Skip to content
Shahid Malla

Server security

Server Hardening Service for Linux and cPanel Servers

I harden Linux and cPanel servers by closing what is not needed and testing each control from outside, covering SSH, firewall, patching, PHP isolation, mail abuse limits, logs and backups. It is for hosting owners and agencies who want less exposure and a clear plan for when something still goes wrong.

By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated

What does a server hardening service check?

A server hardening service reduces what an attacker can reach and what they can do if they get in. I work through twelve controls and test each one, so nothing on the list is assumed to work.

ControlWhyHow I verify
SSH keys only, no root password loginPasswords are what brute-force bots guess all day.sshd -T shows passwordauthentication no and restricted root login, then a login test from a second session.
Brute-force protectionLimits repeated guesses on SSH, panel and mail logins.Failed attempts from a spare address get blocked and the block shows in the logs.
Host firewall, minimal open portsEvery listening service is attack surface.ss -tulpn on the server compared with an outside port scan and the list of intended ports.
Panel ports restrictedWHM on port 2087 is effectively a root login page.Where resellers do not need WHM, the port is unreachable from an address that is not on the allow-list.
Kernel and panel patchingMass attacks target known flaws that already have fixes.The running kernel matches the installed one, update logs are clean and no reboot is pending.
WAF rulesBlocks common exploit probes aimed at web applications.A harmless request that matches a rule gets a 403 and an audit-log entry.
Malware scanningFinds web shells and injected code in customer files.The scanner flags a harmless test file placed in a scratch account.
PHP limitsStops one customer's code reaching system functions or other accounts.A test script on one account cannot read another account's files or call a disabled function.
Mail abuse controlsOne hijacked mailbox can blocklist the server IP within hours.Hourly caps trigger in a controlled test and the queue alert fires.
Least privilegeAdmins, databases and API tokens should hold only the power they need.Review of sudo users, panel tokens and per-application database users.
Log reviewAn intrusion is invisible in logs nobody reads.Logs are copied to a second location and I run one review pass during the job.
Protected backupsAn intruder with root deletes backups stored on the same machine.Backup credentials cannot delete old copies, and a restore from them works.

Patching has one wrinkle on cPanel servers. The panel manages its own packages, so I let its updater handle those and the operating system updater handle the rest. Kernel fixes need a reboot unless a live-patching service is in place. I schedule that reboot with you.

How do open-source and commercial WAF and malware tools compare?

Both kinds work, and the right pick depends on budget, who will read the alerts and how much false-positive tuning you will accept. I describe the trade-offs and configure the tool you choose.

ModSecurity with the OWASP Core Rule Set is open source and free. It blocks common attack patterns, but it needs tuning and someone must read its audit log. Commercial server security suites, Imunify360 for example, bundle vendor-maintained rules, malware scanning, cleanup tools and support for a per-server license fee. Open-source scanners such as ClamAV and Linux Malware Detect carry no license cost, but you maintain the signatures and own the cleanup process. A cloud WAF in front of a website is a different layer. It filters web traffic before it reaches the server, but it does nothing for SSH, mail or panel ports.

How do I harden PHP on a hosting server?

The strongest PHP hardening is isolation. Each account's PHP runs as its own Unix user through PHP-FPM, and the settings in php.ini add friction on top of that.

  • disable_functions. Block process-execution functions such as exec, passthru, shell_exec, system, proc_open and popen. Test with real applications first, because some plugins call them legitimately.
  • open_basedir. Limits file access to the account's own directories. It is useful but weak alone, so I treat it as a second layer behind user separation.
  • Defaults. Set expose_php and allow_url_include off, and keep upload and session directories out of world-writable locations.
  • Old versions. Remove PHP versions that no longer receive security fixes once customers have moved off them.

Can hardening stop every attack?

No. Hardening lowers risk and shortens an attacker's window, but it cannot prevent every attack. Unknown flaws in the panel or other software, stolen customer passwords, a vulnerable plugin inside one customer's website and a phished administrator all bypass server controls. So the job includes detection, backups you can restore and a written response plan, and the report lists which risks remain open instead of calling the server secure.

What should I do in the first hour after a compromise?

In the first hour, contain the damage, keep the evidence and change credentials from a clean machine. Do not start cleaning yet.

