Skip to main content
🔒

Security

42 articles in this section

This section covers how to keep a site or server from being compromised at three levels at once: the network perimeter, the panel or VDS itself, and the accounts used to reach it. It walks through practical scenarios — from a bot hammering SSH with password guesses to preparing for a real DDoS attack — rather than vague advice like "use a strong password".

On the server side it covers the firewall (UFW) and Fail2ban, which together stop SSH brute-forcing and Nginx login abuse, plus baseline MySQL hardening against common misconfigurations. At the application layer: ModSecurity as a WAF, Content Security Policy against XSS, and spam and bot filtering that would otherwise flood forms and the admin panel.

It also explains the difference between SSL certificate types (DV, OV, EV) and why a mixed content warning on an HTTPS site is not cosmetic but an actual security hole. For login, there are SSH keys instead of passwords on a VDS and two-factor authentication in cPanel; for DDoS, how protection works on ZevsHost's side and what else can be configured.

How to Protect Your Website from Hacking Basic website security rules for WordPress and other CMS platforms on ZevsHost hosting. DDoS Protection at ZevsHost: How It Works How L3/L4/L7 DDoS protection works on ZevsHost servers and what to do during an attack. Strong Passwords and Password Managers Rules for creating strong passwords for hosting accounts and password manager recommendations. SSL Certificate Types: DV, OV, EV — What's the Difference How DV, OV, and EV SSL certificates differ: verification level, cost, browser display, and which sites each type suits. Comparison table. Protecting Your Website from Spam and Bots Methods for protecting website forms and comments from spam: reCAPTCHA, honeypot, anti-spam plugins. HTTPS Mixed Content: How to Find and Fix It What mixed content is on an HTTPS site, why the browser blocks resources, and how to fix mixed content errors in WordPress, code, and via .htaccess. Fail2ban: Protecting SSH and Nginx from Password Guessing Installing and configuring Fail2ban on Ubuntu/Debian. Protect SSH, your web server, and control panel from automated password-guessing attacks. ModSecurity WAF: protecting web applications on Apache/Nginx What ModSecurity WAF is, how to install and configure it on Apache and Nginx, enable OWASP CRS rules, manage false positives, and monitor attacks. SSH Keys: Secure Passwordless Login to VPS Generating SSH keys, adding a public key to the server, disabling password login. Setup for Windows PuTTY and Linux/Mac. Content Security Policy (CSP): protection from XSS How to configure Content Security Policy against XSS: default-src, script-src, style-src, report-uri directives. CSP examples for WordPress and SPA apps. Cloudflare: Free CDN and DDoS Protection Connecting Cloudflare to your domain: changing NS servers, cache setup, DDoS protection, SSL, and site acceleration on the free plan. Two-Factor Authentication in cPanel: setting up 2FA How to enable two-factor authentication (2FA) in cPanel with Google Authenticator or Authy. Guide covering the QR code, backup codes, and account recovery. MySQL Security on a VPS: Protecting Against Intrusion How to secure a MySQL server on a VPS: disabling remote root, mysql_secure_installation, separate database users, encrypted connections, query monitoring. UFW Firewall on a VPS: Configuring the Ubuntu Firewall How to set up UFW (Uncomplicated Firewall) on an Ubuntu VPS: basic rules, opening SSH/HTTP/HTTPS ports, blocking IPs, DDoS protection, and event logging. HSTS: forcing HTTPS to secure your site What HSTS is, how to add the header via .htaccess or Nginx, enable preload, configure max-age, and avoid errors when rolling back to HTTP. WireGuard VPN on a VPS: Quick Setup and Configuration How to install WireGuard VPN on an Ubuntu VPS in 10 minutes: key generation, server and client setup, adding peers, a QR code for your phone, and autostart. SSH Hardening: Secure Server Configuration Against Break-ins Hardening SSH security on Linux: change the port, disable root login, configure AllowUsers, MaxAuthTries, keys, and two-factor authentication. Hardening Nginx: Secure Web Server Configuration Secure Nginx configuration: hide the version, security headers, restrict HTTP methods, rate limiting, protection against clickjacking and MIME sniffing. WordPress security: a complete site protection checklist Complete WordPress protection: file permissions, xmlrpc.php, Wordfence, wp-config.php, two-factor authentication, and