SkyHorse.Org

Security by Obscurity

I will include here the necessary steps to remove all version information from named, exim, apache and cppop.

Some recommended actions:

1)Change the default port for SSH. Ideally you should have as litle shell users as possible, so it is not an inconvenient to advise whoever uses it to use a different non-standard port.
On a regular day, even with pro-active firewalling, you will have hundreds of attempts to connect to SSH. Serious. This is how you do it:

ACTION

sudo pico -w /etc/ssh/sshd_config

You’ll probably see this:

#Port 22

Change this to:

Port 12345

Or whatever port number you like, keeping in mind not to use any other standard port for other services (I recommend anything between 9999 and 49151)

While you’re at it, remove ssh version 1 from usage:

Protocol 2

You can also only listen on certain IP addresses and there are plenty of other options here, play around.

Now you need to close port 22 on your firewall and open your new port up:

sudo pico -w /etc/apf/conf.apf

Look for your line looking like this one:

IG_TCP_CPORTS=”20,21,25,26,53,80,110,143,443….”

and remove 22 and add your new port.

After you finish, just do:

apf –restart
service sshd restart

Before you logoff, you better ensure your configuration is working:

ssh -2 -l username -p newPortNumber yourhost.com

Now, you might want to change your local SSH client options to set the new port number and protocol, just so you don’t have to do that all the time. Under linux, this can easily be done by editing, this time on your local computer, the same ssh_config file:

sudo pico -w /etc/ssh/ssh_config

Add these lines:

Host yourdomain.com
Port 12345 (your port number)
Protocol 2

Thats it!

DeliciousFacebookTwitterLinkedInShare/Bookmark

Related posts:

  • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
  • A2DP aka Stereo Bluetooth on Mac OS X: finally an easy and quality solution
  • Free SMS’s – Hacked software circulates on the net
  • Tags

    advertising AI apple behavioural-targeting business Computing cPanel deep packet inspection Downloads DSP Games GNU/Linux google hacking hacking Hardware headphones hosting Ideas Instant Messaging iphone marketing online-advertising online media Personal Philosophy phorm poker Programming satire scripts Security sociology startups technology Travel ubuntu v-moda Visionarism web-2.0 web-marketing Web Design WHM wunderloop yahoo
  • Pages

    • About
    • Web Server Administration
      • Auto update modsecurity rules – modsec.sh
      • DirectAdmin to cPanel : a partial BASH solution
      • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
        • Configuring E-mail (Exim) related areas
        • Fixing open DNS servers
        • Monitoring your server
        • Scripts and misc information
        • Security by Obscurity
        • Tweaking apache web server
  • Twitter Updates

    • Ads

    • RSS ExchangeWire.com

      • IAB/PwC Digital Ad-Spend Study 2012: UK up 12.5% to Almost £5.5bn 11 April, 2013
      • ‘RTB: UK Takes the Lead’, by Nicolle Pangis, President of Real Media Group 9 April, 2013
      • ‘The Ego-System vs the Eco-System’, By Gareth Holmes, UK Publisher Director, PubMatic 8 April, 2013
    • RSS Lies, Damned Lies…

      • Google launches cloud-based BigQuery service 1 May, 2012
      • Returning to the fold 8 March, 2012
      • Big (Hairy) Data 8 February, 2012
    • RSS iMedia Connection: Consumer Strategies

      • A consumer-driven mindset in a big media package
      • Learn to leverage the social-search connection
      • Your social media disaster kit
    • RSS Segmentacion por comportamiento

      • New Theme: Truly Minimal 11 April, 2013
      • Improved Menus, Autosave, Revision Tracking, and Post Locking, FTW! 11 April, 2013
      • New! Send to Readmill Widget 9 April, 2013
    • RSS Sandlines

      • The Social Phone doesn’t come with an IVR menu 7 November, 2011
      • Are you ready for Big Data? 2 November, 2011
      • Sandlines @ Mediapro 29 October, 2011
    • RSS Adotas

      • Geek Charming: How Agencies Can Attract Digital Talent 11 April, 2013
      • Meet Arnie the Beer Machine 11 April, 2013
      • A Time to Be Reborn: 6 Steps to Bring Time Inc. Back from the Brink 11 April, 2013
    • RSS NMA

    • RSS Brand Republic

      • TeamRock reveals new senior management team 12 April, 2013
      • Cake appoints Leroyson Figueira as creative director 12 April, 2013
      • ITV to unveil next wave of idents: watch the videos 12 April, 2013
    • RSS MarketingVox

      • Cookie Doom Already Appearing in Data | ComScore Shames Ad Clutterers | Global Adspend in Doldrums as Dog Bites Man 11 April, 2013
    • RSS Behavioural Targeting news

      • WEBORAMA : 5% growth in consolidated revenue for Q1 2013 - 4-traders (press release) 12 April, 2013
      • Mobile location-based advertising will be worth € 6.5 billion in 2017 - GoMo News 11 April, 2013
      • Digital media and junk food advertising - Crikey (blog) 11 April, 2013
      • New App Lets Mobile Users Opt Out Of Behavioral Targeting - MediaPost Communications 11 April, 2013
      • Businesses, advertise better! Follow your customers' tracks with with ENGINE 212 - LubbockOnline.com 11 April, 2013
    • Ads

    • Blogroll

      • 90kts
      • Acxiom Poker Nights
      • Amy’s blog
      • Bytter’s blog
      • Impare Arquitectura
      • Impare Design
      • morena flor no samba da saudade
      • Not Quite There Yet
      • Swedish Pirate Party
    • Cartoons

      • Geek & Poke
      • Order of the Stick
      • User Friendly
    • Gaming

      • Neverwinter Nights
    • online media

      • Knowledge for the Digital Economy
      • Mike on Ads
    • Personal

      • Banksy
      • Designarte
      • Made to measure shirts – Atelier de Camisa
      • My Amazon Wishlist
      • SkyServers.Org
    • Science

      • New Scientist
      • Rex Research
      • ScienceBox
      • Wired
    • Security

      • GPG4Win
      • GPGol
      • GPGShell
      • Mod Security
      • Offline Windows NT(2k,XP) Password Recovery
    • Web Design

      • PageStrength
      • SiteScore
      • UrlTrends
    • Meta

      • Log in
      • Entries RSS
      • Comments RSS
      • WordPress.org

    © 2003 - 2011 Paulo Cunha | SkyHorse.Org is proudly powered by WordPress | Theme based on Bob