If you run your own server and host websites for clients on it, one weak account can put every other account at risk. This guide covers the hardening steps that matter most on a multi-user Linux hosting server in 2026: a supported operating system, locked-down SSH, a firewall, account isolation, safe PHP settings, a web application firewall, malware scanning and monitoring. It applies to a server you manage yourself, such as a VPS; on Domain India shared hosting these layers are already managed for you.
CentOS Linux has reached end of life, so build new hosting servers on AlmaLinux or Rocky Linux and keep them patched. Log in with SSH keys only, allow only the ports you use, isolate every hosting account from the others, run PHP per user with dangerous functions disabled, add a web application firewall and a malware scanner, and send logs and alerts somewhere you will actually see them. None of this is needed on Domain India shared hosting, where the server security is managed for you.
These steps are for a server where you have root access, such as a Domain India VPS. On our shared hosting you can't change server configuration, and you don't need to: see the software that secures our shared hosting servers.
1. Start from a supported operating system
CentOS Linux 8 reached end of life at the end of 2021 and CentOS Linux 7 in June 2024. Neither receives security updates. CentOS Stream still exists, but it is a development stream that sits ahead of Red Hat Enterprise Linux, not a stable hosting base.
For a new hosting server, use AlmaLinux or Rocky Linux, which follow Red Hat Enterprise Linux release for release. If you still run CentOS 7, plan a migration to a fresh AlmaLinux or Rocky Linux server rather than patching around it. Background: why AlmaLinux and Rocky Linux are outshining CentOS.
Then keep it patched:
sudo dnf upgrade --refresh -y
sudo dnf install -y dnf-automatic
sudo systemctl enable --now dnf-automatic.timer # set apply_updates = yes in /etc/dnf/automatic.confOn AlmaLinux and Rocky Linux, dnf replaces yum. Reboot after kernel updates; sudo dnf needs-restarting -r tells you when one is due.
2. Lock down SSH
In /etc/ssh/sshd_config (or a file in /etc/ssh/sshd_config.d/):
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3Log in as a normal user with sudo rights, using a key. Keep your current session open while you run sudo sshd -t and sudo systemctl reload sshd, and test a new login in a second window before you close the first. If your team works from fixed IP addresses, allow SSH only from them. Moving SSH to another port cuts log noise but is not a security control on its own. More in the SSH security hardening checklist.
3. Firewall and brute-force protection
firewalld is the standard firewall on AlmaLinux and Rocky Linux. Open only the services your hosting stack uses:
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service=ssh --add-service=http --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-allAdd mail, FTP and control-panel ports only if you run those services. Keep database ports such as MySQL's 3306 closed to the internet; users can reach databases through an SSH tunnel.
Add Fail2Ban (from the EPEL repository) to ban addresses after repeated failed logins to SSH, mail and panels. ConfigServer stopped developing CSF in 2025, so avoid it on a new server.
4. Isolate every account
Isolation is what makes a server "shared hosting" rather than one big website. Each customer should be a separate Linux user, and one compromised site must not be able to read or change another.
- Home folder permissions. No account should be able to list or read other home folders. Never use 777 permissions.
- PHP per user. Run a separate PHP-FPM pool for each account, running as that account's user, so PHP code can only touch its owner's files.
- Resource limits. Limit CPU, memory and processes per account so one busy or hacked site can't take the server down.
- A file-system jail. CloudLinux (a commercial distribution compatible with AlmaLinux) adds CageFS, which gives each user a private view of the file system, plus per-account limits. Control panels such as cPanel and DirectAdmin support it.
5. Harden PHP
Set these in the PHP configuration for each version you offer:
| Setting | Recommended value | Why |
|---|---|---|
| expose_php | Off | Hides the PHP version from response headers |
| disable_functions | exec, shell_exec, system, passthru, proc_open, popen, and similar | Stops uploaded scripts from running system commands |
| open_basedir | The account's own home folder | Limits which files PHP can open |
| allow_url_include | Off | Blocks remote file inclusion attacks |
| display_errors | Off in production | Keeps paths and queries out of visitors' browsers |
Offer only PHP versions that still receive security fixes, and move customers off end-of-life versions on a schedule you announce in advance. Disabling functions will break some applications, so tell customers what is disabled; our own list is explained in PHP disabled functions on shared hosting.
6. Add a web application firewall and malware scanning
- Web application firewall. ModSecurity with the OWASP Core Rule Set blocks common attacks such as SQL injection and cross-site scripting. ModSecurity is now maintained under OWASP; Coraza is a newer compatible alternative. Commercial suites such as Imunify360 combine a WAF, malware scanning and PHP-level protection under one licence.
- Malware scanning. ClamAV (from EPEL) is a free scanner; schedule regular scans of home folders and review the results before deleting anything. Commercial scanners detect more web-specific malware and can clean files automatically.
See understanding and implementing a web application firewall for how rules and false positives work.
7. Remove what you don't use
Every running service is something to patch and something to attack. List what is listening and what is enabled:
sudo ss -tulpn
systemctl list-unit-files --state=enabledDisable services you don't need with sudo systemctl disable --now name and remove unused packages with sudo dnf remove name.
8. Audit, monitor and back up
- Audit regularly.Lynis (from EPEL) checks hundreds of settings and suggests fixes. Run it after setup and after major changes.
- Watch file integrity.AIDE, or Wazuh for a fuller host intrusion detection system, alerts you when system files change.
- Read your logs.Logwatch mails a daily summary; a full ELK stack is usually too heavy for a single server.
- Monitor from outside.An external uptime check tells you when sites go down.
- Back up off the server.Keep account backups on separate storage, keep several versions, and test a restore.
When you host other people's sites, you will receive complaints about spam, phishing and copyright. Have a process for investigating them and suspending an account quickly, and keep customers' data under the rules that apply to you, such as India's Digital Personal Data Protection Act, 2023.
9. Where Domain India fits
A Domain India VPS gives you root access and is self-managed: you install, secure and update everything yourself. cPanel is not offered on our VPS plans; the control panel options at checkout are none, CyberPanel, Webuzo or DirectAdmin. If you would rather resell hosting without running the server, look at our reseller hosting, where the servers are managed for you.
- 2 vCPU
- 4 GB DDR4 RAM
- 128 GB NVMe SSD Storage
- 3 TB Monthly Bandwidth
- 4 vCPU
- 8 GB DDR4 RAM
- 256 GB NVMe SSD Storage
- 5 TB Monthly Bandwidth
The cards show live Domain India list prices, excluding 18% GST. For general VPS hardening beyond hosting, see essential security and optimisation tips for your VPS.
Frequently asked questions
Is CentOS still safe for a hosting server?
No. CentOS Linux 7 reached end of life in June 2024 and CentOS Linux 8 at the end of 2021, so neither gets security updates. Use AlmaLinux or Rocky Linux for a new server and migrate old CentOS servers.
What is the most important step in securing a shared hosting server?
Isolating accounts from each other. Run each site as its own Linux user with its own PHP-FPM pool and resource limits, so a hacked site can't reach its neighbours.
Should I change the SSH port?
It reduces log noise from automated scans but doesn't stop a targeted attacker. Key-only login, no root login and Fail2Ban matter far more.
Is CSF still a good firewall choice?
Not for a new server. ConfigServer stopped developing CSF in 2025. Use firewalld with Fail2Ban on AlmaLinux or Rocky Linux.
Do I need to do this on Domain India shared hosting?
No. On Domain India shared hosting the server is managed for you, and you can't change its configuration. This guide is for a server where you have root access, such as a VPS.
Does Domain India secure my VPS for me?
No. A Domain India VPS is self-managed. You have root access and are responsible for updates, the firewall, security software and backups.
Ready to build your own hosting server? Compare VPS plans, or choose cPanel hosting if you would rather have the server security managed for you. Questions? Open a support ticket.
Root access on KVM virtualisation, with AlmaLinux, Rocky Linux and other current Linux choices.
See VPS plans