Türkce » WHM cPanel

Security & Firewall - csf v2.91 de Check Server Security cikan Hatalari Nasil Düzeltiriz

http://forum.whmdestek.com/

Go Back   WHM/cPanel Support Platform » Türkce » WHM cPanel
 

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 15.11.07, 01:14
Athlon
 
Join Date: Sep 2007
Posts: 134
Rep Power: 3
prowas is on a distinguished road
Security & Firewall - csf v2.91 de Check Server Security cikan Hatalari Nasil Düzeltiriz

Security & Firewall - csf v2.91 de Check Server Security cikan Hatalari Nasil Düzeltiriz
Bende Check Server Security Bastigimda Bu Hatalar cikiyor Bazilarini Düzelttim Ama Bunlari Düzeltemedim + Her Rebootan Sonra Firewall Status: Stopped! [TEST MODE ENABLED]
Ayarlarinda Aktif Etmeme Ragmen Bu Yazilar Degismiyor

Check iptables is configured
WARNING

iptables is not configured. You should install csf and make sure that it is working correctly
---------
Check whether csf is in TESTING mode
WARNING

If the iptables firewall is working set TESTING to "0" in the Firewall Configuration
---------
Check csf LF_IMAPD option
WARNING
This option helps prevent brute force attacks on your server services
---------
Check /dev/shm is mounted noexec,nosuid
WARNING
/dev/shm isn't mounted with the noexec,nosuid options (currently: none). You should consider adding a mountpoint into /etc/fstab for /dev/shm with those options
----------
Check /etc/named.conf for recursion restrictions
WARNING

You have a local DNS server running but do not have any recursion restrictions set in /etc/named.conf. This is a security and performance risk and you should look at restricting recursive lookups to the local IP addresses only
----------
Check SSHv1 is disabled
WARNING

You should disable SSHv1 by editing /etc/ssh/sshd_config and setting:
Protocol 2
----------
Check SSH on non-standard port
WARNING

You might want to consider moving SSH to a non-standard port to avoid basic SSH port scans by editing /etc/ssh/sshd_config and setting:
Port nnnn
Where nnnn is a port of your choosing. Don't forget to open the port in the firewall first!
----------
Check SSH PasswordAuthentication
WARNING

For ultimate SSH security, you might want to consider disabling PasswordAuthentication and only allow access using PubkeyAuthentication. For more information read this article and this article
-----------
Check Background Process Killer
WARNING

You should enable each item in the WHM > Background Process Killer
-----------
Check exim for extended logging
WARNING

You should enable extended exim logging to enable easier tracking potential outgoing spam issues. Add:
log_selector = +arguments +subject
to the first textarea in the Advanced Mode Exim Configuration Editor
-----------
Check server startup for cups
WARNING

On most servers cups isn't needed and should be stopped and disabled from starting, as it could pose a security threat. This service is currently enabled in init and can be disabled using:
service cups stop
chkconfig cups off
-----------
Check server startup for nfslock
WARNING
On most servers nfslock isn't needed and should be stopped and disabled from starting, as it could pose a security threat. This service is currently enabled in init and can be disabled using:
service nfslock stop
chkconfig nfslock off
-----------
Check server startup for rpcidmapd
WARNING
On most servers rpcidmapd isn't needed and should be stopped and disabled from starting, as it could pose a security threat. This service is currently enabled in init and can be disabled using:
service rpcidmapd stop
chkconfig rpcidmapd off,
-----------
Check server startup for anacron
WARNING

On most servers anacron isn't needed and should be stopped and disabled from starting, as it could pose a security threat. This service is currently enabled in init and can be disabled using:
service anacron stop
chkconfig anacron off

-----------

Biraz Uzun Oldu Ama Zamani Olan Arkadas Cevap Yazarsa cok Sevirinim
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2  
Old 15.11.07, 13:59
Tickhi's Avatar
Athlon Dual Core
 
Join Date: Jul 2007
Location: Bulgaria
Posts: 369
Rep Power: 8
Tickhi is just really niceTickhi is just really niceTickhi is just really niceTickhi is just really niceTickhi is just really nice
Send a message via MSN to Tickhi Send a message via Yahoo to Tickhi Send a message via Skype™ to Tickhi
test modu kapicaksin WHMDestek bunu acikladi zaten konunun icinde

service anacron stop
chkconfig anacron off

bu tip uyarilari ssh den yapicaksin yazip enter a basman yeterli
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3  
Old 15.11.07, 14:16
CaLViN's Avatar
Sevgi güctür.
 
