SkyHorse.Org

Security by Obscurity

I will include here the necessary steps to remove all version information from named, exim, apache and cppop.

Some recommended actions:

1)Change the default port for SSH. Ideally you should have as litle shell users as possible, so it is not an inconvenient to advise whoever uses it to use a different non-standard port.
On a regular day, even with pro-active firewalling, you will have hundreds of attempts to connect to SSH. Serious. This is how you do it:

ACTION

sudo pico -w /etc/ssh/sshd_config

You’ll probably see this:

#Port 22

Change this to:

Port 12345

Or whatever port number you like, keeping in mind not to use any other standard port for other services (I recommend anything between 9999 and 49151)

While you’re at it, remove ssh version 1 from usage:

Protocol 2

You can also only listen on certain IP addresses and there are plenty of other options here, play around.

Now you need to close port 22 on your firewall and open your new port up:

sudo pico -w /etc/apf/conf.apf

Look for your line looking like this one:

IG_TCP_CPORTS=”20,21,25,26,53,80,110,143,443….”

and remove 22 and add your new port.

After you finish, just do:

apf –restart
service sshd restart

Before you logoff, you better ensure your configuration is working:

ssh -2 -l username -p newPortNumber yourhost.com

Now, you might want to change your local SSH client options to set the new port number and protocol, just so you don’t have to do that all the time. Under linux, this can easily be done by editing, this time on your local computer, the same ssh_config file:

sudo pico -w /etc/ssh/ssh_config

Add these lines:

Host yourdomain.com
Port 12345 (your port number)
Protocol 2

Thats it!

DeliciousFacebookTwitterLinkedInShare/Bookmark

Related posts:

  • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
  • A2DP aka Stereo Bluetooth on Mac OS X: finally an easy and quality solution
  • Free SMS’s – Hacked software circulates on the net
  • Tags

    advertising AI apple behavioural-targeting business Computing cPanel deep packet inspection Downloads DSP Games GNU/Linux google hacking hacking Hardware headphones hosting Ideas Instant Messaging iphone marketing online-advertising online media Personal Philosophy phorm poker Programming satire scripts Security sociology startups technology Travel ubuntu v-moda Visionarism web-2.0 web-marketing Web Design WHM wunderloop yahoo
  • Pages

    • About
    • Web Server Administration
      • Auto update modsecurity rules – modsec.sh
      • DirectAdmin to cPanel : a partial BASH solution
      • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
        • Configuring E-mail (Exim) related areas
        • Fixing open DNS servers
        • Monitoring your server
        • Scripts and misc information
        • Security by Obscurity
        • Tweaking apache web server
  • Twitter Updates

    • Ads

    • RSS ExchangeWire.com

      • Looking Beyond The Gadget Porn, What Were The Key Takeaways From This Year’s CES For Ad Tech? 27 January, 2012
      • AppNexus CEO, Brian O’Kelley, And Brian Lesser, CEO, Xaxis, Confirmed To Speak At Ad Trader Conference, Hamburg, On April 19 27 January, 2012
      • The PostView: Are Facebook And Amazon About To Disrupt The Multi-Billion Euro/Dollar Traditional Display Model? 26 January, 2012
    • RSS Lies, Damned Lies…

      • Building the Perfect Display Ad Performance Dashboard, Part II – metrics 20 December, 2011
      • Should Wikipedia accept advertising? 21 November, 2011
      • Building the Perfect Display Ad Performance Dashboard, Part I – creating a measurement framework 9 November, 2011
    • RSS iMedia Connection: Consumer Strategies

      • A consumer-driven mindset in a big media package
      • Learn to leverage the social-search connection
      • Your social media disaster kit
    • RSS Segmentacion por comportamiento

      • Chrome Users: Try the WordPress.com Extension 27 January, 2012
      • Your Stats Have a New Home 26 January, 2012
      • Reblogging is Back! 22 January, 2012
    • RSS Sandlines

      • The Social Phone doesn’t come with an IVR menu 7 November, 2011
      • Are you ready for Big Data? 2 November, 2011
      • Sandlines @ Mediapro 29 October, 2011
    • RSS Adotas

      • Sponsormob Leads the Way Into RTB for Mobile 27 January, 2012
      • Clearstream Rolls Out Verification for Online Video Ads 27 January, 2012
      • Study: How Do Marketers Define Social Media ROI? 27 January, 2012
    • RSS NMA

      • Twitter embroiled in censorship row 27 January, 2012
      • Security fears lead O2 to exceed tweet limit 27 January, 2012
      • Facebook urges clearer understanding of social commerce 26 January, 2012
    • RSS Brand Republic

      • Eurostar to appoint AMV BBDO to pan-European advertising 27 January, 2012
      • Telegraph prepares for London 2012 adspend lift with Allen appointment 27 January, 2012
      • Ireland's Out of Home sector drops 5% to total €194.6m in 2011 27 January, 2012
    • RSS MarketingVox

      • Closing Bell: FBI plans social map app | Facebook IPO | Twitter censorship 27 January, 2012
      • MovenBank Moves Industry Closer to Social Media Credit Scoring 27 January, 2012
      • Google+ May Be Wasting Its Time on the Teen Market 27 January, 2012
    • RSS Behavioural Targeting news

      • Changing people's behavior: From reducing bullying to training scientists - EurekAlert (press release) 27 January, 2012
      • Videology Partners with I-Behavior and Kantar Shopcom to Extend CPG Purchase ... - MarketWatch (press release) 26 January, 2012
      • Channel 4's 'Richard Wilson On Hold' - I don't believe it… - The Drum 26 January, 2012
      • Advertisers to police themselves when targeting online users - Toronto Star 25 January, 2012
      • Digital Advertising Alliance Promotes Your Ad Choices Campaign - brandchannel.com 23 January, 2012
    • Ads

    • Blogroll

      • 90kts
      • Acxiom Poker Nights
      • Amy’s blog
      • Bytter’s blog
      • Impare Arquitectura
      • Impare Design
      • morena flor no samba da saudade
      • Not Quite There Yet
      • Swedish Pirate Party
    • Cartoons

      • Geek & Poke
      • Order of the Stick
      • User Friendly
    • Gaming

      • Neverwinter Nights
    • online media

      • Knowledge for the Digital Economy
      • Mike on Ads
    • Personal

      • Banksy
      • Designarte
      • Made to measure shirts – Atelier de Camisa
      • My Amazon Wishlist
      • SkyServers.Org
    • Science

      • New Scientist
      • Rex Research
      • ScienceBox
      • Wired
    • Security

      • GPG4Win
      • GPGol
      • GPGShell
      • Mod Security
      • Offline Windows NT(2k,XP) Password Recovery
    • Web Design

      • PageStrength
      • SiteScore
      • UrlTrends
    • Akismet

      99,726 spam comments blocked by
      Akismet
    • Meta

      • Log in
      • Entries RSS
      • Comments RSS
      • WordPress.org

    © 2003 - 2011 Paulo Cunha | SkyHorse.Org is proudly powered by WordPress | Theme based on Bob