Discussed in depth in a number of places in Holistic Info-Sec for Web Developers.

Also covered in Kim’s interview of Haroon Meer on Software Engineering Radio.

Installation and Hardening of Debian Web Server

These are the steps I took to set-up and harden a Debian web server before being placed into a DMZ and undergoing additional hardening before opening the port from the WWW to it. Most of the steps below are fairly simple to do, and in doing so, remove a good portion of the low hanging fruit for nasty entities wanting to gain a foot-hold on your server->network.