Dev {Tricks}

  • Home
  • WordPress
  • OJS
  • Oxwall
  • Server and Hosting
You are here: Home / Archives for Server and Hosting / Providers

April 15, 2020 by dev Leave a Comment

How to restrict direct root access | Linux | CentOS

We can do it just in two steps.

Step One:

At first we will create new root user as follows (for example, newroot)

  1. Login as root using SSH.
  2. Create new user e.g., newroot and add user to wheel group
    useradd -G wheel newroot
  3. Set password for newroot
    passwd newroot
  4. You will get option to enter password. Use letter and number only.
    Save the newroot and password somewhere of you edge.
  5. Su to newroot
    su - newroot
  6. Test sudo permission (permission should be root)
    sudo whoami
  7. Enter password of newroot and it will show result “root”.
  8. Open sshd config file and check whether it has the “newroot” in AllowUsers. If not, add the user manually. (usually at the end).
    vi /etc/ssh/sshd_config

    [Permission Denied!] Quit :q

    AllowUsers newroot
  9. Restart sshd.service
    sudo systemctl restart sshd.service

Step Two:

Now we are going to disable the root user. Before doing this, you have to logout from “root” and then login with “newroot”.

You can only disable the  “root”, if you can successfully login with “newroot”.

  1. After successfully login with “newroot”, su to “root” using root password.
    su - root
  2. Then open sshd_config.
    vi /etc/ssh/sshd_config
  3. Search and change permitRootLogin “yes” to “no” as follows.
    permitRootLogin no
  4. Restart sshd.service to implement the change
    sudo systemctl restart sshd.service
  5. Now logout from “newroot” and try to login “root”
  6. Login with root now not allowed. Access Deny.
  7. So login with “newroot” and then su to root with root password
    su - root

Filed Under: Digitalocean, DirectAdmin, Security, Server and Hosting Tagged With: CentOS, create new root, restrict root access, vps security

December 1, 2019 by dev Leave a Comment

How to create One-Click login to RoundCube and phpMyAdmin ?

To enable one-click login for RoundCube

cd /usr/local/directadmin/
./directadmin set one_click_webmail_login 1
service directadmin restart
cd custombuild
./build update
./build dovecot_conf
./build exim_conf
./build roundcube

To enable one-click login for phpMyAdmin

cd /usr/local/directadmin/
./directadmin set one_click_pma_login 1
service directadmin restart
cd custombuild
./build update
./build phpmyadmin

To disable browser access to phpMyAdmin

cd /usr/local/directadmin/custombuild
./build update
./build set phpmyadmin_public no
./build phpmyadmin

 

 

Filed Under: Digitalocean, DirectAdmin, Security, Server and Hosting, VPS Management

November 29, 2019 by dev Leave a Comment

How to add Swap file on CentOS 8?

  1. Check whether you have sudo privileges.
    sudo -v

    Getting error message deny sudo!

  2. Check you already have swap partition
    sudo swapon --show

    Showing none means that you don’t have swap partition

Filed Under: Digitalocean, DirectAdmin, Security, Server and Hosting, VPS Management

November 28, 2019 by dev Leave a Comment

Start / Stop / Restart Berkeley Internet Name Daemon (BIND) DNS Server

  • Start BIND server
    service named start
  • Stop BIND server
    service named stop
  • Restart BIND server
    service named restart
  • Reload BIND server to reload zone file or config file changes
    service named reload
  • Current status of BIND server
    service named status

Filed Under: Digitalocean, DirectAdmin, Server and Hosting, VPS Management

November 27, 2019 by dev Leave a Comment

ConfigServer Security & Firewall, CSF basic commands, advanced configurations and settings

Basic CSF commands

  • Enable CSF
    csf -e
  • Disable CSF
    csf -x
  • Start CSF
    csf -s
  • Flush/Stop CSF
    csf -f
  • Reload CSF
    csf -r
  • Allow an IP and add it to csf.allow – /etc/csf/csf.allow
    csf -a 162.162.1.219
  • Remove and delete an IP from csf.allow – /etc/csf/csf.allow
    csf -ar 162.162.1.209
  • Place an IP on temporary deny list in /var/lib/csf/csf.tempban
    csf -td
  • Remove an IP from the temporary IP ban or allow list
    csf -tr 162.162.1.209
  • Flush all IPs from the temporary IP entries
    csf -tf
  • Deny an IP and add to csf.deny
    csf -d 162.162.1.209
  • Remove and Unblock an IP from csf.deny
    csf -dr 162.162.1.209
  • Remove and Unblock all entries from csf.deny
    csf -df
  • Search for a pattern match on iptables e.g : IP, CIDR, Port Number
    csf -g 152.167.1.118

