I recently set up a Linode running Debian Etch, and everything is going fine so far. But I'm concerned about security, and am looking for general advice for improving it on my site.
I recently hosted a VPS web site on another provider, who shall remain nameless (OK, it was Startlogic :->). I had a phishing site break-in, so I began using longer passwords, and SSH for all my file transfers. But the break-ins continued. Startlogic wasn't able to track down the problem, which is one of the reasons why I switched to Linode.
I installed mod-security on my Apache2 server. What else should I do to improve security? The Linode Wiki lists several security tips at
http://www.linode.com/wiki/index.php/Security_Tips , but there's a caveat there saying "Not much of this will actually help you." Hmm . . .
Specifically, I'm looking for advice about phishing sites, email security, and blog security -- and on how best to optimize mod-security.
Thanks for any suggestions!
- Chris M.