Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Server Security

Discussion in 'Security' started by Audiopro, Apr 12, 2014.

  1. Audiopro

    Audiopro Active Member

    Joined:
    Feb 15, 2014
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    I was quite surprised to see that my VPS was delivered with some security issues unresolved, is it normal for them to be delivered this way?
    I have closed a lot of the obvious holes but security advisor reports that there are still some outstanding issues.
    Which of the following security alerts should be dealt with urgently and which, if any can I ignore or is it a case of, if they appear in the list they must be dealt with as soon as?

    Apache vhosts are not segmented or chroot()ed.

    ClamAV is not installed.

    Frontpage is installed

    Current kernel version is out of date. current: 2.6.32-358.14.1.el6, expected: 2.6.32-431.11.2.el6

    SSH password authentication is enabled.

    SSH direct root logins are permitted.

    Outbound SMTP connections are unrestricted.
     
  2. pauloray

    pauloray Well-Known Member

    Joined:
    Jan 16, 2012
    Messages:
    74
    Likes Received:
    0
    Trophy Points:
    56
    Location:
    Philippines
    cPanel Access Level:
    Root Administrator
    Is this a new Unmanaged VPS?

    Usually, VPS providers will just install the OS and Control Panel and you take care of the rest.

    You can also use CSF with your Cpanel, it's a good firewall.
     
  3. Audiopro

    Audiopro Active Member

    Joined:
    Feb 15, 2014
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    Thanks for the reply, yes it is unmanaged.
    CSF is not installed, is that something I can install myself or does the ISP have to do that for me?
     
  4. PenguinInternet

    PenguinInternet Well-Known Member
    PartnerNOC

    Joined:
    Jun 20, 2007
    Messages:
    178
    Likes Received:
    13
    Trophy Points:
    68
    Location:
    Cardiff, UK
    cPanel Access Level:
    DataCenter Provider
    Twitter:
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  5. Audiopro

    Audiopro Active Member

    Joined:
    Feb 15, 2014
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    Thanks - I will look into that tomorrow when the beer has worn off.
    I am sure I will get my head round all this eventually and the journey is made easier with the help from you guys.
     
  6. cPanelMichael

    cPanelMichael Technical Support Community Manager
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    45,442
    Likes Received:
    1,961
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hello :)

    To answer your question, it's not out of the ordinary for a VPS provider to setup your server from a template. This may result in an older kernel version, and require you to make some changes to the server in order to increase the security. Let us know if you have any questions about the specific recommendations listed on the Security Advisor.

    Thank you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. Audiopro

    Audiopro Active Member

    Joined:
    Feb 15, 2014
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    Do you recommend I carry out all the changes highlighted by security advisor or are some of them not required?
     
  8. cPanelMichael

    cPanelMichael Technical Support Community Manager
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    45,442
    Likes Received:
    1,961
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Twitter:
    Yes, personally I would follow the recommendations and implement the changes. However, you may need to review the suggested changes and see if it works for your particular environment, or consider alternatives if necessary.

    Thank you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice