{"id":1301,"date":"2010-12-16T14:03:49","date_gmt":"2010-12-16T20:03:49","guid":{"rendered":"https:\/\/webhostinggeeks.com\/blog\/?p=1301"},"modified":"2016-02-22T02:34:42","modified_gmt":"2016-02-22T07:34:42","slug":"the-basics-of-web-server-security","status":"publish","type":"post","link":"https:\/\/webhostinggeeks.com\/blog\/the-basics-of-web-server-security\/","title":{"rendered":"The Basics Of Web Server Security"},"content":{"rendered":"<p>Web server security is an ever evolving issue.\u00a0 Everyday new and improved attacks are being leveraged against major web servers causing it managers to scramble and find a solution. As new technologies emerge, the internet hacker will always find a way to break through anything thrown at them. If time has shown us anything, it\u2019s that web developers will always need to be very aware of security issues on their servers.<\/p>\n<p><strong>Extra Services<\/strong><\/p>\n<p>One area of major concern to a web developer is unnecessary services. Running extra and unnecessary services on a server creates a possible security problem. Default operating system installations are not very secure and typically these operating system will turn on a large variety of services that aren\u2019t really needed. The more services that are left open, the more likely a hacker will find a hole in the server\u2019s security.<\/p>\n<p><strong>Remote Access<\/strong><\/p>\n<p>Remote access is becoming more and more popular for web administrators, as it allows virtual constant access to the server machine. However, this does increase the risk for security threats to the server. Whenever possible a web administrator should log on to the machine locally. Remote access should be limited in use as well as in depth. Whenever possible, if using remote access, limit the number of IP addresses that are allowed to use it. This will help to harden some of the security for the server.<br \/>\n<strong><br \/>\nPatches<\/strong><\/p>\n<p>All updates to security should be installed immediately. Often web administrators put this off because it requires some time and effort to get the server patched, restarted and back online.\u00a0 Generally speaking patches come out because a security hole has been identified. When the patch is released that hole becomes public knowledge. You are putting yourself at an unnecessary risk by putting of installing patches to the operating system. These patches should be installed at the first available opportunity.<\/p>\n<p><strong>Monitor the Server<\/strong><\/p>\n<p>Its good practice to take a regular look at the server access logs. If you\u2019re running a database program you should look at those two. These logs will help to identify any possible malicious attempt to access the system. With this information you can block ports or IP addresses that seem problematic. This helps to further harden the security of the web server.<br \/>\n<strong><br \/>\nUser Accounts<\/strong><\/p>\n<p>Never under any circumstance use the default accounts. Quickly <a href=\"https:\/\/webhostinggeeks.com\/tools\/passwordgenerator\/\">change the passwords<\/a> for all the default accounts on the server. Leaving the default accounts can increase the servers chances of an attack. Be sure you rename the built in administrator accounts too.<\/p>\n<p>Server security is a major issue on the internet these days. Take caution and spend a bit of time hardening the security for your web server. Monitor the traffic and logs on a regular basis and quickly identify and take care of any possible threats.\u00a0 By doing so, you will greatly reduce the likely hood of attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Web server security is an ever evolving issue.\u00a0 Everyday new and improved attacks are being leveraged against major web servers causing it managers to scramble and find a solution. As&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"wds_primary_category":0,"footnotes":""},"categories":[9],"tags":[321,1677,2300,210],"class_list":["post-1301","post","type-post","status-publish","format-standard","hentry","category-security-issues","tag-hackers","tag-remote-access","tag-secuity-problem","tag-web-server"],"views":93,"_links":{"self":[{"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/posts\/1301","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/comments?post=1301"}],"version-history":[{"count":0,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/posts\/1301\/revisions"}],"wp:attachment":[{"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/media?parent=1301"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/categories?post=1301"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/tags?post=1301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}