• The APS Catalog has been deprecated and removed from all Plesk Obsidian versions.
    Applications already installed from the APS Catalog will continue working. However, Plesk will no longer provide support for APS applications.
  • Please be aware: with the Plesk Obsidian 18.0.78 release, the support for the ngx_pagespeed.so module will be deprecated and removed from the sw-nginx package.

Resolved server security

noasetpro

New Pleskian
Hello!
Just one question about server security.
Currently I have one small VPS (just for testing) Debian 10 + Plesk Obsidian 18.0.40 + Imunify360, but I want to setup something better like VDS with max. 10 hosted domains.
VDS will be based on Debian 10 with Plesk and Imunify360 just like already have.
My question is: What I need to do for maximum server secure? How to protect it against hacking?
Thank's for help and answers!
Best regards,
Goran
 
Just a few tips which are not mentioned on the above link:

- mount /tmp with nodev, nosuid, and noexec options:
- be careful with the php allow_url_fopen setting. Disable it if possible. This used to be a huge hacker honeypot back in the days, not sure if this is still the case?
 
Back
Top