Best defense is a good offense... how to 'booby trap' a server?

CLKeenan

Banned
Jun 24, 2006
2,506
14
0
Boston, MA
Anyone got any good tricks/tips to booby trap my server in case someone manages to gain access? I've heard of password traps so that whenever the password is changed, the new one is sent to an email. Stuff like that, but even more awesome would be good.
 


It depends on how high-end you want to go. There are some enterprise level monitoring tools that will actually prevent/reset any change done at the OS level even when it is done by root.

They're expensive obviously.
 
Change your system language to only latin
i've had hackers not knowing wtf to do after gaining access, simply because the whole machine was Chinese. 'twas funny :)

Check your access log for all those attempted hacks, like trying to search your site for an open phpMyAdmin and so forth, and make those paths a redirect.
true... i redirect most error/debug stuff straight back to / 403's go straight to fw-level drop.

Another tip... if you have something like a backend or other administration that is standalone from the frontend, consider changing them to Port-based URLs (website.com/admpanel -> website.com:4445/admpanel) and then adding only your own physical location(s) as port allowed IPs. No web exploit will pass after that. People will have to hack your server's fw/machine itself.

error_log can also be ran through analyzers that automatically e-mail/sms you on certain keywords etc.

there is a lot of possibility..;

also: if your website is consumer-driven, just blanket-deny every dedicated server company in the world by /24 at fw level.
 
Most of those access log hacks are just bots though...
true... outside of useragent denies and *bot* , the freakiest things are scrapers. i haven't installed any detection patterns for those yet, but it's something someone could add.
 
Attn Refrozen need some support and can't contact you

Hi

Apologies if this post is in the wrong place but just need to contact refrozen for some support to WP Link Engine as none of the support email addresses work. If you could get in touch with me that would be great

Cheers
Mike Capper
 
Hi

Apologies if this post is in the wrong place but just need to contact refrozen for some support to WP Link Engine as none of the support email addresses work. If you could get in touch with me that would be great

Cheers
Mike Capper

Sorry, was probably in the process of moving the mailing stuff over. Try again now, I actually believe I've responded to one of your emails. If not, PM your questions here and I'll help you out.
 
If you have a FTP server, instead of blocking an IP/user after x failed logins, log it into the anonymous account, disallow uploads, but keep some of your 'favorite' files in there.