---
title: Drupal Deployment Security Hardening
description: Tips for helping to add overall improvements to the deployment stack of a Drupal site.
image: https://email.networksgroup.com/hubfs/Blogs/hardening.jpg
---

- info@networksgroup.com
- [Contact Us](https://www.networksgroup.com/contact/)

- <https://www.facebook.com/networksgroupinc/>
- <https://www.facebook.com/networksgroupinc/>
- <https://twitter.com/networksgroup>
- [mailto:info@networksgroup.com](mailto:info@networksgroup.com)

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_300-154x42.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_1500px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

<https://email.networksgroup.com/drupal-deployment-security-hardening#sidr>

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

# NetWorks Group Blog

# Drupal Deployment Security Hardening

Posted by [NetWorks Group](https://email.networksgroup.com/author/networks-group) on Apr 16, 2013 11:38:00 AM

![](https://email.networksgroup.com/hubfs/Portraits/NWG.png)

Find me on:

[Facebook](https://www.facebook.com/networksgroupinc/) [LinkedIn](https://www.linkedin.com/company/networks-group) [Twitter](https://twitter.com/networksgroup)

- [Tweet](https://twitter.com/share)

Web applications continue to be an easy target for many attackers. There's generally a large attack surface, many best practices are often forgotten, and a single coding flaw can lead to a full compromise of the database or arbitrary code execution. Still, a quality Content Management System (CMS) can provide for a very functional web deployment and is hard to pass-up for many organizations.

Here are some thoughts and tips for helping to add overall improvements to the deployment stack of a [Drupal 7](http://drupal.org/drupal-7.0) site. While some of these items may not fit your deployment needs, you should still be able to find equivalent technologies to do similar hardening. As a further caveat, additional areas of hardening have been excluded since this list could go on for a few blog posts if we tried to fit in everything.

**Drupal**

- Patch all modules as soon as updates are available, preferably after you've tested them on a development site.
- Install and configure the module [Security Kit](http://drupal.org/project/seckit) to provide for additional protections against XSS, CSRF, click-jacking, and add HSTS for SSL.
- Utilize the [Tiny-IDS](http://drupal.org/project/tinyids) module to view attacks against your site. Add IP addresses attacking your deployment to a firewall or block via .htaccess.
- Investigate findings of the [Security Review](http://drupal.org/project/security_review) module to see any misconfiguration that may lead to potential issues.
- Integrate [Duo Security's module](http://drupal.org/project/duo) to provide for two-factor authentication, preventing simple brute-force attacks against weak passwords.
- If you don't utilize two-factor (or even if you do), please enforce strong passphrases to ensure that you're not compromised easily.

**MySQL**

- Limit exposure of your database service to only the loop-back interface (lo0) or, better yet, only to a socket (skip-networking in my.cnf).
- Use a separate user for Drupal, different from your 'root' MySQL account. Do not give more privileges than are required to run your site.
- If you're very concerned about [SQL Injection](https://www.owasp.org/index.php/SQL_Injection) attacks, you have the option to deploy an SQL security proxy such as [GreenSQL](http://www.greensql.com/).

**CentOS**

- Ensure a fully patched, current-branch of your Operating System deployment.
- Leave SELinux enabled and fix any incompatibilities that you run across (sealert -a /var/log/audit/audit.log).
- Similar to Drupal, utilize [Duo Security](https://www.duosecurity.com/docs/duounix) for two-factor authentication for SSH.
- Limit SSH access to internal networks or via VPN — don't needlessly expose it to the Internet.
- Utilize IPTables to firewall all ingress and egress traffic not explicitly needed to run your web site properly.

**Apache**

- Disable all modules not required to run the site properly.
- Set **ServerTokens **to *Prod *to reduce the amount of information the server discloses about its self.
- Utilize SSL for any pages with sensitive form data (such as logins) and ensure proper configuration with [SSL Server Test](https://www.ssllabs.com/ssltest/).
- Ensure detailed logging exists for all traffic, whether successful or resulting in an error.
- Limit visibility to sensitive pages or forms using .htaccess directives with authentication or IP requirements.

**PHP**

- Keep your system's version of PHP fully patched.
- Disable all modules not required to run the site properly.
- Set **expose\_php** to *off* to hide the specific version information of PHP running.
- Set **display\_errors** and **display\_startup\_errors** to *off* in order to prevent showing debugging information to end-users.
- Enable **session.cookie\_secure** with a setting of *1* in your server will be handling user sessions via SSL (which it should).
- Set **session.cookie\_httponly** to *1* to help prevent XSS attacks from stealing user sessions.
- Configure **session.hash\_function** to *1* for usage of SHA-1 instead of MD5 for session ID generation.

That concludes our overview of Drupal deployment hardening tips. While there are certainly other avenues, technologies, modules, and configuration settings possible to further increase security, this list would be considered a great start for most organizations. The best approach to security is one that has layered mechanisms to help provide a better, more holistic approach to mitigation. Before implementing any of these tips, however, you should thoroughly test each one in a sandboxed or development environment to ensure they work as you expected and have no adverse consequences for your deployment.

 Topics: [Information Security](https://email.networksgroup.com/topic/information-security), [Vulnerability Management](https://email.networksgroup.com/topic/vulnerability-management), [Threat Management](https://email.networksgroup.com/topic/threat-management)

### Subscribe to our blog!

### Stay Informed!

### Recent Posts

### Posts by Topic

- [Information Security (50)](https://email.networksgroup.com/topic/information-security)
- [Threat Management (34)](https://email.networksgroup.com/topic/threat-management)
- [Ethical Hacking (31)](https://email.networksgroup.com/topic/ethical-hacking)
- [Managed Detection & Response (25)](https://email.networksgroup.com/topic/managed-detection-response)
- [Penetration Testing (21)](https://email.networksgroup.com/topic/penetration-testing)
- [Vulnerability Management (12)](https://email.networksgroup.com/topic/vulnerability-management)
- [Compliance (11)](https://email.networksgroup.com/topic/compliance)
- [Security Monitoring (11)](https://email.networksgroup.com/topic/security-monitoring)
- [Healthcare (9)](https://email.networksgroup.com/topic/healthcare)
- [Threat Advisory (8)](https://email.networksgroup.com/topic/threat-advisory)
- [Threat Hunting (7)](https://email.networksgroup.com/topic/threat-hunting)
- [Security Architecture Review (6)](https://email.networksgroup.com/topic/security-architecture-review)
- [HIPAA (5)](https://email.networksgroup.com/topic/hipaa)
- [Device Management (4)](https://email.networksgroup.com/topic/device-management)
- [Incident Response (4)](https://email.networksgroup.com/topic/incident-response)
- [Events (1)](https://email.networksgroup.com/topic/events)
- [PCI (1)](https://email.networksgroup.com/topic/pci)

see all

###### About Us

NetWorks Group is a Managed Detection & Response (MDR) and Ethical Hacking Service provider. We help organizations detect and respond to advanced cyber security threats through a powerful combination of our proprietary threat detection platform, expertise and security tools. Our unique approach to security not only helps you stay ahead of cyber criminals but also helps you reduce cost and increase efficiency.

###### More Links

- [Home](https://www.networksgroup.com/)
- [Blog](http://blog.networksgroup.com/)
- [About](https://www.networksgroup.com/about/)

###### Contact Us

(888) 798-1012  
 info@networksgroup.com  
 www.networksgroup.com

- <https://www.facebook.com/networksgroupinc/>
- <https://www.linkedin.com/company/networks-group>
- <https://twitter.com/networksgroup>

© 2017 - NetWorks Group