The web hosting publication by web hosting users for web hosting users
Update a Host / Editor Login
Search
Article News Host Business Name
DIRECTORY TOP RATING EDITOR REVIEW SEARCH HOSTING SHOWCASE BECOME AN EDITOR
RECENT NEWS
Pingdom Adds Business Monitoring Plan
Apptix Offers Hosted VoIP Products
Hostway Offers Free Server Setup
FWHN Offers 3 Discount Programs
Hosting Networking Site Launches
Infinera Names Strategic Materials VP
Egenera Hosts Virtualization Webinar
DRT Offers Euro Data Center Study
ARTICLES
Co-location Hosting
Dedicated Servers
Domain Names
E-Commerce / Merchant Accounts / Payment Gateways
Free Web Hosting
General Web Hosting
Hosting Software & Control Panels
Managed Web Hosting
Programming
Reseller Hosting
Running a Web Hosting Business
Search Engine Optimization
Specific Web Hosting Provider or Company
Technical & Security
Useful Website Tools
Virtual Private Servers
Web Design & Content
Website Marketing Campaign
SEARCH ARTICLES
WEBHOST DIRECTORY
By Location

By Category
Application Hosting
Collocation Hosting
Dedicated Servers
Domain Name Registration
Ecommerce Hosting
Free Web Hosting
Reseller Domain Name Registration
Reseller Hosting
Shared Web Hosting
Virtual Private Servers
By Function
Windows Web hosting
PHP Web Hosting
Mysql Web Hosting
ASP Web Hosting
MS SQL Server Web Hosting
Coldfusion Web Hosting
MS FrontPage Web Hosting
Ecommerce Web Hosting
Cheap/Discount Web Hosting
Personal Web Hosting
Domain Name Web Hosting
A-Z Listing
Enter web host domain:




Articles
  You are here : Home Articles Technical & Security
Check Your Server Security
Submitted by Larry Anderson on | 176 reads
Check Your Server Security

Your server is compromised, and you do not even realize it happened since the actions made by attacker do not affect your server functionality? Sadly to say, it is a fact, and yes, you may never find that your machine was compromised. Get the creeps?

For sure, it is good from time to time to check your server security, to see if any strange activities/processes are in your system. Check if your server resources are affected.

~    You could check CPU usage by issuing top command. Look for applications/scripts that consume your CPU.
~    Check for strange processes with ps -awux command.
~    Check your /tmp directory and also your /var/tmp directory for scripts/binaries copied there.
~    When a server is compromised, sometimes the attacker uses it to host an IRC bot (like psybnc or eggdrop) that connects to port 6667. You could check if any of your applications connect to that port with sockstat: #sockstat | grep 6667
~    If there is not much traffic on your server, you could use netstat command to see if suspect connections are made: #netstat –a
~    At a regular period of times, install and run a rootkit finder application (for example /usr/ports/security/rkhunter).
~    Check your open ports with nmap. See if you have other open ports than the ones you use for your running services.

Feel much better now?


ARTICLES | NEWS | DIRECTORY | TOP REVIEWS| TOP RATINGS| SEARCH | SHOWCASE | UPDATE A HOST
OUR EDITORS | CONTACT US | ADVERTISING | TERMS OF AGREEMENT
© Copyright 2006 , The Web Hosting Herald. All rights reserved.