Tag: Security

  • Evading Webapp Vulnerability Scans

    Most attackers aren’t after your digital property or information stored on your server.  They’re mostly after your server for its resources to send spam, host phishing sites or launch attacks against other servers.  So unless you’re running a high profile site or have managed to anger a malcontent, your server likely isn’t going to be…

  • WordPress Upgrade Script 2.8.5

    Heres a little Shell Script I wrote which, if run, will check your entire server for insecure versions of wordpress.  If it finds any, it will give you the option to upgrade. If you say yes it will backup the existing sites file and database in /root/wp_upgrade and upgrade it. Please Note: This has not…

  • Spam Addresses

    I hate spam.  I really hate spam.  I guess everybody can relate to that.  I not only hate spam, but I don’t like receiving correspondence from some website that made me register to view some content or post a message, some site that that I’ve ordered from or any other place that I’ve had to…

  • checking the checksums of your binary packages

    Occasionally you just want a bit of piece of mind about your server or Linux install. You may suspect there is somebody who has hacked your computer or even something changed by a package install that shouldn’t have been. Heres a couple of ideas on how to do a quick ‘health’ check on he md5sum…

  • Unsure who is sending spam? Try this

    Anyone who has hosted peoples websites before, has had  either a blog hacked, or some guy thinking he is going to send mass mailouts using PHP or similar happen. Its extremely hard to trackdown and deal with, and yet it can get your server listed at spam service denying legitimate email from getting through. This…

  • Does your VPS have MD5 enabled for passwords?

    We recently discovered that the way we install a VPS differs slightly from the usual CD install. This is not something we do specifically but something that can be improved on in the set-ups of CentOS5.3. When you install from a CD it automatically enables MD5 encryption in passwords (which should be the norm), however…

  • Has your VPS been hacked?

    If you use any pre-packaged software, it always pays to sign up to their mailing list or security advisory list. This means if any exploits or updates happen, you are on the ball and up to date. Today we had an email from a customer whos front page had been replaced. I noticed it was…

  • Safe rm prevents accidents! try it!

    I found this the today http://www.safe-rm.org.nz/ , and having had the odd accident im most definitely going to be installing this on my own server! What is safe-rm? Safe-rm is a safety tool intended to prevent the accidental deletion of important files by replacing /bin/rm with a wrapper, which checks the given arguments against a…

  • We’re a Team

    We see lots of different problems every day as Liz noted the other day.  It’s really quite varied work that we do and you can go from resetting a password one minute to setting up load balanced proxy servers the next.  There’s always a fun and challenging problem right around the corner. The most important…

  • David’s Handy Scripts – bandwidth usage – disk usage

    I thought a useful addition to our blog might be a running series of handy scripts.  Just for the sake of things (and because I couldn’t find a better title), I’m calling the series “David’s Handy Scripts”.  I’ll get this show on the road with a quick script I put together to track 2 things…