Join Date: Apr 2007
Location: Outta nation
Age: 28
Posts: 2,079
Rep Power: 100000
CaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond repute
Mesela sunlar

Quote:
Check server startup for cups
On most servers cups isn't needed and should be stopped and disabled from starting, as it could pose a security threat. This service is currently enabled in init and can be disabled using:
service cups stop
chkconfig cups off
-----------
Check server startup for nfslockOn most servers nfslock isn't needed and should be stopped and disabled from starting, as it could pose a security threat. This service is currently enabled in init and can be disabled using:
service nfslock stop
chkconfig nfslock off
-----------
Check server startup for rpcidmapdOn most servers rpcidmapd isn't needed and should be stopped and disabled from starting, as it could pose a security threat. This service is currently enabled in init and can be disabled using:
service rpcidmapd stop
chkconfig rpcidmapd off,
-----------
Check server startup for anacron
On most servers anacron isn't needed and should be stopped and disabled from starting, as it could pose a security threat. This service is currently enabled in init and can be disabled using:
service anacron stop
chkconfig anacron off

-----------
kalin yazdiklarim komutlardir.
ssh a root olarak girip o komutlari yazmaniz yeterli.
__________________
1.)Lütfen destek talebinde bulunmak icin özel mesaj ile iletisime gecmeyiniz.
2.)Ücretsiz destek almak icin forum sayfalarimizi kullanmaniz ayni sorunu yasayan diger üyelerin cevaplara en kisa sürede ulasabilmesi ve sizlere yardimci olmak isteyen bizlerin ve diger üyelerimizin zaman kazanmalari acisindan cok önemlidir.
3.)Forumlarimizda sorunlarinizi anlatirken mümkün oldugunca cok detay vermeniz en kisa sürede sorununuza cözüm bulmaniz acisindan mühimdir.

Daha cok ögrenmek ve ögretmek dilegiyle..
Sevgiler..
The Platform.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #4  
Old 15.11.07, 22:22
Athlon
 
Join Date: Sep 2007
Posts: 134
Rep Power: 3
prowas is on a distinguished road
Arkadasim Dedigini Yaptim Ama Bu Kodu Girdigimde Digerlerinde OK Diyor Ama
service nfslock stop Bunu Yazdigimda Failed Yazdi :S

Bide Bu Dediginiz Ayarlari Her Reboottan Sonra Yapacakmiyim Yoksa Bunda Sonra Bu Ayarlari Yapmama Gerek Kalmayacak mi ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5  
Old 15.11.07, 22:25
CaLViN's Avatar
Sevgi güctür.
 
Join Date: Apr 2007
Location: Outta nation
Age: 28
Posts: 2,079
Rep Power: 100000
CaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond reputeCaLViN has a reputation beyond repute
sadece bir sefer yapacaksiniz.
__________________
1.)Lütfen destek talebinde bulunmak icin özel mesaj ile iletisime gecmeyiniz.
2.)Ücretsiz destek almak icin forum sayfalarimizi kullanmaniz ayni sorunu yasayan diger üyelerin cevaplara en kisa sürede ulasabilmesi ve sizlere yardimci olmak isteyen bizlerin ve diger üyelerimizin zaman kazanmalari acisindan cok önemlidir.
3.)Forumlarimizda sorunlarinizi anlatirken mümkün oldugunca cok detay vermeniz en kisa sürede sorununuza cözüm bulmaniz acisindan mühimdir.

Daha cok ögrenmek ve ögretmek dilegiyle..
Sevgiler..
The Platform.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6  
Old 20.11.07, 11:59
Celeron
 
Join Date: Aug 2007
Posts: 53
Rep Power: 3
Ptah is on a distinguished road
Check /dev/shm is mounted noexec,nosuid

hatasini nasi düzenliyebilirim ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #7  
Old 21.11.07, 14:45
sinangunay's Avatar
FULL DESTEK SUNUCULAR
 
Join Date: Jul 2007
Location: biLi biLi boP
Age: 29
Posts: 1,706
Rep Power: 1075
sinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond reputesinangunay has a reputation beyond repute
gerekli servisleride kapatmissiniz sanirim sunucu ayarlari komple bozulmus olabilir..
__________________
-----------------------------------------------------------------------------------------
>> LÜTFEN ÜCRETSiZ DESTEK TALEP ETMEK iciN MSN ADRESLERiMiZi EKLEMEYiNiZ. HER TÜRLÜ ÜCRETSiZ DESTEK iciN FORUMLARIMIZI KULLANINIZ. TEsEKKÜRLER <<
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8  
Old 09.01.08, 13:35
Atari
 
Join Date: Jan 2008
Posts: 9
Rep Power: 0
nelson is on a distinguished road
Quote:
Originally Posted by Ptah View Post
Check /dev/shm is mounted noexec,nosuid

hatasini nasi düzenliyebilirim ?
/etc/fstab dosyasini acacaksin

dev/shm yanindaki

Quote:
defaults 0 0
kismini

Quote:
noexec,nosuid 0 0
ile degistireceksin, sonra suncuyu reboot edeceksin, ve o hata csfden kalakcak.

