ALERT Un-PIAF a system?

sleipnirtron

New Member
Joined
Oct 3, 2014
Messages
7
Reaction score
0
Hi,

I have a PIAF system installed in a CloudAtCost vm. I've found that C@C is too rocky to keep as a PIAF install so I've been using Vultr vm, which has been rock-solid for quite some time with my one phone.

I'd like to use the C@C PIAF as a web dev machine, SFTP backup server, and other non-critical stuff. I've been using it for this for a couple of weeks but I'm concerned about the security implications of having unused parts just lying around, ripe for exploitation in the future. I could reinstall everything but I've already put time into configuring it just so.

I'd like to disable FreePBX, asterisk, recordings, etc. so that I can sleep easier knowing some of the locked doors have been walled up completely. So far I've been powering it down every time I'm done for the day.

What should I do to remove unnecessary services, ports and programs? Should I just bite the bullet and reinstall? I'm using a centOS 6.4 base.
 
I've found the #1 exploitation location is apache. Service httpd stop
 
Thanks for the reply. I'm looking for the changes to survive a reboot, so I'd probably use chkconfig httpd off. And is there a more secure web server replacement you can recommend, seeing as how I'm specifically wanting to use this as a web development machine?

Just to be clear, I know that machines are innately insecure and I'm not looking to completely disable everything that's a potential security risk, especially things that I need to use. I could disable networking and be very secure but it would render the machine useless.
 
Use a VPN no web exposure to your box then, traveling man is builtin to PIAF

Leon
 
WARNING WARNING WARNING

These systems were never designed to be used as a general purpose PUBLIC server, most especially NOT a public web server!

Do yourself and your wallet a favor. Start over using one of the excellent tutorials on the Internet to set up the box.

WARNING WARNING WARNING
 
WARNING WARNING WARNING

These systems were never designed to be used as a general purpose PUBLIC server, most especially NOT a public web server!

Do yourself and your wallet a favor. Start over using one of the excellent tutorials on the Internet to set up the box.

WARNING WARNING WARNING
Those who don't heed the Nerd proceed at their own peril..... often they are never heard from again.:angel:
 

Members online

Forum statistics

Threads
26,687
Messages
174,411
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top