Harden Three Linux Servers
Budget: $30 – $250 USD
I manage three dedicated Linux machines that were recently flagged for outbound DoS traffic, so I need a full-scale hardening session. I have root access on each box and a few basic safeguards already running, but the incident makes it clear my current setup isn’t enough.
Here’s the outcome I’m after:
• Eliminate password authentication entirely and generate fresh SSH key pairs for every authorised admin.
• Move the SSH daemon to a non-standard port and close any unused ports via iptables or nftables.
• Install and configure Fail2Ban (or an equally effective alternative) to block brute-force attempts, plus a lightweight IDS so I’ll be alerted if anything slips through. (Already installed but make more strong)
• Perform a clean malware / rootkit sweep, confirm the DoS process is gone, and supply a short report of findings.
• Update all packages, enable automatic security updates where possible, and verify kernel parameters (sysctl) reflect best practice for DoS mitigation.
• Produce a concise hand-off document covering every change, commands used and how to roll back if needed.
All three servers are with Linode, running current LTS distributions. Once you’re finished, I’ll lift the temporary network restrictions with their abuse team, so I’ll need your evidence that the malicious traffic has stopped.
Timing is important—I’d like to regain full connectivity quickly—so please outline how soon you can start and an estimated turnaround for the tasks above.
Also change weekly backup to daily backup. Keep last 4 backups
Here’s the outcome I’m after:
• Eliminate password authentication entirely and generate fresh SSH key pairs for every authorised admin.
• Move the SSH daemon to a non-standard port and close any unused ports via iptables or nftables.
• Install and configure Fail2Ban (or an equally effective alternative) to block brute-force attempts, plus a lightweight IDS so I’ll be alerted if anything slips through. (Already installed but make more strong)
• Perform a clean malware / rootkit sweep, confirm the DoS process is gone, and supply a short report of findings.
• Update all packages, enable automatic security updates where possible, and verify kernel parameters (sysctl) reflect best practice for DoS mitigation.
• Produce a concise hand-off document covering every change, commands used and how to roll back if needed.
All three servers are with Linode, running current LTS distributions. Once you’re finished, I’ll lift the temporary network restrictions with their abuse team, so I’ll need your evidence that the malicious traffic has stopped.
Timing is important—I’d like to regain full connectivity quickly—so please outline how soon you can start and an estimated turnaround for the tasks above.
Also change weekly backup to daily backup. Keep last 4 backups
Related categories:
System Admin
Linux
Web Security
Apache
Documentation
Security
Network Security
System Administration