SkyHorse.Org

Security by Obscurity

I will include here the necessary steps to remove all version information from named, exim, apache and cppop.

Some recommended actions:

1)Change the default port for SSH. Ideally you should have as litle shell users as possible, so it is not an inconvenient to advise whoever uses it to use a different non-standard port.
On a regular day, even with pro-active firewalling, you will have hundreds of attempts to connect to SSH. Serious. This is how you do it:

ACTION

sudo pico -w /etc/ssh/sshd_config

You’ll probably see this:

#Port 22

Change this to:

Port 12345

Or whatever port number you like, keeping in mind not to use any other standard port for other services (I recommend anything between 9999 and 49151)

While you’re at it, remove ssh version 1 from usage:

Protocol 2

You can also only listen on certain IP addresses and there are plenty of other options here, play around.

Now you need to close port 22 on your firewall and open your new port up:

sudo pico -w /etc/apf/conf.apf

Look for your line looking like this one:

IG_TCP_CPORTS=”20,21,25,26,53,80,110,143,443….”

and remove 22 and add your new port.

After you finish, just do:

apf –restart
service sshd restart

Before you logoff, you better ensure your configuration is working:

ssh -2 -l username -p newPortNumber yourhost.com

Now, you might want to change your local SSH client options to set the new port number and protocol, just so you don’t have to do that all the time. Under linux, this can easily be done by editing, this time on your local computer, the same ssh_config file:

sudo pico -w /etc/ssh/ssh_config

Add these lines:

Host yourdomain.com
Port 12345 (your port number)
Protocol 2

Thats it!

Related posts:

  • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
  • A2DP aka Stereo Bluetooth on Mac OS X: finally an easy and quality solution
  • Free SMS’s - Hacked software circulates on the net
  • Tags

    AI apple behavioural-targeting business christianity Computing cPanel design DNS Downloads Games GNU/Linux google hacking Hardware headphones hosting Ideas Instant Messaging iphone islam marketing online-advertising online media Personal Philosophy poker Programming satire scripts search Security sociology startups technology Travel ubuntu v-moda Visionarism web-2.0 web-marketing Web Design WHM wunderloop
  • Pages

    • About
    • Web Server Administration
      • Auto update modsecurity rules - modsec.sh
      • DirectAdmin to cPanel : a partial BASH solution
      • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
        • Configuring E-mail (Exim) related areas
        • Fixing open DNS servers
        • Monitoring your server
        • Scripts and misc information
        • Security by Obscurity
        • Tweaking apache web server
  • Twitter Updates

    • Ads

    • RSS NMA

      • MailOnline sees site traffic grow 18% during October 20 November, 2008
      • WPP's Sorrell looks to emerging countries for growth 20 November, 2008
      • The Guardian pushes Barnardo's via full-page HD video ads 20 November, 2008
    • RSS Brand Republic

      • ABCe figures show UK increases lag behind global growth 20 November, 2008
      • Guardian website breaks 25-million user barrier 20 November, 2008
      • ITV free of CRR disputes reveals half-year report 20 November, 2008
    • RSS iMedia Connection: Consumer Strategies

      • 5 brands that gave 'em something to talk about
      • Social networking: Where it's headed
      • 5 ways to bring targeting to another channel
    • RSS Behavioural Targeting news

      • Behavioral Targeting In Context - Mediapost.com 19 November, 2008
      • Behavioral targeting and video search marketing with AlmondNet - ReelSEO Online Video News 18 November, 2008
      • Web Analytics Association Announces Upcoming December Webcast: "5 ... - MarketWatch 19 November, 2008
      • New privacy group to shape policy - BBC News 20 November, 2008
      • Integrating Behavioral Into TV, Web, and Mobile Campaigns - ClickZ News 19 November, 2008
    • RSS Adotas

      • How Google Is Jeopardizing Search Biz 19 November, 2008
      • New Yahoo CEO Must Be Willing To Do Microsoft Deal 19 November, 2008
      • Trulia, Placecast Partner on Geo-Targeted Ads 19 November, 2008
    • RSS MarketingVox

      • 1/5 of Marketers Send Emails After Users Unsubscribe
      • Google, P&G Conduct Labor-Swap
      • MSFT to Pass on YHOO — But Search Might Do, Ballmer Says
    • RSS SimsCity blog

      • Scalability 8 July, 2008
      • A message to Mac users 5 July, 2008
      • Transfering files from computer to iPhone 26 June, 2008
    • RSS Donald Hamilton

      • Online ad spending bucks trends 29 September, 2008
      • Ad:Tech 25 September, 2008
      • Phorm in the clear? 18 September, 2008
    • RSS Don't be Square

      • x 11 September, 2008
      • See no evil with TELEVISION 18 August, 2008
      • Science meets Culture = PHILOTAXIS 14 August, 2008
    • Ads

    • RSS mindcode

      • On Patterns… 20 November, 2008
      • Just a shrimp… 16 November, 2008
      • Another Quote of the Day 15 November, 2008
    • RSS ZDnet Security

      • iPhone vs. Android development: Day 1 18 November, 2008
      • Making Man As Super As His Computer 17 November, 2008
      • Is Sonatype a harbinger of the future? 14 November, 2008
    • TechDispenser


    • Blogroll

      • 90kts
      • Acxiom Poker Nights
      • Amy’s blog
      • Bytter’s blog
      • morena flor no samba da saudade
      • Not Quite There Yet
      • Swedish Pirate Party
    • Cartoons

      • Geek & Poke
      • Order of the Stick
      • User Friendly
    • Gaming

      • Neverwinter Nights
    • online media

      • Knowledge for the Digital Economy
      • Mike on Ads
    • Personal

      • Atelier de Camisa
      • Banksy
      • Designarte
      • My Amazon Wishlist
      • SkyServers.Org
    • Science

      • Hermetic Research
      • New Scientist
      • Rex Research
      • ScienceBox
      • Wired
    • Security

      • GPG4Win
      • GPGol
      • GPGShell
      • Mod Security
      • Offline Windows NT(2k,XP) Password Recovery
    • Web Design

      • PageStrength
      • SiteScore
      • UrlTrends
    • Akismet

      33,361 spam comments
      blocked by
      Akismet

    © 2003 - 2008 Paulo Cunha | SkyHorse.Org is proudly powered by WordPress | Theme based on Bob