-
How to get an A pass SSL rating for your SSL website
Everyone wants security, and its ideal that your SSL certificates are also secure. With this in mind, websites like SSLLabs have a testing tool that is used to grade the SSL certificate installed on your server. Often people get a low ranking when its fairly easy to get an A. I could make this post…
-
Monitor sites for exploits
We dislike dealing with exploited websites. A common cause is “the long forgotten outdated install from a web developer who left years ago. hoping works forever”. Public facing services need to be kept updated in order to remain secure, so script-kiddies can’t use your server for abuse, like selling dodgy medicinal products. One would always…
-
Brute force SSH protection
We have implemented some brute force SSH attack protection on VMs. Your servers should start to receive fewer connections from bots trying to bruteforce crack passwords on your server user accounts. Behind the scenes we have setup honey trap servers. Botnets with no good reason to connect to these servers attempt to connect to the…
-
deghost ridding the world of the ghost vulnerability one host at a time
As part of our mission to wipe the ‘ghost’ vulnerability (CVE-2015-0235) from our customers servers we have created ‘deghost’. Deghost is a cross-distro script to determine the vulnerability of a libc library on a server and then patch that where possible. https://github.com/pbkwee/distrorejuve In most cases this is as simple as apt-get install libc6 or yum…
-
Replace webmin self-signed certificate to avoid sec_error_invalid_key error
Recent browser versions (e.g. Firefox 33) refuse to work with older Webmin installs. They give a sec_error_invalid_key error, offer a ‘Try again’ button, but do not offer an option to add an exception. Firefox 33 no longer supports certificates with private keys smaller than 1024 bits. You can replace your webmin certificate with a new…
-
SSLv3 and securing against Poodle
If you are using SSL in your web server, you probably want to read this. Google recently published details about an attack that targets SSLv3. The exploit first allows attackers to initiate a “downgrade dance” that tells the client that the server doesn’t support the more secure TLS (Transport Layer Security) protocol and forces it…
-
NTP servers and DoS Attacks
NTP servers have been in the news over the New Year, as security sites and social media talk about potential attacks. This is important because many linux servers run ntpd to help keep their clock time correct. One of the first reports and some solutions are clearly described on litnet … In LITNET we recently…
-
Old tomcat 5.5 installs being exploited
We have noticed a couple of people running older tomcat 5.5 installs, and these are being exploited . The main thing we noticed were slowdowns on bandwidth as well as CPU along with a few odd other things running as tomcat user eg www-data 20654 0.0 0.6 38616 8004 ? S 21:26 0:00 \_ /usr/sbin/apache2…
-
How to restore your root password after forgetting or being exploited via Single user mode
-
Identifying exploits and exploited websites