HN user

wwdevries

182 karma

wwdevries.net

Posts11
Comments27
View on HN

Patchman | http://patchman.co | ONSITE or REMOTE | Enschede, The Netherlands

Our customers comprise of large web hosting providers all around the globe. Security is – obviously – extremely important to them. However, there’s one layer of the security stack they have little or no control over: the code of their end users. Most websites use standard software as a foundation. Did you know that about 30% of the web is running on WordPress, Joomla or Drupal? Hackers continuously exploit security vulnerabilities in these foundations to upload and execute malware. Effectively, this allows hackers to run any malicious code they want. For example: to send spam, launch DDoS attacks or inflict far worse damage.

Patchman comes to the rescue! We offer web hosting providers a fully automated SaaS solution to index security vulnerabilities/risks and resolve them by automatically applying safe backported patches and by defusing malware. On top of that, we offer a web app that helps all stakeholders (including security officers, system administrators, helpdesk employees and end users) to operate Patchman and keep the web secure.

We're currently hiring for three positions:

### Software Engineer: Threat Analysis & Response (PHP) ###

Info & apply: http://jobs.patchman.co/software-engineer-threat-analysis-re...

### Software Engineer: Back-end (Python/Django) ###

Info & apply: http://jobs.patchman.co/software-engineer-back-end

### Software Engineer: Linux Security R&D (C/C++) ###

Info & apply: http://jobs.patchman.co/software-engineer-linux-security-rd

We run scheduled scans and very soon we'll be hooking into Apache, FTP, etc. But Patchman is actually preventing malware from being uploaded in the first place by fixing vulnerabilities before they get exploited.

Also, most malware is not executed right after uploading. They usually wait for the weekends.

Malware is by definition self contained and can simply be removed. We move the file to another directory, so it cannot be executed.

Regarding security vulnerabilities, we specifically patch only those vulnerabilities. This way you can be rest assured that your customer's websites continue to function properly.

Patchman (http://www.patchman.co) - Enschede, The Netherlands (or remote) - Full time

Hosting providers suffer on a daily basis from the consequences of the many security vulnerabilities found in commonly used PHP applications such as WordPress, Drupal and Joomla. It is a frequently used entry point to deface customer’s websites and upload/execute malware. Besides this being a significant security risk, it also causes an unstable hosting platform and unhappy customers.

Patchman patches vulnerabilities before they get exploited. Best of all, customers won't even notice! Patchman helps hosting providers to achieve substantial savings in operational costs, increase customer happiness and reduce their churn rate. To support Patchman’s rapid growth, we’re looking to expand its team.

Read more: http://patchman.co/downloads/software_engineer.pdf

Shameless plug: if you're a shared hosting provider you should check out http://www.patchman.co.

Approximately 30% of your hosting accounts run an outdated version of WordPress, Joomla or Drupal with serious security vulnerabilities. These vulnerabilities can be easily exploited to run malicious code. But you already know that, since you're getting sick of all the spam runs and DoS attacks that are continuously being launched this way from your platform. Not to mention the more serious attacks. Aren't you tired of cleaning up after your customers?

Patchman runs on your platform and automatically detects and patches vulnerabilities in WordPress, Joomla and Drupal core (without breaking the application!). It will also automatically remove malware. On top of that, it takes care of all communication with your customers. It integrates with all the popular control panels, such as cPanel, Plesk and DirectAdmin. Saves you a lot of headaches and puts you in control of this mess :)

Hangouts for iOS 13 years ago

Now that Google is pushing Google+ even harder in everything new they launch.. I just wish Google would somehow make it possible to merge two Google Apps accounts into one public Google+ account. Now I have to manage multiple Google+ which makes me feel a little schizophrenic and it's confusing to other people who aren't sure on which account to connect with me. It's getting messy.

Tested the exploit on CentOS:

Linux 2.6.32-358.6.1.el6.x86_64 #1 SMP Tue Apr 23 19:29:00 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux (latest CentOS kernel):

  [user@centos ~]$ gcc -O2 exploit.c 
  [user@centos ~]$ ./a.out 
  2.6.37-3.x x86_64
  sd@fucksheep.org 2010
  -sh-4.1#

I'm sorry, I think due to our lacking description of how the technology exactly works you're confusing it with existing technologies. What we announced today is not comparable with something like Installatron, they do just version updates. Those automatic updates usually breaks plugins. We only patch the vulnerabilities, without modifying any functionality.

Thank you for your interest. The service focuses on fixing vulnerabilities in commonly used and popular software solutions such as WordPress, Drupal and Joomla. So, currently, we do not fix handwritten SQL injection vulnerabilities.

On a technical level it differs primarily on that it's not an external service that can only start responding after the website has been hacked; they treat the damage caused by a successful hack instead of preventing the hack in the first place. Because we can scan the code itself, we can actually patch vulnerabilities before they are being exploited. The beauty is in that we do not do "normal" updates but just patch the vulnerabilities in a non-obtrusive way, this prevents the website to fail because of incompatibilities.

Congratulations to the 37signals team on launching the all new Basecamp. Just migrated our projects from Basecamp Classic and it's working beautifully.

Just start. Usually the problem is that you unnecessarily look up to your tasks. You think it's boring, difficult, or you don't know where to start. Just start. Once you start, you get into a positive flow and become motivated to finish it.

Coincidentally I noticed that both Simple and Square do not mention anything (anymore) about who they are. No about page, no team page, no nothing. Especially with companies that are all about your money, I'd at least like to know who's running the shop.

Since it's pretty much the standard for startups to tell about themselves on their web site, this must have been a deliberate choice. What advantage does it have – especially in the case of Square and Simple – not to show who you are?