to become technically proficient without hosting your own server. If you DIY something, you may learn a lot about it, but it won't make you any better at the thing you actually wanted to do with it.
- NinjaKitten 9y agoYou could have said that without the snark.
- deleted 9y ago[deleted]
- madez 9y agoIt is not about learning everything by doing it yourself from scratch. Hosting a service yourself on your own server is becoming simpler and simpler by the day. Capable hardware is cheaply available in the form of single board computers and projects like Freedombox[0] and Yunohost[1] make the hosting part simple for the services they preconfigure. I don't know why you write such a confrontative comment. Hosting your server is important to have control over your data. You don't need to build your own Linux distro for that... [0] https://freedombox.org/ https://freedombox.org/ [1] https://yunohost.org/ https://yunohost.org/
- AFNobody 9y agoMy list is similar but I do a UFW setup and move SSH to a non-standard port that is easy to remember (i.e. 12345) to reduce noise in my log files. Is there any particular reason you left firewall setup off?
- Sir_Cmpwn 9y agoI don't think firewall is terribly important. I know it's kind of against the grain, probably best to do it if you don't understand the consequences.
- entelechy0 9y agoMy go to: http://www.codelitt.com/blog/my-first-10-minutes-on-a-server-primer-for-securing-ubuntu/ http://www.codelitt.com/blog/my-first-10-minutes-on-a-server...
- jlgaddis 9y agoIs that the entire chapter? Seems a little... "thin", I suppose.
- jimmies 9y agoI am so glad nowadays to get websites for my hobby projects going, I just have to do a Github page, and don't have to worry about all that stuff (and don't have to pay, either). Github pages + Static content generators are among the best advancements in the recent years.
- throwawayReply 9y agoBack in the day we used to call that "Shared hosting" and it was looked down on by the in-crowd.
- dspillett 9y agoIn my experience shared hosting was looked down upon (and still is) not because we were high-and-mighty better-than-thou you-know-nothing toffee-nosed snobs about the entire idea[1], but because of the many (the majority?) of hosts who were absolutely terrible at security (and stability, and performance both generally & through silly levels of over-selling, and everything else, but security is most important). In this case the hosting is by a company with the technical skills and infrastructure to properly secure and support the service, not some inexperienced kid living with his parents who thinks a simple cPanel installation (that never gets updated for some reason he doesn't notice or can't be bothered to diagnose) is a great almost-zero-effort way to sell hosting to make a bit of extra pocket money over the school/college/other holidays. Also the lack of control made using certain things impossible, you were usually held back on an old version of mySQL & PHP, and little else to if you wanted to use postgres or python or anything other you were stuck. That is the same here of course: this probably gives you even less control because it is not trying to be shared hosting it is a hosting-platform-as-a-service. [1] I may actually be a high-and-mighty better-than-thou you-know-nothing toffee-nosed snob, but that is beside the point here!
- jimmies 9y agoYears ago someone I used to know ;-) used to upload php scripts to traverse the ".." dir to shared hosts. You can do that with 9 out of 10 smaller shared hosts. It was hillarious. There is a whole lot less of attack surface when it comes to static content generators.
- sonaltr 9y agoOne of the things that I'm super happy about is that for basic stuff I don't need to manage servers (static sites / web apps hosted on S3 etc., FaaS for basic Code) and when I do need to have full on servers, I can use something like GKE/EKS/AKE to just deploy containers and not manage the underlying infrastructure. It's super awesome when working on personal projects! (although in a way I did enjoy doing all that in the first place)
- holri 9y agoThe old advice to have separate machines for isolation is still valid in spectre and meltdown times.
- HankB99 9y agoA minor nit, I suppose. Formatting of cli commands has mangled them to the point they cannot be used. For example # dpkg — list will not work. The correct command is dpkg --list I suppose I'm particularly sensitive to this because I ran into a problem copying some commands from a terminal window into a Google Document and then copying/pasting them back to the command line. Google Docs had changed some of the spaces to something that looked like a space (both in the doc and in the shell) but was not and caused inexplicable error messages. Anyway... I prefer stuff where I can copy/past directly to a terminal window and have it work as the author expected.
- snowwrestler 9y agoHere are the basics of users and groups! And now, here's containerization and complicated awk commands! I get that it's Chapter 9 in a book, so there is missing context. But I'm also wondering why users and groups seem to be getting intro'd in Chapter 9. And why the author thinks that a person who is learning about users and groups is in any position to consider containers.
- frabbit 9y agoIn case anyone else was wondering: "Shipyard" is a mothballed Docker compose project https://github.com/shipyard/shipyard https://github.com/shipyard/shipyard
- frabbit 9y agoMeh, sorry. I meant this as a reply to a comment downthread which referenced https://www.codelitt.com/blog/my-first-10-minutes-on-a-server-primer-for-securing-ubuntu/ https://www.codelitt.com/blog/my-first-10-minutes-on-a-serve...