VPS Account and Its Security
Written by Naveed Ashraf Friday, 15 February 2013
The VPS hosting at a hosting provider like Arvixe utilize standard safety measure, but they ensure security at network and server levels. Keeping your own VPS portion and the websites hosted on it needs extra attention from your end. The list of some basic rules is written for VPS owners:
- Always use a firewall and only allow your own IP to prevent unauthorized SSH access.
The authentication key files are better instead of using passwords for SSH access
- You can create rules to regret direct root access to your VPS via SSH and instead do setting to ask logins.
- Always close unused ports at your firewall level
- Update operating system and installed software frequently. It is better to subscribe to the security/announcements mailing list for the operating system and installed software (including web applications)
- The PHP and scripts should be up-to-date to disallow any hacking or lacking portion in script. It is most important as even one single leakage in a single script can allow an attacker to compromise not only a single website but all websites present in your VPS, or even to compromise the VPS itself.
- For FTP and client login, use difficult password and wherever possible change password frequently.
- The installation of security tools such as rkhunter (to search for and notify you of a server compromise), mod_security (to help prevent website compromises) or suhosin (to better protect PHP) can help you to secure your VPS.
- The PHP’s safe_mode should not be off globally, if require only turn it off for a particular domain.
- The chmod a file or directory to 777 is not free of harm. Do it only if you really require this permission.
- Regularly analyze your system log for any suspicious activity. Whenever you catch such event inform hosting provider and also take action yourself.
- Keep yourself up to date about coming threads and their remedies. For this you can read online books/websites and can be a part of mailing list of such websites.
- Be conscious if you are accepting un-known customer into your VPS. They might install of use scripts that can compromise their website and in result can affect your VPS too.
Follow these rules for a more secure VPS account
Looking for quality web hosting? Look no further than Arvixe Web Hosting!