How to protect the xampp directory?

brainknight wrote on Sunday, November 30, 2014:

Dears All,

I am asking about How to protect the xampp directory on drive C: at the customer server?

Please if any ideas about securing and protecting the directory to prevent coping, accessing or modifying.

Thank you in advance.

Regards,
B. K.

blankev wrote on Sunday, November 30, 2014:

Hide he directory. Give it a different name.

Login computer with password, Login and only give permissions to change files for administrators, Login with the severe restricted password for OpenEMR and ask to change password frequently.

Last resort: Put the Server in a fire proof, underground-, hurricane-, and earthquake- proof bunker and throw the keys away. If they find the bunker at least they can’t access any files.

blankev wrote on Sunday, November 30, 2014:

It is also advisable to go to the XAMPP site and see what advise they give to make everything optimal secure.

Make frequent back-ups and store them is a safe place. or even different safe places.

fsgl wrote on Sunday, November 30, 2014:

The only way to prevent OpenEMR from being hacked is to take it offline.

Since this is not possible for many practices, do the following:

  1. set up XAMPP Security Console, see part 5.
  2. secure OpenEMR & harden Apache.

For more secure communications between multiple sites, consider:

  1. VPN’s.
  2. 2 step authentication, second with tokens. Ideally it should be 3 steps.

brainknight wrote on Monday, December 01, 2014:

Thank you Pieter W. and fsgl For your advices.

I will take care of all that, may be will get back to you.

My Regards.

B.K.