SkyHorse.Org

Security by Obscurity

I will include here the necessary steps to remove all version information from named, exim, apache and cppop.

Some recommended actions:

1)Change the default port for SSH. Ideally you should have as litle shell users as possible, so it is not an inconvenient to advise whoever uses it to use a different non-standard port.
On a regular day, even with pro-active firewalling, you will have hundreds of attempts to connect to SSH. Serious. This is how you do it:

ACTION

sudo pico -w /etc/ssh/sshd_config

You’ll probably see this:

#Port 22

Change this to:

Port 12345

Or whatever port number you like, keeping in mind not to use any other standard port for other services (I recommend anything between 9999 and 49151)

While you’re at it, remove ssh version 1 from usage:

Protocol 2

You can also only listen on certain IP addresses and there are plenty of other options here, play around.

Now you need to close port 22 on your firewall and open your new port up:

sudo pico -w /etc/apf/conf.apf

Look for your line looking like this one:

IG_TCP_CPORTS=”20,21,25,26,53,80,110,143,443….”

and remove 22 and add your new port.

After you finish, just do:

apf –restart
service sshd restart

Before you logoff, you better ensure your configuration is working:

ssh -2 -l username -p newPortNumber yourhost.com

Now, you might want to change your local SSH client options to set the new port number and protocol, just so you don’t have to do that all the time. Under linux, this can easily be done by editing, this time on your local computer, the same ssh_config file:

sudo pico -w /etc/ssh/ssh_config

Add these lines:

Host yourdomain.com
Port 12345 (your port number)
Protocol 2

Thats it!

Related posts:

  • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
  • A2DP aka Stereo Bluetooth on Mac OS X: finally an easy and quality solution
  • Free SMS’s – Hacked software circulates on the net
  • Tags

    AI apple behavioural-targeting business christianity Computing cPanel deep packet inspection design Downloads Games GNU/Linux google hacking hacking Hardware headphones hosting Ideas Instant Messaging iphone marketing mod-security online-advertising online media Personal Philosophy phorm poker Programming satire scripts Security sociology startups technology Travel ubuntu v-moda Visionarism web-2.0 web-marketing Web Design WHM wunderloop
  • Pages

    • About
    • Web Server Administration
      • Auto update modsecurity rules – modsec.sh
      • DirectAdmin to cPanel : a partial BASH solution
      • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
        • Configuring E-mail (Exim) related areas
        • Fixing open DNS servers
        • Monitoring your server
        • Scripts and misc information
        • Security by Obscurity
        • Tweaking apache web server
  • Twitter Updates

    • Ads

    • RSS NMA

      • Common currency an impossible dream, says Mindshare 12 March, 2010
      • Twitter lets users add their location to their tweets 12 March, 2010
      • Social media is a challenge for brands to measure 12 March, 2010
    • RSS Brand Republic

      • TAG Heuer launches augmented reality demo 12 March, 2010
      • Nivea adopts umbrella positioning for female products 12 March, 2010
      • Guinness digital campaign aims to gather grins 12 March, 2010
    • RSS iMedia Connection: Consumer Strategies

      • The 4 Cs of scaling social media
      • The underlying drivers of social media success
      • How to turn user-generated content into profits
    • RSS Behavioural Targeting news

      • Who Owns The Privacy? - Mediapost.com 12 March, 2010
      • Why behavioural targeting is not the be all and end all - Econsultancy (blog) 12 March, 2010
      • When Behavioral Targeting Identifies A New Audience Segment - Mediapost.com 10 March, 2010
      • Go, and Target No More? - ClickZ News 10 March, 2010
      • 5 Digital Truisms for Marketers - Adweek 8 March, 2010
    • RSS Adotas

      • Twitter Knows Where I Am; Gulp 12 March, 2010
      • WWN Has a Stopwatch on Ad Visibility 12 March, 2010
      • Jumptap Offers Self Service Lane 12 March, 2010
    • RSS MarketingVox

      • With or Without the FTC, the Mobile Ad Market Will Be Unrecognizable in Five Years 12 March, 2010
      • Google Throws Retail Inventory into the Local Mix 12 March, 2010
      • San Francisco's BART Adds Augmented Reality 12 March, 2010
    • RSS ExchangeWire.com

      • How Online Advertising Really Works In Europe; Real-Time Bidding Best Practices Whitepaper 12 March, 2010
      • Paul Turner Talks Buy-Side Platforms, Automated Ad Trading And The Evolution Of European Display 11 March, 2010
      • Rubicon And AOL Deal Increases European Reach Of Yield Optimiser; Unanimis Using Alenty To Improve Ad Visibility And Engagement 10 March, 2010
    • RSS SimsCity blog

      • Attaching pixels to pages 2 January, 2009
      • Frequency capping 28 December, 2008
      • ITV player 27 December, 2008
    • RSS Donald Hamilton

      • Never a True Word said with an “F” 1 December, 2009
      • Whose audience is it anyway? 19 October, 2009
      • Online ad spending bucks trends 29 September, 2008
    • RSS Segmentacion por comportamiento

      • La “Santa Alianza” contra Google. 18 February, 2010
      • Torsten Ahlers, CEO de wunderloop, en el OMExpo2010 26 January, 2010
      • Lanzamiento de la Alianza de editores en Alemania, con la tecnología de wunderloop como motor. 26 January, 2010
    • RSS Sandlines

      • the iPad and Marketing 28 January, 2010
      • The anticipation of disappointment 7 December, 2009
      • Groundhog Day 27 November, 2009
    • RSS ladig.net

      • DMEXCO Premiere war erfolgreich / Topthema Targeting 6 October, 2009
      • Mit „Behavioral“ den optimalen Werbe-Weg finden 8 May, 2009
      • Mit ToDo und Toodledo das Chaos beherschen 6 May, 2009
    • Ads

    • Blogroll

      • 90kts
      • Acxiom Poker Nights
      • Amy’s blog
      • Bytter’s blog
      • morena flor no samba da saudade
      • Not Quite There Yet
      • Swedish Pirate Party
    • Cartoons

      • Geek & Poke
      • Order of the Stick
      • User Friendly
    • Gaming

      • Neverwinter Nights
    • online media

      • Knowledge for the Digital Economy
      • Mike on Ads
    • Personal

      • Atelier de Camisa
      • Banksy
      • Designarte
      • My Amazon Wishlist
      • SkyServers.Org
    • Science

      • New Scientist
      • Rex Research
      • ScienceBox
      • Wired
    • Security

      • GPG4Win
      • GPGol
      • GPGShell
      • Mod Security
      • Offline Windows NT(2k,XP) Password Recovery
    • Web Design

      • PageStrength
      • SiteScore
      • UrlTrends
    • Akismet

      51,338 spam comments
      blocked by
      Akismet
    • Meta

      • Log in
      • Entries RSS
      • Comments RSS
      • WordPress.org

    © 2003 - 2010 Paulo Cunha | SkyHorse.Org is proudly powered by WordPress | Theme based on Bob