How to secure the VPS before install VirtualMin

14 posts / 0 new
Last post
#1 Fri, 03/16/2012 - 06:51
w7u64xi7

How to secure the VPS before install VirtualMin

Hello How to really well secure the VPS before I go for installing the VirtualMin? I am on CentOS 6 32x.

Fri, 03/16/2012 - 09:38
andreychek

Howdy,

Your Linux setup should be secure by default.

There's some details on that here:

http://www.virtualmin.com/documentation/security/faq

Fri, 03/16/2012 - 11:01 (Reply to #2)
w7u64xi7

Thanks a lot, and I will check them in details.

Fri, 03/16/2012 - 14:20
ronald
ronald's picture

Since you will use a PHP based website like Drupal, you may be interested in http://phpsec.org/
This is to secure your box when using php based scripts.
You can download and install on your box and then run the script. It will show you the weaknesses so you can repair them.

Fri, 03/16/2012 - 14:43 (Reply to #4)
w7u64xi7

Is it to be installed before or after Drupal?

Fri, 03/16/2012 - 21:06 (Reply to #5)
Locutus

It would appear this phpsec website has not been updates in 5 years?

Sat, 03/17/2012 - 03:12
ronald
ronald's picture

Ah, i was referring to this tool http://phpsec.org/projects/phpsecinfo/
It can give insights to improvements on the server.
I would upload the script after creating a domain on the box and run it in its environment.

to see a live example http://izihost.eu/phpsec/

Sat, 03/17/2012 - 05:07
Locutus

Looks quite nice, but also this script has not been updated in 5 years... You sure it still covers current-day security needs? :)

If there is any more-up-to-date alternative for this, please let me know! I'm quite interested in that.

Sat, 03/17/2012 - 05:29
ronald
ronald's picture

I have found a newer version here (0.3) it was updated last month
http://phpsec.xqus.com/download

Sat, 03/17/2012 - 11:17
Locutus

Aah, very nice, thanks!

Sat, 03/17/2012 - 11:44 (Reply to #10)
w7u64xi7

How to install it?

Sat, 03/17/2012 - 12:00
Locutus

Haven't tested it yet.

Sat, 03/17/2012 - 12:01
w7u64xi7

Please if any one knows to tell :)

Sun, 03/18/2012 - 06:21
ronald
ronald's picture

Here is the manual
http://phpseclib.com/manual

Topic locked