Just some Plesk-Server-Notes to show up how to set up a Ubuntu 16.04.4 Server by HostEurope.de by a example...
- Note all changes down for documentation... (...you can make a commit to get them here included! ;-) )
- Renember to make always backups of changed files to have them again e.g. for migration.
- Renember to first try to solve issues with Plesk and Plesk-Extensions - so you have it easier later to migrate with Plesk Migrator!
This is a own documentation...
https://github.com/LV-Crew/Plesk-Notes
Create new user: https://www.digitalocean.com/community/tutorials/how-to-create-a-sudo-user-on-ubuntu-quickstart
Change old user with Command Line: usermod -aG sudo -username-
- mc
- 'rkhunter filerights'
- chkrootkit
- rkhunter
Follows...
Files to back up: hostname_vps, hostname_vps.service, my.hosts
I would definitely recommend using RSA keys for SSH, that is what I use for my personal SSH server. I personally generate 4096-bit RSA keys, so I would recommend that, as well, just for extra security. Usually the default is 2048. It's also important to remember to disabled passwords,
"PasswordAuthentication no" in the sshd_config, so the SSH server requires keys and does not allow passwords.
https://support.plesk.com/hc/en-us/articles/115000065489-How-to-set-up-SSH-keys
Files to back up: sshd_config + User Keys
https://www.hosteurope.de/faq/server/sicherheit-spam/risikopotenzial-bind/
Follows...
The old location is here:
/var/www/vhosts/-domain-/httpdocs/administrator/
The new location is here:
/var/www/vhosts/-domain-/private/
Files to back up: .htaccess, .htpasswd
We also move the Joomla log files to a new directory to make it more secure. Because it contains user IP addresses, it is "sensitive" and should be protected for data privacy reasons.
The old location is here:
/var/www/vhosts/-domain-/httpdocs/administrator/logs/error.php
The new location is here:
/var/www/vhosts/-domain-/logs/joomla/error.php
https://www.andrehotzler.de/en/blog/technology/63-protect-joomla-login-with-fail2ban.html
Files to back up: ...
https://github.com/LV-Crew/Hidden-Service-Notes
Files to back up: ...
- drweb
- clamav Files to back up: ...
Add parking website from e.g. https://www.domainholder.io/.
Example: https://y-lounge.com/
...always just suggest advertising domain names on as many sites as possible...
...there is no any one special website for it, everyone just uses all of them to increase their chances to find someone they can negotiate a good price with.
https://www.domainholder.io/
https://auctions.godaddy.com/
https://sedo.com/de/
https://www.payoneer.com/escrow/domain-names/
https://www.escrow.com/