Skip to content

Tweaking My Server Security

Over the past few weeks my web/email server has been attacked multiple times. So I’ve started hardening my defenses. Stay tuned as I will be documenting what I do and what I learn. Today I’ve been experimenting with iptables and the settings for my sshd (the server that allows me to connect to the web server “behind the scenes”).

Just this morning as I was tweaking things I “watched” someone in Russia try to guess passwords and account names. He was at 212.110.146.180 (u590.so-com.net) in case anyone is interested.

One of the biggest things I need to do is to re-train my customers to use a different program to upload files to their web sites. Right now I have them set to use FTP, but that needs to go away. SFTP looks like it will be the way to do things.

Twitter Updates for 2010-07-15

Twitter Updates for 2010-07-11

  • 66.197.194.213 is browsing with user-agents made up of random character strings to attack my web sites. #
  • Same thing happening from 173.212.244.114 #

Twitter Updates for 2010-07-07

  • @tracfonecalls Getting frustrated with Tracfone. All reps are busy, so you hang up on me? Who do you think you are, Verizon? #

Twitter Updates for 2010-07-06

  • Block the wonderful user from 93.95.100.82 (pointer transmetall.ru), user-agent of REDIRECT_FROM_SEO. #
  • @Spotus I am receiving spam to the email address I gave only to spot.us. Did you guys sell out, have a privacy breach, or post my email? #
  • Is hardcoding some text into a WordPress theme "better" than getting content from a WP database? The text only changes once per year at most #

Twitter Updates for 2010-07-05

  • @perishable July 4th is also Rube Goldberg's birthday. Plus the logo is animated, which did surprise me. How else to launch the rocket? 🙂 in reply to perishable #

Twitter Updates for 2010-07-03

  • @panic Is it just me or is the CSS book included in Coda really old? 2007 was several generations, and 2004 for the original book is ancient #

Twitter Updates for 2010-07-01

  • Just renewed a bunch of domain registrations before the price increases hit on July 1st. #
  • Block 209.17.186.226 . Looking for WordPress vulnerabilities, as well as using the "fakeuser" username. #

Twitter Updates for 2010-06-27

  • 204.51.97.63 is a lame hacker. #

Twitter Updates for 2010-06-24

  • I am really enjoying reading web articles with the Safari 5 Reader feature. No more looking for a "view all" or "print" link. #
  • Another reason I like Safari Reader: Sites that use tiny fonts, or poor color choices. With Reader I can read the entire article easily. #
  • @tracfonecalls Does a LG420G purchased at retail include DMFL? Tech support hasn't responded to my inquiry. #