ConfigServer Security & Firewall - csf v4.54| Firewall Check | Status | Comment |
|---|---|---|
| Check whether csf is enabled | OK | |
| Check csf is running | OK | |
| Check whether csf is in TESTING mode | OK | |
| Check whether lfd is enabled | OK | |
| Check incoming MySQL port | OK | |
| Check whether webmin is running | OK | |
| Check csf SMTP_BLOCK option | OK | |
| Check csf LF_SCRIPT_ALERT option | OK | |
| Check csf LF_SSHD option | OK | |
| Check csf LF_FTPD option | OK | |
| Check csf LF_SMTPAUTH option | OK | |
| Check csf LF_POP3D option | OK | |
| Check csf LF_IMAPD option | OK | |
| Check csf LF_HTACCESS option | OK | |
| Check csf LF_MODSEC option | OK | |
| Check csf LF_CPANEL option | OK | |
| Check csf LF_DIRWATCH option | OK | |
| Check csf LF_INTEGRITY option | OK | |
| Check csf PT_SKIP_HTTP option | OK | |
| Check csf PT_ALL_USERS option | OK | |
| Server Check | Status | Comment |
| Check /tmp permissions | OK | |
| Check /tmp ownership | OK | |
| Check /tmp is mounted as a filesystem | OK | |
| Check /tmp is mounted noexec,nosuid | OK | |
| Check /etc/cron.daily/logrotate for /tmp noexec workaround | OK | |
| Check /var/tmp permissions | OK | |
| Check /var/tmp ownership | OK | |
| Check /var/tmp is mounted as a filesystem or is a symlink to /tmp | OK | |
| Check /usr/tmp permissions | OK | |
| Check /usr/tmp ownership | OK | |
| Check /usr/tmp is mounted as a filesystem or is a symlink to /tmp | OK | |
| Check /dev/shm is mounted noexec,nosuid | OK | |
| Check /etc/resolv.conf for localhost entry | OK | |
| Check /etc/named.conf for recursion restrictions | OK | |
| Check /etc/named.conf for random query source port | OK | |
| Check server runlevel | OK | |
| Check nobody cron | OK | |
| Check Operating System support | OK | |
| Check perl version | OK | |
| Check MySQL version | OK | |
| Check SUPERUSER accounts | OK | |
| SSH/Telnet Check | Status | Comment |
| Check SSHv1 is disabled | OK | |
| Check SSH on non-standard port | WARNING | You should consider moving SSH to a non-standard port to evade basic SSH port scans. Don't forget to open the port in the firewall first! |
| Check SSH PasswordAuthentication | WARNING | For ultimate SSH security, you should consider disabling PasswordAuthentication and only allow access using PubkeyAuthentication |
| Check telnet port 23 is not in use | OK | |
| Check shell limits | OK | |
| Check Background Process Killer | OK | |
| Exim Check | Status | Comment |
| Check root forwarder | OK | |
| Check exim for extended logging | WARNING | You should enable extended exim logging to enable easier tracking potential outgoing spam issues. Add: log_selector = +arguments +subject to the first textarea in the Advanced Mode Exim Configuration Editor |
| Check exim weak TLS Ciphers | OK | |
| Check for maildir conversion | OK | |
| Apache Check | Status | Comment |
| Check apache version | OK | |
| Check suPHP | OK | |
| Check Suexec | OK | |
| Check apache for mod_security | OK | |
| Check apache for RLimitCPU | OK | |
| Check apache for RLimitMEM | OK | |
| Check apache Cipher Suite | OK | |
| Check mod_userdir protection | OK | |
| PHP Check | Status | Comment |
| Check php version | OK | |
| Check php for enable_dl | OK | |
| Check php for disable_functions | OK | |
| Check php for ini_set disabled | WARNING | You should consider adding ini_set to the disable_functions in the PHP configuration (usually in /usr/local/lib/php.ini) as this setting allows PHP scripts to override global security and performance settings for PHP scripts. Adding ini_set can break PHP scripts and commenting out any use of ini_set in such scripts is advised |
| Check php for register_globals | OK | |
| Check php for Suhosin | OK | |
| Check php open_basedir protection | OK | |
| WHM Settings Check | Status | Comment |
| Check cPanel version | WARNING | Your current version of cPanel is 11.24.7-EDGE_34168. According to the cPanel site, the latest available is 11.24.7-EDGE_34209, you should consider upgrading to ensure bugs and security patches are up to date |
| Check cPanel login is SSL only | OK | |
| Check boxtrapper is disabled | OK | |
| Check max emails per hour is set | OK | |
| Check whether users can reset passwords via email | OK | |
| Check whether native cPanel SSL is enabled | OK | |
| Check compilers | OK | |
| Check Anonymous FTP Logins | OK | |
| Check Anonymous FTP Uploads | OK | |
| Check FTP Cipher Suite | OK | |
| Check FTP Logins with Root Password | OK | |
| Check allow remote domains | OK | |
| Check block common domains | OK | |
| Check allow park domains | OK | |
| Check cPAddons update email to owner | OK | |
| Check cPAddons update email to root | OK | |
| Check package updates | OK | |
| Check security updates | OK | |
| Check melange chat server | OK | |
| Check root/reseller login to users cPanel | WARNING | You should enable and then disable this option after use. WHM > Tweak Settings > Disable login with root or reseller password into the users' cPanel interface |
| Check cPanel php for register_globals | OK | |
| Check cPanel php.ini file for register_globals | OK | |
| Check cPanel passwords in email | OK | |
| Check Referrer Security | OK | |
| Server Services Check | Status | Comment |
| Check server startup for cups | OK | |
| Check server startup for xfs | OK | |
| Check server startup for atd | OK | |
| Check server startup for nfslock | OK | |
| Check server startup for canna | OK | |
| Check server startup for FreeWnn | OK | |
| Check server startup for cups-config-daemon | OK | |
| Check server startup for iiim | OK | |
| Check server startup for mDNSResponder | OK | |
| Check server startup for nifd | OK | |
| Check server startup for rpcidmapd | OK | |
| Check server startup for bluetooth | OK | |
| Check server startup for anacron | OK | |
| Check server startup for gpm | OK | |
| Check server startup for saslauthd | OK | |
| Check server startup for avahi-daemon | OK | |
| Check server startup for avahi-dnsconfd | OK | |
| Check server startup for hidd | OK | |
| Check server startup for pcscd | OK | |
| Check server startup for sbadm | OK | |
| Check server startup for webmin | OK | |
| Check server startup for ossec | OK |
|
Your Score: 106/112*
*This scoring does not necessarily reflect the security of your server or the relative merits of each check |
csf: v4.54
©2006-2009, ConfigServer Services (Way to the Web Limited)