This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

sentora security enhancement
#3
RE: sentora security enhancement
(01-23-2015, 05:36 AM)Me.B Wrote: I can help you over this for fine tuning.. I don't think that disabling php function would work as the panel will need to execute zsudo... It will break the panel daemon for sure.

I see fail2ban & good tools... also could be tuned for centos instead of focusing only on Ubuntu.

Also adding clamav/spamassassin to postfix will require a lot more ram... It should be optional or checking ram first. If you plan mainly to use server for hosting it won't help really.

forget about suphp as we plan to add suExec in next release would be more fun.

Webalizer is a mess...

Modsecurity if you enable all rules it will break sentora and CMS, so rules need to be tested with big care.

M B

Thank you for your comments, I will appreciate any help on this because security is not an easy task.

About:
- zsudo, you were rigth PHP system() function must be enabled in command line CLI-mode and daemon runs perfectly
- centOS, yes, Ubuntu is not the one and only but is the one I know, hope somebody can help with this
- clamav/spamassasin, My tests indicates that the high resources consuming is at first time, I will check on production and review load average regularly,...mmm your RAM checking sounds good, so may be this packages can be optional, and I consider it because one of my clients has a public webmail service, but again, you are right, is not required for everyone
- suphp, forget about it, i will take a look about apache suExec support
- ModSecurity, good to know,

thanks for the tips
Reply
Thanks given by:


Messages In This Thread
sentora security enhancement - by mars - 01-23-2015, 04:22 AM
RE: sentora security enhancement - by Me.B - 01-23-2015, 05:36 AM
RE: sentora security enhancement - by mars - 01-24-2015, 05:14 AM
RE: sentora security enhancement - by Me.B - 01-24-2015, 05:34 AM
RE: sentora security enhancement - by mars - 01-24-2015, 05:54 AM
RE: sentora security enhancement - by yusha - 09-30-2017, 10:11 PM

Possibly Related Threads…
Thread Author Replies Views Last Post
Is Sentora dead? rajeevrrs 2 3 ,965 12-17-2022, 09:20 AM
Last Post: TGates
Sentora debug and error files johnnyp 0 1 ,588 10-27-2022, 06:16 PM
Last Post: johnnyp
Transfer Account to another Sentora BenI 1 3 ,330 07-21-2022, 07:19 PM
Last Post: Nigel

Forum Jump:


Users browsing this thread: 1 Guest(s)