HN user
pert
From: http://lists.grok.org.uk/pipermail/full-disclosure/2009-July...
1) Register 'Anti-Sec ' with Free Mail Provider 2) Claims to Full Disclosure 3) ???? 4) PROFIT.
brilliant
Not according to the subject of their post:
OpenSSH <= 5.2 zero day exploit code
Doh!
I got burned about 10 years ago by 'samba' not doing what I thought I'd told it to. I used the 'bind interfaces only' configuration directive, which I thought would prevent it from opening any ports on my Internet interface. I was wrong.
Unfortunately I also had no idea about the concept of security patches and, to this day, I still have no idea how I should have gone about getting security updates for Slackware (I switched to Debian and never looked back). The result was some script kiddie got root and started to use my box to start scanning for more vulnerable samba installations to break.
My response was to unplug all of the network cables and have a poke around to see what he'd been up to. I took a full backup of the box and then re-installed it from scratch as I couldn't trust it.
I learned that you should always look at what ports you have open (`netstat -lpn` is my favourite command for this) and that there are some times when a firewall might be of use (I'm not a fan of firewalls on anything other than gateway boxes).
I'd say the the single most important thing that you've mentioned there is 'logcheck'. If you can remove all of the login spam (by moving ssh to a non-default port for example), then watching your logs becomes a reasonable task and will alert you to any specifically targeted attacks.
"If I have to change it every XX days, I tend to pick very easy to remember passwords, and just change a digit at the end of it every time. As a result of this password "enhancement" system, I think I personally have much weaker passwords."
Assuming that "XX days" === 'less than 100 days', I totally agree.
We use a six month password cycle at work, and I think that's reasonable as it only takes me a few days to remember a password that I use tens of times a day. If it's a password that I use less frequently or a change is mandated more frequently, then I would do the same as Bruce and use something more obvious or only make small changes to the password each time.
The price comparison sites that don't contain reviews but do manage to come high up in a Google search for 'X reviews'.
This may be a good introduction to BSD (I don't know BSD at all so can't comment on that side much), but it certainly isn't representative of modern Linux kernels and distributions.
"Last modified: $Date: 2005/04/15 06:38:18 $" explains a lot.
I don't mind that, but I do like to make the distinction between the two.
Cracker news on Hacker News.
Related to:
http://news.ycombinator.com/item?id=648806 (LxLabs boss found hanged after vuln wipes websites) same story on the register
and
http://news.ycombinator.com/item?id=648788 (Hack wipes out data for 100,000 sites)
and
http://news.ycombinator.com/item?id=646451 (VAServ 'hacked' - all web sites and hosted VMs down)
Related to:
http://news.ycombinator.com/item?id=648788 (Hack wipes out data for 100,000 sites)
and
http://news.ycombinator.com/item?id=646451 (VAServ 'hacked' - all web sites and hosted VMs down)
More information is available in my other post on the subject:
I can hardly believe what I'm reading here ('ISSUE #24' is the most impressive):
http://securityreason.com/wlb_show/WLB-2009060016
"Kloxo (Previously Lxadmin) The most flexible software on this planet. From Kloxo HostInaBox, World's lightest and the most efficient webhosting platform, to Kloxo Enterprise, which can manage 100s of thousands of domains on hundreds of servers."
It's 'flexible' a euphemism for 'full of holes'?
Hmm... I can't seem to edit the main URL and the status page seems to have moved here:
Can anyone edit the URL for me?
Lots more chat here: http://www.webhostingtalk.com/showthread.php?t=867100
Can you say 'oops'?
I was looking for the change-log for 'HyperVM' and found this thread on their own user forum, where some users are requesting a change-log!
Why do you need this? Google will accept mail via authenticated and encrypted SMTP so you can use standard tools to send your mail.
If you're looking to configure mail from your slicehost and you do go with the Google Apps option (that's what I use), you might like to have a look at this guide to getting sSMTP working with Google:
I can't recommend sSMTP enough to anyone that doesn't want to maintain a mail server. All UNIX systems should be able to send mail and this is very much still the case on modern Linux systems, but this is often overlooked.
I don't think that a hosting company that monitors their servers deserves this much credit. I have a few co-located boxes for personal projects and, even though the services they run aren't that critical, I still monitor them using Nagios. It's not hard and it should be something that every systems administrator sets up as a matter of course.
I do, however, agree that 20 minutes down-time for a hardware failure is impressive. I wonder if they just yanked the disks from one box and jammed them in a spare?
I am a Linux sysadmin for a large company and I can say, without any hesitation, that we would love this! In our case, there aren't _that_ many systems that "absolutely cannot be rebooted" but scheduling a reboot on any system does take significant time and effort.
Why don't you think that the Linux vendors won't support this? I can see it taking some time to be introduced, but there'll be a lot of corporate customers out there who would be interested in this and, as long as the process of generating a new patch doesn't take too long, I can't see any reason why this process can't be used by the commercial Linux vendors.
I only resort to the 'new' page once I've read everything on the front page, everything on my other news bookmarks and am still bored.
AFAIK Google has done all of these things for some years. I regularly use it for the sorts of calculations mentioned in this article, such as:
The article didn't need to be more than the title and the picture, but that's modern "journalism" for you...
The problem for most ISPs, in the UK at least, is not the last mile but actually the last hundred miles. We have one Telecom monopoly: BT and one cable monopoly Virgin Media.
I agree with you that costs to Virgin Media should be quite low, as they own all of their infrastructure and most of it has been in place for 20 years or more.
The problem for the ADSL ISPs in the UK is BT. There are some IPSs which have installed their own equipment in BT's telephone exchanges and hence only pay BT for use of the 'last mile', but most of the ISPs in this country have to pay BT for not only the 'last mile', but also for the hundred or so miles before that. BT charges the ISPs based on how much bandwidth they consume, so for the majority of Internet users in the UK, the amount of bandwidth they consume is an important cost to their ISP.
I'm into music?
I wasn't particularly interested in the article, but do love the title!