4 ms·
* Disable everything that's not the web server * Turn on the firewall to only allow 80/443 and SSH in case you turn something else on * only use passwordless
by caw 12y ago
* Disable everything that's not the web server
* Turn on the firewall to only allow 80/443 and SSH in case you turn something else on
* only use passwordless SSH
* Use the latest version of (apache | nginx | other web server)
* subscribe to a mailing list for exploits for the software you're using
* Patch monthly, if not sooner for critical bugs