Not sure what I am missing here and I have been following the conversation but sure I need some help,
I used the security advisor to check my VPS and I found the following issues,
Apache vhosts are not segmented or chroot()ed.
Enable “Jail Apache” in the “Tweak Settings” area, and change users to jailshell in the “Manage Shell Access” area. Consider a more robust solution by using “CageFS on CloudLinux”. Note that this may break the ability to access mailman via Apache.
SSH password authentication is enabled.
Disable SSH password authentication in the “SSH Password Authorization Tweak” area
SSH direct root logins are permitted.
Manually edit /etc/ssh/sshd_config and change PermitRootLogin to “without-password” or “no”, then restart SSH in the “Restart SSH” area
1. The Jail Apache option is not available to me (am pretty sure am missing something here),
2. SSH Password authentication -> I keep on changing it to off and later on it comes back on, I have researched the web and pretty much could not find anything,
3. SSH direct root logins, I have been changing that and pass the advisor's checks but then it goes right back to on, not sure why this is happening I can't find any info,
Is there any way I could possibly get some help from you guys? Is there anything else I can check to figure out why the SSH stuff defaults to vulnerable settings rather than staying where I set them?
Thanks much for your time.
I used the security advisor to check my VPS and I found the following issues,
Apache vhosts are not segmented or chroot()ed.
Enable “Jail Apache” in the “Tweak Settings” area, and change users to jailshell in the “Manage Shell Access” area. Consider a more robust solution by using “CageFS on CloudLinux”. Note that this may break the ability to access mailman via Apache.
SSH password authentication is enabled.
Disable SSH password authentication in the “SSH Password Authorization Tweak” area
SSH direct root logins are permitted.
Manually edit /etc/ssh/sshd_config and change PermitRootLogin to “without-password” or “no”, then restart SSH in the “Restart SSH” area
1. The Jail Apache option is not available to me (am pretty sure am missing something here),
2. SSH Password authentication -> I keep on changing it to off and later on it comes back on, I have researched the web and pretty much could not find anything,
3. SSH direct root logins, I have been changing that and pass the advisor's checks but then it goes right back to on, not sure why this is happening I can't find any info,
Is there any way I could possibly get some help from you guys? Is there anything else I can check to figure out why the SSH stuff defaults to vulnerable settings rather than staying where I set them?
Thanks much for your time.
Last edited by a moderator: