Security (Imunify360, ModSecurity)

Securing Shared Hosting Servers: A Guide for CentOS and AlmaLinux

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (10 sections)

If you run your own server and host websites for clients on it, one weak account can put every other account at risk. This guide covers the hardening steps that matter most on a multi-user Linux hosting server in 2026: a supported operating system, locked-down SSH, a firewall, account isolation, safe PHP settings, a web application firewall, malware scanning and monitoring. It applies to a server you manage yourself, such as a VPS; on Domain India shared hosting these layers are already managed for you.

Key takeaways

CentOS Linux has reached end of life, so build new hosting servers on AlmaLinux or Rocky Linux and keep them patched. Log in with SSH keys only, allow only the ports you use, isolate every hosting account from the others, run PHP per user with dangerous functions disabled, add a web application firewall and a malware scanner, and send logs and alerts somewhere you will actually see them. None of this is needed on Domain India shared hosting, where the server security is managed for you.

This guide is for your own server

These steps are for a server where you have root access, such as a Domain India VPS. On our shared hosting you can't change server configuration, and you don't need to: see the software that secures our shared hosting servers.

1. Start from a supported operating system

CentOS Linux 8 reached end of life at the end of 2021 and CentOS Linux 7 in June 2024. Neither receives security updates. CentOS Stream still exists, but it is a development stream that sits ahead of Red Hat Enterprise Linux, not a stable hosting base.

For a new hosting server, use AlmaLinux or Rocky Linux, which follow Red Hat Enterprise Linux release for release. If you still run CentOS 7, plan a migration to a fresh AlmaLinux or Rocky Linux server rather than patching around it. Background: why AlmaLinux and Rocky Linux are outshining CentOS.

Then keep it patched:

bash
sudo dnf upgrade --refresh -y
sudo dnf install -y dnf-automatic
sudo systemctl enable --now dnf-automatic.timer   # set apply_updates = yes in /etc/dnf/automatic.conf

On AlmaLinux and Rocky Linux, dnf replaces yum. Reboot after kernel updates; sudo dnf needs-restarting -r tells you when one is due.

2. Lock down SSH

In /etc/ssh/sshd_config (or a file in /etc/ssh/sshd_config.d/):

text
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3

Log in as a normal user with sudo rights, using a key. Keep your current session open while you run sudo sshd -t and sudo systemctl reload sshd, and test a new login in a second window before you close the first. If your team works from fixed IP addresses, allow SSH only from them. Moving SSH to another port cuts log noise but is not a security control on its own. More in the SSH security hardening checklist.

3. Firewall and brute-force protection

firewalld is the standard firewall on AlmaLinux and Rocky Linux. Open only the services your hosting stack uses:

bash
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service=ssh --add-service=http --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

Add mail, FTP and control-panel ports only if you run those services. Keep database ports such as MySQL's 3306 closed to the internet; users can reach databases through an SSH tunnel.

Add Fail2Ban (from the EPEL repository) to ban addresses after repeated failed logins to SSH, mail and panels. ConfigServer stopped developing CSF in 2025, so avoid it on a new server.

4. Isolate every account

Isolation is what makes a server "shared hosting" rather than one big website. Each customer should be a separate Linux user, and one compromised site must not be able to read or change another.

  • Home folder permissions. No account should be able to list or read other home folders. Never use 777 permissions.
  • PHP per user. Run a separate PHP-FPM pool for each account, running as that account's user, so PHP code can only touch its owner's files.
  • Resource limits. Limit CPU, memory and processes per account so one busy or hacked site can't take the server down.
  • A file-system jail. CloudLinux (a commercial distribution compatible with AlmaLinux) adds CageFS, which gives each user a private view of the file system, plus per-account limits. Control panels such as cPanel and DirectAdmin support it.

5. Harden PHP

Set these in the PHP configuration for each version you offer:

SettingRecommended valueWhy
expose_phpOffHides the PHP version from response headers
disable_functionsexec, shell_exec, system, passthru, proc_open, popen, and similarStops uploaded scripts from running system commands
open_basedirThe account's own home folderLimits which files PHP can open
allow_url_includeOffBlocks remote file inclusion attacks
display_errorsOff in productionKeeps paths and queries out of visitors' browsers

Offer only PHP versions that still receive security fixes, and move customers off end-of-life versions on a schedule you announce in advance. Disabling functions will break some applications, so tell customers what is disabled; our own list is explained in PHP disabled functions on shared hosting.