Ancak fstab dosyasi tehlikelidir, bir hata yaparsan server bir daha acilmaz. Ona göre. Sunucu ayarlarinin komple bozuldugunu falan göstermez bu hata her sunucuda bu hatayi verir ayarlanmamissa.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9  
Old 12.02.08, 21:35
diyadin2's Avatar
Atari
 
Join Date: Feb 2008
Posts: 3
Rep Power: 0
diyadin2 is on a distinguished road
Code:
Check exim for extended logging
WARNING
You should enable extended exim logging to enable easier tracking potential outgoing spam issues. Add:
 log_selector = +arguments +subject
to the first textarea in the Advanced Mode Exim Configuration Editor
nano /etc/exim.conf

ctrl+w tuslariyla arama kutusuna asagidakini yaziyoruz

Code:
hostlist auth_relay_hosts = *
buldugumuz bu satirin hemen altina

Code:
 log_selector = +arguments +subject
ekliyoruz

service exim restart
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #10  
Old 03.04.08, 20:56
Sempron
 
Join Date: Apr 2008
Location: izmir
Posts: 34
Rep Power: 0
Yuma is on a distinguished road
Check csf SMTP_BLOCK option WARNING This option will help prevent the most common form of spam abuse on a server that bypasses exim and sends spam directly out through port 25. Enabing this option will prevent any web script from sending out using socket connection, such scripts

Check /dev/shm is mounted noexec,nosuid WARNING /dev/shm isn't mounted with the noexec,nosuid options (currently: none). You should consider adding a mountpoint into /etc/fstab for /dev/shm with those options

Check /etc/named.conf for recursion restrictions WARNING you have a local DNS server running but do not have any recursion restrictions set in /etc/named.conf. This is a security and performance risk and you should look at restricting recursive lookups to the local IP addresses only

Check MySQL version WARNING You are running a legacy version of MySQL (v4.1.22) and should consider upgrading to v5.* as recommended by MySQL

Check SSHv1 is disabled WARNING You should disable SSHv1 by editing /etc/ssh/sshd

Check SSH on non-standard port WARNING You might want to consider moving SSH to a non-standard port to avoid basic SSH port scans by editing /etc/ssh/sshd_config and setting:
Port nnnn

Check SSH on non-standard port WARNING You might want to consider moving SSH to a non-standard port to avoid basic SSH port scans by editing /etc/ssh/sshd_config and setting:
Port nnnn

Check Background Process Killer WARNING You should enable each item in the WHM > Background Process Killer

Check root forwarder WARNING The root account should have a forwarder set so that you receive essential email from your server


Check exim for extended logging WARNING You should enable extended exim logging to enable easier tracking potential outgoing spam issues. Add:
log_selector = +arguments +subject
to the first textarea in the Advanced Mode Exim Configuration Editor

Check apache version WARNING You are running a legacy version of apache (v2.0.63) and should consider upgrading to v2.2.* as recommended by apache

Check suPHP WARNING To reduce the risk of hackers accessing all sites on the server from a compromised PHP web script, you should enable suPHP when you build apache/php. Note that there are sideeffects when enabling suPHP on a server and you should be aware of these before enabling it

Check apache for mod_security WARNING You should install the mod_security apache module during the easyapache build process to help prevent exploitation of vulnerable web scripts, together with a set of SecFilters

Check php for register_globals WARNING You should modify the PHP configuration (usually in /usr/local/lib/php.ini) and set:
register_globals = Off
unless it is absolutely necessary as it is seen as a significant security risk


Check php for disable_functions WARNING You should modify the PHP configuration (usually in /usr/local/lib/php.ini) and disable commonly abused php functions, e.g.:
disable_functions = show_source, system, shell_exec, passthru, exec, phpinfo, popen, proc_open, allow_url_fopen
Some client web scripts may break with some of these functions disabled, so you may have to remove them from this list

Check php for enable_dl WARNING You should modify /usr/local/lib/php.ini and set:
enable_dl = Off
This prevents users from loading php modules that affect everyone on the server. Note that if use dynamic libraries, such as ioncube, you will have to load them directly in the PHP configuration (usually in /usr/local/lib/php.ini)


arkadaslar bu kirmizi uyari verilen degerlerin bu sekilde kalmasinin bir kötü yani varmi var ise nelerdir ve hangi degerleri nasil güvenli hale getirebiliriz.? simdiden yardimci olacak arkadaslara tesekkürlerimi iletirim.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
CSF(ConfigServer Security & Firewall) CaLViN WHM cPanel 114 19.02.10 08:51
ELS - Easy Linux Security script - Server Optimizasyon ve Güvenlik Tickhi WHM cPanel 32 20.01.10 11:45
tweak security [örnek ayarlamalar] emucu WHM cPanel 2 29.08.08 16:44
mod security icin inspration WHM cPanel 1 27.02.08 16:45
Cr@> Server Security Methods 2 CashAsiq WHM cPanel 2 22.08.07 19:23



netinternet

Navigasyon
Menü