Advanced Configuration to csf.conf at /etc/csf/csf.conf

  • Add root and admin notification email addresses at /etc/aliases.
    root: root@domain.com
    admin: admin@domain.com
    
  • Add email address to get all notifications – /etc/csf
    (csf > firewall configuration > Reporting Settings > LF_ALERT_TO = alert@domain.com)

    LF_ALERT_TO = "alert@domain.com"
  • Stop or disable “excessive resource usage” change PT_USERTIME = 0
    PT_USERTIME = "0"

    Under Process Tracking at /etc/csf

  • Don’t Block IP addresses that are in the csf.allow files
    IGNORE_ALLOW = "1"
  • Allow Incoming and Outgoing ICMP
    ICMP_IN = "1"
    ICMP_OUT = "1"
  • Block Certain Countres
    CC_DENY = "CA,CN,US"
    CC_ALLOW = "IN,ME,DE"
  • Send the Su and SSH Login log by Email
    LF_SSH_EMAIL_ALERT = "1"
    LF_SU_EMAIL_ALERT = "1"
  •  Get alert or notification
    LF_ALERT_TO = "email@domain.tld"

Warning in CSF

  • SYSLOG_CHECK option check
    (This option helps prevent brute force attacks on your server services)

    • Open /etc/csf/csf.conf
    • Search for “SYSLOG_CHECK”
    • Put value between 300 and 3600 seconds
      SYSLOG_CHECK = "600"
    • Restart CSF firewall
      #csf -r
  • Check for DNS recursion restrictions
    (You have a local DNS server running but do not appear to have any recursion restrictions set. This is a security and performance risk and you should look at restricting recursive lookups to the local IP addresses only)
    • Add following options to /etc/named.conf
      options {        
         allow-recursion {
         localhost;
      };
    • Restart named
      service named restart
  • Check for cxs
    (You should consider using cxs to scan web script uploads and user accounts for exploits uploaded to the server)

    ConfigServer eXploit Scanner (cxs) - from $60/server

    https://configserver.com/cp/cxs.html

  • Check for osm
    (You should consider using osm to provide protection from spammers exploiting the server)

    Outgoing Spam Monitor (osm) - $40/server

    https://www.configserver.com/cp/osm.html

  • Check for swap file
    (The server appears to have no swap file. This is usually considered a stability and performance risk. You should either add a swap partition, or create one via a normal file on an existing partition)
  • SSH/Telnet Check
    • Check SSH PasswordAuthentication
      (You should disable PasswordAuthentication and only allow access using PubkeyAuthentication to improve brute-force SSH security)
    • Check SSH UseDNS
      (You should disable UseDNS by editing /etc/ssh/sshd_config. Otherwise, lfd will be unable to track SSHD login failures successfully as the log files will not report IP addresses)

      UseDNS no

 

Filed Under: Digitalocean, DirectAdmin, Security, Server and Hosting, VPS Management Tagged With: CSF, csf.conf

  • « Previous Page
  • 1
  • …
  • 11
  • 12
  • 13
  • 14
  • Next Page »
  • Upwork
  • Freelancer
  • Fiverr
  • Guru

www.ojsexpert.com
www.ojsdev247.com

Recent Posts

  • To get your email for castamodel.com going to the right place, you need to update your DNS settings.
  • Security and WordPress
  • ROR
  • How do we copy google form to google workspace?
  • Install ImageMagick – Almalinux
  • How to remove /public/ from URL in Laravel
  • How to install Maldet alert?
  • How to Install Maldet and Run a Scan | Maldetect
  • Where is Roundcube location on CWP control panel?
  • How To Add Node.js Projects In aaPanel?
  • SPF/DKIM/DMARC Tools
  • Associative arrays – How to loop over Associative arrays
  • Indexed Arrays. How to loop over Indexed Arrays.
  • PHP Break | Continue
  • For Loop | While Loop | Do…While Loop | Foreach Loop
  • Strict mode in PHP
  • PHP Function Return Types
  • PHP Anonymous Functions (or Closures)
  • PHP Variadic Functions
  • PHP nullable type hints

