Company
Web Hosting
Resellers
Servers
VPS
Support
Contact Us
Servers Security
Unlike many other hosts, we take the security of our servers very seriously. The following, among many other procedures, are applied to our fleet of servers.

FIREWALL PROTECTION

Advanced Policy Firewall (APF) is installed and configured. Ports which are not used by cPanel are firewalled off to maximize the security of your server, the TCP/IP stack is hardened, and ICMP rate limiting is enabled to prevent DoS attacks. Additionally, Brute Force Detection (BFD) is installed which detects brute force attacks against your server and automatically denies access to attackers.

OrionCities also enables more security features to defend against SYN based DoS attacks, DNS poisoning and spoofing protection.

ANTI-SPAM / ANTI-VIRUS PROTECTION

Realtime Blackhole List (RBL) filtering is configured for anti-spam protection on your server. The configuration, and combination of nearly 10 blacklists, is designed to maximize spam filtering while keep false positives to an absolute minimum. OrionCities maintains local mirrors of these blacklists for maximum server performance. Updates are made approximately every 30 minutes to ensure your server is constantly protected.

HTTP INTRUSION PROTECTION

ModSecurity intrusion detection and prevention engine is installed for Apache. This module increases web application security, protecting web applications from both known and unknown attacks. The customized ruleset OrionCities provides protects from a wide variety of common http attacks, such as PHPBB exploits. If a new exploit is released, your server can be protected in as little as 15 minutes as we push out ruleset updates.

SERVER HARDENING

Besides our initial system audit, which ensures proper installation of the Operating System and control panel and all packages are at the latest patch level, OrionCities performs many other security tweaks to your server. Temporary directories and shared memory locations are secured to prevent against rogue files being uploaded or executed on the system. All unnecessary services are disabled, and unused packages are removed. Fetching programs, which are commonly used in exploit attempts are restricted to superuser access only. SSH is hardened, and kernel operating variables are tweaked to add additional security without impacting any use of the server. For a full list of performed services, please see below.

HTTP DOS PREVENTION

ModEvasive is installed for Apache. This module provides evasive action in the event of an HTTP DoS or DDoS attack or brute force attack.and works well in both single-server script attacks as well as distributed attacks.

Attacking hosts are blocked temporarily from Apache while legitimate requests are allowed through.

DAILY SECURITY AUDITS

OrionCities installs our own security scripts which run daily to look for signs of system intrusion or exploits which could threaten the health of your system. Rootkit Hunter and Chkrootkit are also installed and scan the system daily. If any anomalies are discovered, our technicians are alerted and can manually investigate to ensure your server is secure.

Data Center
At OrionCities, we set our standards very high when choosing a suitable data center for our Web hosting environment. Primary points that we take into consideration include (but are not limited to): location, quality & availability of bandwidth, security, and the building staff/management. Find out more.
About | Legal | Home | Contact Us
© 2008 OrionCities, All rights reserved.