Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
first time security configuration for webserver
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
InsaneHamster
Guru
Guru


Joined: 02 May 2003
Posts: 435

PostPosted: Thu Feb 23, 2006 12:49 am    Post subject: first time security configuration for webserver Reply with quote

hi im first time configuring a server
i want to log EVERYTHING cause im on a little kids chat site and the basterds hate me and always attempt to hack me

so im just wondering whats the best way to go about it

iptables for one ?
then like mysql apache2 and those online snort scanners in php for two?

anything else

im a n00b clearly and i want to make sure its as secure as possible

at this point i will use a mail client (right now i got ssmtp gentoo)

and this mail client will send all messages to my blackberry
what would u recommend as the best mail client for a webserver with this type of forwarding

thank u
Back to top
View user's profile Send private message
kamagurka
Veteran
Veteran


Joined: 25 Jan 2004
Posts: 1026
Location: /germany/munich

PostPosted: Thu Feb 23, 2006 12:11 pm    Post subject: Reply with quote

I would emerge shorewall, which is a nice but powerful frontend to iptables (which is just brainfuck to configure). The default logging is from shorewall is a lot of output, and setting it to verbose (logging everything) would flood the fuck out of your poor blackberry. I still need to see the kiddy who can get past a reasonbly configured iptables on a *nix box, though.
If you want to go all out, look into honeypots and tripwire.
_________________
If you loved me, you'd all kill yourselves today.
--Spider Jerusalem, the Word
Back to top
View user's profile Send private message
InsaneHamster
Guru
Guru


Joined: 02 May 2003
Posts: 435

PostPosted: Thu Feb 23, 2006 2:42 pm    Post subject: Reply with quote

kamagurka wrote:
I would emerge shorewall, which is a nice but powerful frontend to iptables (which is just brainfuck to configure). The default logging is from shorewall is a lot of output, and setting it to verbose (logging everything) would flood the fuck out of your poor blackberry. I still need to see the kiddy who can get past a reasonbly configured iptables on a *nix box, though.
If you want to go all out, look into honeypots and tripwire.


that is an incredible answer

im all over it

thank you my friend

:P
Back to top
View user's profile Send private message
think4urs11
Bodhisattva
Bodhisattva


Joined: 25 Jun 2003
Posts: 6659
Location: above the cloud

PostPosted: Thu Feb 23, 2006 3:28 pm    Post subject: Reply with quote

some starters for your quest

http://httpd.apache.org/docs/2.0/misc/security_tips.html
http://dev.mysql.com/doc/refman/4.1/en/security-guidelines.html
http://www.php.net/manual/en/security.php
http://www.gentoo.org/doc/en/security/security-handbook.xml?full=1#book_part1_chap3
_________________
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Back to top
View user's profile Send private message
InsaneHamster
Guru
Guru


Joined: 02 May 2003
Posts: 435

PostPosted: Thu Feb 23, 2006 3:30 pm    Post subject: Reply with quote

Think4UrS11 wrote:
some starters for your quest

http://httpd.apache.org/docs/2.0/misc/security_tips.html
http://dev.mysql.com/doc/refman/4.1/en/security-guidelines.html
http://www.php.net/manual/en/security.php
http://www.gentoo.org/doc/en/security/security-handbook.xml?full=1#book_part1_chap3


thank you also

cosidering im stuck on shorewall complaining about Policy Match: Not Available and the patches are failing lol
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum