View Single Post


Old
  Post #6 (permalink)   12-10-2008, 10:12 AM
handsonhosting
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 1,851

Status: handsonhosting is offline
No issues with the software on this end since we started with them live about a year ago. No issues with ModernBill prior to that going back to 2000.

Many of the hacks are not software exploits but admin exploits. People failing to review logs, password protect areas, and change passwords on a regular basis. A 12 character random password is necessary on anything (if not a long password). NO two passwords that same in our network on any of our servers.

Put CSF on the server, watch for failed passwords.
Kill Telnet Access and limit from a single or a couple of servers that you own - static IP.
Disable root access, only allow login under one user, then SU to root.

And the number one issue for people with problms - when an upgrade comes out - UPGRADE!!