Secure /tmp (noexec, nosuid, nodev )
mod_security
Secured /root/.my.cnf
Block all outgoing connections to port 22 using iptables
Latest Secure Stable kernel
C and C++ compilers are disabled. Many canned exploits require
a working c on the system
Linux Environment Security:
Root-only permissions on binaries, path traversal, immutable
bit on rpm, shell scripts
Linux Socket Monitor
designed to track changes to Network sockets and Unix domain
sockets