  1. Preserve. Take a provider snapshot if you can, and copy /var/log, the process list and the output of last -F somewhere safe. Avoid rebooting, which discards memory evidence.
  2. Contain. Restrict inbound traffic to your own address at the firewall or the provider's network level, and stop outbound mail so the server stops spamming.
  3. Rotate credentials. Change root and SSH keys, WHM and cPanel passwords, API tokens and database passwords, using a computer you trust.
  4. Look for persistence. Check authorized_keys files, extra accounts with user ID 0, cron entries, new systemd units and modified system binaries (rpm -Va on RHEL-family systems).
  5. Decide. If root was reached, rebuild on a clean system and restore data from a backup that predates the intrusion. Cleaning in place leaves doubt.
  6. Tell people. Notify affected customers as your contracts and local law require, and keep notes of what you did and when.

If WHMCS runs on the same machine, rotate its admin passwords, API credentials and gateway keys too, and consider a WHMCS security audit. Rebuilding relies on tested backups, which is the subject of server migration and backup.

What a hardening job will not do

It will not make the server unbreakable, certify compliance or replace a penetration test. I only work on servers you are authorized to give me access to. Some controls can block legitimate traffic, which is why I stage them and keep rollback notes. Pricing is a fixed quote after a scoping call, or $55 to $65 per hour. For a brand-new machine, hardening pairs naturally with cPanel and WHM setup, and the alert side is covered under monitoring and performance.

Who this is for

  • Hosting owners whose server has never had a security review
  • Teams that inherited a server and do not know what is exposed
  • Operators recovering from a compromise who want the rebuilt server hardened properly
  • Agencies hosting client sites who need to show which protections exist

What is included

  • Review of exposed ports, running services and user accounts
  • SSH key authentication, root password login disabled and brute-force protection
  • Host firewall rules with panel ports limited to known addresses
  • A repeatable update process for kernel, operating system and control panel
  • WAF rules and malware scanning, configured with the option you choose
  • PHP hardening and per-account isolation
  • Mail abuse limits and outbound mail alerts
  • Log review routine, protected backups and a written incident checklist

How the work runs

  1. 1

    Map

    I list what is listening, who can log in, what is patched and what is backed up, using local commands and a port scan from outside.

  2. 2

    Rank

    You get findings ranked by likely impact, with the change I propose for each one and the risk of making it.

  3. 3

    Apply

    I change one control at a time with a second root session open and a rollback note, so a bad rule cannot lock you out.

  4. 4

    Verify

    Every control is tested from outside the server and not assumed. The checklist records the result beside each control.

  5. 5

    Hand over

    You receive a written report of changes, checks, open risks and an incident checklist, plus two weeks of support.

Frequently asked questions

Will hardening make my server impossible to hack?

No. Hardening removes easy routes and shortens the time an attacker has, but it cannot prevent every attack. Unknown flaws in software, stolen customer passwords and vulnerable plugins inside customer websites still happen. That is why the work also covers detection, restorable backups and a written response plan.

How long does server hardening take?

One server with a standard cPanel stack typically takes one to three working days, depending on the number of services and how much needs rebuilding. Servers that have run for years without review take longer because I test every change against live sites. I give you a date after the review step, not before.

Will hardening break my customers' websites?

It can if done carelessly. Disabling PHP functions, enforcing open_basedir or switching on ModSecurity rules can block legitimate code. I apply those changes in stages, test against real sites, watch the logs for blocked requests and keep a rollback note for each change.

Do I need a commercial malware scanner?

Not always. Open-source scanners cost no license but need someone to maintain signatures and handle cleanup. Commercial suites bundle rules, scanning, cleanup tools and support for a per-server fee. The right choice depends on budget and who will review alerts. I explain the trade-offs and configure the one you pick.

Is this a penetration test or a compliance audit?

No. It is a configuration review and fix: I check and tighten the server and verify the controls work. It does not replace a formal penetration test or a compliance assessment. If a customer or regulator requires an independent report, that needs a specialist firm, and I will tell you so.

My server is already compromised. Can you help?

Yes. First I contain the damage and preserve evidence. If an attacker had root, I recommend rebuilding on a clean system and restoring data from a backup that predates the intrusion, then hardening the new server. Cleaning a rooted machine in place always leaves some doubt about what remains.

Related services

Ready to talk about your project?

Send the details and I reply within one business day with questions, an estimate and a plan.