file change monitoring. Linux File Permissions: chmod, chown, SUID and ACL Linux file permissions: numeric and symbolic chmod notation, changing ownership with chown, special bits SUID/SGID/Sticky, extended ACLs. Secure PHP Configuration: php.ini Settings for Production Secure PHP configuration for production: display_errors, expose_php, open_basedir, disable_functions, session protection, and resource limits. Brute Force Protection: fail2ban, CAPTCHA, and Rate Limiting Comprehensive brute force protection: configuring fail2ban for SSH and the web, CAPTCHA on forms, Nginx rate limiting, geoblocking, and IP whitelisting. CrowdSec: a modern IPS defense system for VPS CrowdSec is a next-generation open-source IPS: installation on Linux, collection setup, Nginx integration, and threat blocking via shared threat intelligence. Detecting Rootkits on Linux: rkhunter and chkrootkit How to find rootkits on a Linux server: installing and configuring rkhunter and chkrootkit, automatic scheduled scanning, and reading the reports. Hacked Website: Diagnosis, Cleanup, and Recovery What to do if your website is hacked: signs of a hack, finding malicious code, cleaning up malware, restoring from backup, and preventing reinfection. New Linux Server Security Checklist: 30 Steps A complete security checklist for a new VPS/VDS: updates, SSH, firewall, fail2ban, users, monitoring — 30 steps from a bare server to a hardened host. Linux Security Auditing with auditd: Server Event Monitoring Configuring auditd for Linux security monitoring: tracking logins, file changes, privileged commands, and log analysis via ausearch. Secure MariaDB and MySQL Setup on a VPS Hardening MariaDB/MySQL: mysql_secure_installation, creating users with minimal privileges, encrypting connections, disabling remote root, and backups. Two-Factor Authentication for SSH and Web Panels Setting up two-factor authentication (2FA) on a Linux server: TOTP via Google Authenticator for SSH, ISPmanager, and WordPress, with recovery instructions. DDoS attack protection: Nginx and Cloudflare Comprehensive DDoS protection: connection limits in Nginx, rate limiting, configuring Cloudflare DDoS Protection, sysctl tuning, and responding to an attack. Let's Encrypt Wildcard: Auto-Renewal for Subdomains How to get a Wildcard SSL certificate from Let's Encrypt via DNS verification, set up Certbot auto-renewal, and verify it with acme.sh and the Cloudflare API. iptables: setting up a Linux firewall from scratch iptables: core INPUT/OUTPUT/FORWARD chains, allowing SSH/HTTP/HTTPS, blocking ports, scan protection, saving rules. Mandatory Access Control: Configuring SELinux and AppArmor Mandatory access control in Linux: how to configure SELinux on RHEL, AppArmor on Ubuntu, check the working mode, and avoid breaking a site during migration. GPG Encryption for Server Files and Backup Archives GPG encryption for files and backups protects server data if a disk is stolen, an archive leaks from S3 storage, or traffic is intercepted in transit. LUKS Disk Encryption: Securing a Server Drive and Keys LUKS disk encryption protects server data if the drive is physically removed: luksFormat, crypttab, keyfile, Clevis+Tang and header backup covered in practice. Wazuh SIEM: Server Security Monitoring and FIM Control Wazuh SIEM for server security monitoring combines log analysis, file integrity monitoring (FIM), and automatic attack blocking through active response rules. osquery: Server Inventory and Breach Traces Osquery turns a Linux server into a SQL database: how to install it, query processes and ports, and find breach traces after an incident. Storing Secrets on a Server: HashiCorp Vault and Env Vars Storing secrets on a server: how to set up HashiCorp Vault, issue temporary passwords for MySQL, and protect environment variables instead of an .env file. Dependency Audit: npm audit and composer audit Dependency audit on a server: how to run npm audit and composer audit, read a vulnerability report, and update packages without breaking a site. SSH Certificates: Login via a Certificate Authority SSH certificates replace distributing public keys: users get short-lived certificates from a certificate authority instead of long-term SSH keys. Port Knocking and SPA for Hidden SSH Access Port knocking and Single Packet Authorization hide the SSH port from scanners: access opens only after a secret sequence of packets. Incident Response Plan: The First 60 Minutes An incident response plan covers the first 60 minutes of an attack: isolating the server, collecting evidence, assessing damage, and notifying staff.