I'm curious about what kind of security (both physical and software) people use for their servers. I'm hoping some discussion on this topic will help out newer server admins learn something (which includes me) and maybe help stop some servers from being compromised in the future.
My server is physically located in my home which lends a decent amount of physical security (if my home is physically compromised, I have more important things to worry about than my eqemu server). As far as software goes, it runs openssh with a fairly decent password for all accounts (random numbers/characters/symbols/capitals) with the root account disabled (ubuntu server does this by default) and
denyhosts. I do not have port 22 blocked on my router because I originally had planned on a friend or two sshing in to do work on it, but that didn't happen and I haven't bothered to close it (maybe I will now though). I still get about 10 attacks a day, mostly from other infected servers.