Showing posts with label mtree. Show all posts
Showing posts with label mtree. Show all posts

Tuesday, May 24, 2011

Compromised Server Security Measures

Recently, my employer's web server hosted on Rackspace Cloud was compromised (yes I still have a day job), and I helped resolve the issue, consequently formulating some security measures which I hope to impart today wishing you won't have to go through the upheavels we had. You may also learn more on this from Linux Server Security and Secure Architectures with OpenBSD.

From the experience we had at work, here are some of the measures I would advocate (some advise you may have encountered somewhere else):
  • Isolate access to the compromised server
  • Secure the workstation that solely accesses the server
  • For web application scripts, have trusted copy in version control systems
  • Your .htaccess may be the culprit
  • Setup routine file change monitor
As our modus operandi goes, below are the rationale and discussion of the measures above.