Categories

  • Affiliate Marketing (1)
  • Customization (4)
    • CSS (2)
  • Email Solutions (23)
    • FrontApp (2)
    • Google Spreadsheet (2)
    • Microsoft Outlook (1)
    • PHP Email Form (3)
    • PolyMail (2)
    • Recaptcha (1)
    • Roundcube (4)
    • Thunderbird (3)
    • WebMail (5)
  • Games (1)
  • How to (87)
  • Joomla (6)
    • Akeeba (1)
    • Fix & Tricks (3)
  • jQuery (4)
  • jQuery Plugins (4)
    • BX Slider (1)
    • Slick (1)
  • Laravel (5)
  • Marketplace (5)
  • Miscellaneous (31)
  • MultiSaaS (1)
  • OJS (56)
    • Crossref (1)
    • Help (37)
    • Installation (10)
      • Issues (5)
    • Plugins (8)
    • Scholar Indexing (2)
    • Theme (7)
      • Templates (7)
        • Frontend (6)
        • legacy (1)
    • Theme Customization (10)
    • Theme Development (14)
    • TPL CSS JS (2)
    • Upgrade (11)
  • OSTAD (17)
  • Oxwall (3)
  • Payment Methods (1)
    • Paypal (1)
  • PC Tips and Tricks (14)
    • MS Office (2)
      • PowerPoint (1)
    • Windows (4)
  • PHP Parse error (2)
  • phpBB (2)
  • Server and Hosting (213)
    • Billing and Management (10)
      • Blesta (5)
      • Boxbilling (2)
      • WHMCS (5)
    • Email (10)
      • Postfix (3)
    • Error and Fix (17)
    • FTP (2)
    • Linux Distribusion (28)
      • Almalinux (13)
      • CentOS (17)
      • Debian (21)
      • Ubuntu (19)
    • Mail Server Solusion (7)
      • iRedMain (6)
    • MySQL (12)
    • Providers (69)
      • AWS (37)
      • Bluehost (37)
      • Cloudcone (26)
      • Contabo (40)
      • Digitalocean (68)
      • Hetzner (3)
      • HostGator (36)
      • Hostinger (8)
      • RackNerd (10)
      • VPSDime (38)
    • Security (21)
      • SSH (8)
    • VPS Management (72)
    • Web Control Panel (147)
      • aaPanel (14)
      • CentOS Web Panel (46)
      • cPanel (33)
      • CyberPanel (7)
      • DirectAdmin (96)
        • Find & fix (38)
      • ISPConfig (17)
      • KeyHelp (7)
      • Plesk (26)
      • Webmin (25)
        • Usermin (2)
        • Virtualmin (13)
      • WHM (18)
  • Uncategorized (19)
  • Wordpress (89)
    • Elementor (2)
    • Find and Fix (11)
    • Functions (5)
    • Genesis (9)
    • Glossary (1)
    • How to (22)
    • Neuron TD (15)
      • Console Error (1)
      • functions (5)
        • register_post_type (1)
        • register_sidebar (1)
        • theme_files (1)
        • theme_supports (1)
      • Image Directory (1)
      • Menu (2)
      • Query (4)
    • Plugins (13)
      • Contact Form 7 (5)
      • Duplicator (1)
      • Essential Grid (2)
    • Softaculous (3)
    • Speed and Security (4)
    • Stock Theme Development (6)
      • Header Footer (1)
      • PHP (1)
      • VC (1)
    • Theme Development (2)
      • Issues (1)
      • Menu (1)
    • Timer Theme Development (3)
    • Update (2)
    • Woocommerce (2)
    • WP Basic Guideline (8)

Important DEV links

  • Premium Themes
    • Themeforest
    • Envato Market
  • Built With (What Theme is That?)
    • What WP theme is that
    • Joomla Template Detector
    • Drupal Template Detector
    • Prestashop Template Detector
    • Shopify Theme Detector
    • Squarespace Template Detector
    • OpenCart Detector
    • WordPress.com Theme Detector
  • Domain/IP history checker
    • Who IS request
    • Hosting Info
  • Check DNS Propagation
    • DNS Checker
    • intoDNS
  • What is my IP
    • What is My IP Address
    • What is My IP
    • IP location
    • What is My IP
    • Porkbun
  • SEO Tools
    • Visitor Traffic
    • Broken Link
    • Website Speed Test
      • SEMrush
      • GTmetrix
      • Pingdom
      • PageSpeed Insights
      • DebugBear
      • keyCDN
  • Photo Image
    • Remove Background 50 Free Preview Image 375 × 666 per month
  • Domain Registrars
    • 123-Reg
    • Porkbun
    • Freenom
    • Namecheap NEWCOM598
  • Hosting Providers
    • Bluehost
    • Hostgator
    • Inmotion
  • Hosting Control Panel
    • CWPpro (FREE)
    • DirectAdmin (Trial 60 Days, One account $2/month)
    • ISPConfig (Free)
  • Webmaster Tools
    • Google
    • Bing
    • Yandex
  • Miscellaneous
    • Time Calculator

