Best Practices/Knowledge Base for Improving Site Security

The purpose if this site is to collect information for  advicing sites on how to improve their site security (or to keep a high standard). 

 

SSH(d)-related security advice

  • avoid sshd password authentication
  • keep sshd related executables on read only filesystems
  • keep MD5 and CRCs database with security related executables