6. Add a web application firewall and malware scanning

  • Web application firewall. ModSecurity with the OWASP Core Rule Set blocks common attacks such as SQL injection and cross-site scripting. ModSecurity is now maintained under OWASP; Coraza is a newer compatible alternative. Commercial suites such as Imunify360 combine a WAF, malware scanning and PHP-level protection under one licence.
  • Malware scanning. ClamAV (from EPEL) is a free scanner; schedule regular scans of home folders and review the results before deleting anything. Commercial scanners detect more web-specific malware and can clean files automatically.

See understanding and implementing a web application firewall for how rules and false positives work.

7. Remove what you don't use

Every running service is something to patch and something to attack. List what is listening and what is enabled:

bash
sudo ss -tulpn
systemctl list-unit-files --state=enabled

Disable services you don't need with sudo systemctl disable --now name and remove unused packages with sudo dnf remove name.

8. Audit, monitor and back up

  1. Audit regularly.
    Lynis (from EPEL) checks hundreds of settings and suggests fixes. Run it after setup and after major changes.
  2. Watch file integrity.
    AIDE, or Wazuh for a fuller host intrusion detection system, alerts you when system files change.
  3. Read your logs.
    Logwatch mails a daily summary; a full ELK stack is usually too heavy for a single server.
  4. Monitor from outside.
    An external uptime check tells you when sites go down.
  5. Back up off the server.
    Keep account backups on separate storage, keep several versions, and test a restore.
Running a hosting business means handling abuse

When you host other people's sites, you will receive complaints about spam, phishing and copyright. Have a process for investigating them and suspending an account quickly, and keep customers' data under the rules that apply to you, such as India's Digital Personal Data Protection Act, 2023.

9. Where Domain India fits

A Domain India VPS gives you root access and is self-managed: you install, secure and update everything yourself. cPanel is not offered on our VPS plans; the control panel options at checkout are none, CyberPanel, Webuzo or DirectAdmin. If you would rather resell hosting without running the server, look at our reseller hosting, where the servers are managed for you.

VPS Basic
₹1,105.30/mo + GST
  • 2 vCPU
  • 4 GB DDR4 RAM
  • 128 GB NVMe SSD Storage
  • 3 TB Monthly Bandwidth
See plan details
VPS Standard
₹2,210.60/mo + GST
  • 4 vCPU
  • 8 GB DDR4 RAM
  • 256 GB NVMe SSD Storage
  • 5 TB Monthly Bandwidth
See plan details

The cards show live Domain India list prices, excluding 18% GST. For general VPS hardening beyond hosting, see essential security and optimisation tips for your VPS.

Frequently asked questions

Is CentOS still safe for a hosting server?

No. CentOS Linux 7 reached end of life in June 2024 and CentOS Linux 8 at the end of 2021, so neither gets security updates. Use AlmaLinux or Rocky Linux for a new server and migrate old CentOS servers.

What is the most important step in securing a shared hosting server?

Isolating accounts from each other. Run each site as its own Linux user with its own PHP-FPM pool and resource limits, so a hacked site can't reach its neighbours.

Should I change the SSH port?

It reduces log noise from automated scans but doesn't stop a targeted attacker. Key-only login, no root login and Fail2Ban matter far more.

Is CSF still a good firewall choice?

Not for a new server. ConfigServer stopped developing CSF in 2025. Use firewalld with Fail2Ban on AlmaLinux or Rocky Linux.

Do I need to do this on Domain India shared hosting?

No. On Domain India shared hosting the server is managed for you, and you can't change its configuration. This guide is for a server where you have root access, such as a VPS.

Does Domain India secure my VPS for me?

No. A Domain India VPS is self-managed. You have root access and are responsible for updates, the firewall, security software and backups.

Ready to build your own hosting server? Compare VPS plans, or choose cPanel hosting if you would rather have the server security managed for you. Questions? Open a support ticket.

Build your hosting server on a Domain India VPS

Root access on KVM virtualisation, with AlmaLinux, Rocky Linux and other current Linux choices.

See VPS plans

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Secure a Shared Hosting Server on AlmaLinux | Domain India