 

Categories

  • Affiliate Marketing (1)
  • Customization (4)
    • CSS (2)
  • Email Solutions (23)
    • FrontApp (2)
    • Google Spreadsheet (2)
    • Microsoft Outlook (1)
    • PHP Email Form (3)
    • PolyMail (2)
    • Recaptcha (1)
    • Roundcube (4)
    • Thunderbird (3)
    • WebMail (5)
  • Games (1)
  • How to (87)
  • Joomla (6)
    • Akeeba (1)
    • Fix & Tricks (3)
  • jQuery (4)
  • jQuery Plugins (4)
    • BX Slider (1)
    • Slick (1)
  • Laravel (5)
  • Marketplace (5)
  • Miscellaneous (31)
  • MultiSaaS (1)
  • OJS (56)
    • Crossref (1)
    • Help (37)
    • Installation (10)
      • Issues (5)
    • Plugins (8)
    • Scholar Indexing (2)
    • Theme (7)
      • Templates (7)
        • Frontend (6)
        • legacy (1)
    • Theme Customization (10)
    • Theme Development (14)
    • TPL CSS JS (2)
    • Upgrade (11)
  • OSTAD (17)
  • Oxwall (3)
  • Payment Methods (1)
    • Paypal (1)
  • PC Tips and Tricks (14)
    • MS Office (2)
      • PowerPoint (1)
    • Windows (4)
  • PHP Parse error (2)
  • phpBB (2)
  • Server and Hosting (213)
    • Billing and Management (10)
      • Blesta (5)
      • Boxbilling (2)
      • WHMCS (5)
    • Email (10)
      • Postfix (3)
    • Error and Fix (17)
    • FTP (2)
    • Linux Distribusion (28)
      • Almalinux (13)
      • CentOS (17)
      • Debian (21)
      • Ubuntu (19)
    • Mail Server Solusion (7)
      • iRedMain (6)
    • MySQL (12)
    • Providers (69)
      • AWS (37)
      • Bluehost (37)
      • Cloudcone (26)
      • Contabo (40)
      • Digitalocean (68)
      • Hetzner (3)
      • HostGator (36)
      • Hostinger (8)
      • RackNerd (10)
      • VPSDime (38)
    • Security (21)
      • SSH (8)
    • VPS Management (72)
    • Web Control Panel (147)
      • aaPanel (14)
      • CentOS Web Panel (46)
      • cPanel (33)
      • CyberPanel (7)
      • DirectAdmin (96)
        • Find & fix (38)
      • ISPConfig (17)
      • KeyHelp (7)
      • Plesk (26)
      • Webmin (25)
        • Usermin (2)
        • Virtualmin (13)
      • WHM (18)
  • Uncategorized (19)
  • Wordpress (89)
    • Elementor (2)
    • Find and Fix (11)
    • Functions (5)
    • Genesis (9)
    • Glossary (1)
    • How to (22)
    • Neuron TD (15)
      • Console Error (1)
      • functions (5)
        • register_post_type (1)
        • register_sidebar (1)
        • theme_files (1)
        • theme_supports (1)
      • Image Directory (1)
      • Menu (2)
      • Query (4)
    • Plugins (13)
      • Contact Form 7 (5)
      • Duplicator (1)
      • Essential Grid (2)
    • Softaculous (3)
    • Speed and Security (4)
    • Stock Theme Development (6)
      • Header Footer (1)
      • PHP (1)
      • VC (1)
    • Theme Development (2)
      • Issues (1)
      • Menu (1)
    • Timer Theme Development (3)
    • Update (2)
    • Woocommerce (2)
    • WP Basic Guideline (8)
  • Home
  • WordPress
  • OJS
  • Oxwall
  • Server and Hosting

Copyright © 2025 · Executive Pro Theme on Genesis Framework · WordPress · Log in