Server Rebuild


Recommended Posts

I run a Linux Debian Lenny server (even though it's in testing it was stable for me). Anyway i have decided i want to nuke it and redo the whole os install etc, as my servers full of usless crap that needs a cleanout etc.

Well anyway i was thinking of going right back to debian. unless someone can convince me otherwise.

The server is my home file server, home web testing server etc, and it's open to the web.

Things i do run on it are:

Apache, mysql5, php5, pureftp, samba, webmin, gnump3d, fireflymediaserver, ssh with no direct root login.

Anyway i am looking for something that will be secure and stable.

I am looking for a nice secure firewall maybe thats easy to understand, ability to support raid etc. I just need an overall secure kernel as well.

Link to comment
https://www.neowin.net/forum/topic/619796-server-rebuild/
Share on other sites

whatever you do is never enough and its advisable to take security measures in steps. I would suggest you the following.

1) http://www.rfxnetworks.com/apf.php http://www.rfxnetworks.com/sim.php http://www.rfxnetworks.com/proj.php

2) recompile your kernel with http://www.grsecurity.net/ ( V .Advance)

3) remove all unwanted services,packages,tools, make sure your folders/files ownership are secure (cant really guide here, its vast)

4) feeling adventurous ,enable SE-Linux .

and I got guide here , old one when i was learning to be admin , its got nice tips too https://www.neowin.net/forum/index.php?showtopic=271716

Link to comment
https://www.neowin.net/forum/topic/619796-server-rebuild/#findComment-589207717
Share on other sites

You shouldn't be running a GUI of any sort on a server, it increases the attack vector and makes it less secure. If you want secure, you can always look at OpenBSD, which has only had 2 remote security holes in it's default install in 10 YEARS! PF is also a very nice firewall/queuing/forwarding/packet filtering system. You might also check out FreeBSD, that is a little easier to get used to than OpenBSD. Debain Etch is my distro that I use for my servers, it's pretty secure out of the box, and is also really easy to use.

Link to comment
https://www.neowin.net/forum/topic/619796-server-rebuild/#findComment-589230520
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Windows 11 gets useful new File Explorer features in the latest build by Taras Buria Friday Windows 11 preview builds are finally here. After skipping one week, Microsoft is back to releasing preview builds for Windows Insiders to try. This time, Insiders in the Experimental Channel can download build 26300.8687. Its changelog does not contain anything major, but there is still useful new stuff, such as some new conveniences for File Explorer, Windows Update improvements, better Windows Search, a new search provider for the built-in GIF library, and more. Here is the changelog: [Windows Update] As announced in the Windows Update announcement blog, we are now bringing a new unified update experience to reduce the number of reboots you see per month. We are starting by coordinating driver, .NET, and firmware updates to align with the monthly quality update, reducing the update experience to a single monthly restart. See the blog for more information. [File Explorer] Middle-click to open a folder in a new tab is now supported in the Address Bar and the Home page for a more consistent and efficient tabbed navigation experience across File Explorer. Improved screen reader announcements for conflict resolution dialog ("Which files do you want to keep?") when moving/copying files. Made some more improvements to how File Explorer responds to increased text scaling. [Search] Finding apps is more forgiving. Search is better at handling typos, dropped letters, extra letters, and partial words for apps. Queries like “utlook” can still find Outlook. Settings results are improving. We’ve made ranking improvements to help more relevant settings appear higher in results. [Taskbar] Improved reliability of loading the system tray area of the taskbar. Fixed an issue where tooltips might unexpectedly appear on top of the Start menu icon in the taskbar when using the taskbar in an alternate position. Also fixed a few other visual polish issues when using the taskbar with small icons. [Windows setup] The digital safety of users and supporting families is central to how we think about the Windows experience. We're improving information on parental controls and their availability during Windows setup, so families can more easily understand available protections and make informed choices from the very beginning. [Input] Update: The emoji panel (Windows key + period (.)) now uses GIPHY as the GIF provider, delivering a smoother GIF browsing and sharing experience following the deprecation of Tenor. Fixed an issue that was causing the mouse cursor to potentially move in the wrong direction in recent Insider builds on secondary monitors when set to portrait mode. [Remote Recovery Management] Adding a recovery remote management plug-in for extending WinRE management capabilities for MDM providers [Audio] Fixed an issue resulting in audio not working for some Insiders after the latest flights. [Settings] Fixed an issue impacting the reliability of Settings > Apps > Installed Apps after the latest flights. [General Reliability] If you were experiencing freezes in the previous flight when interacting with search, Notepad, or certain other scenarios, that should be resolved now. [Other] When using dark mode, if you open "Run new task" from Task Manager, it will now show in dark mode too. As usual, changes above are rolling out gradually. You can find the release notes here in the official documentation.
    • Im in Ohio, and my VPN endpoint is in Boston. If that helps, it does happen both on and off the VPN. and again only in Edge.
    • It is such a shame. I used to really respect Neowin's articles.
    • So.... slower fixes and slower security updates are preferred? I mean, there is no goldilocks zone here until it can literally update without ever needing a restart, and even then I'm sure someone would complain.
  • Recent Achievements

    • One Month Later
      Clizby earned a badge
      One Month Later
    • One Month Later
      Timaximus earned a badge
      One Month Later
    • Week One Done
      Timaximus earned a badge
      Week One Done
    • Rookie
      FBSPL went up a rank
      Rookie
    • First Post
      davidbazooked earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      490
    2. 2
      PsYcHoKiLLa
      168
    3. 3
      +Edouard
      163
    4. 4
      Steven P.
      85
    5. 5
      ATLien_0
      76
  • Tell a friend

    Love Neowin? Tell a friend!