Email & VPN & Web Security
			Feb 2, 2008
				questions about web security and my problems .Please help me about that problem.
1)I have email on Gmail and yahoo. frequently. i saw some changing in my settings in gamil and yahoo and orkut accounts.
sometimes i see somebody remove some items.
Somtimes i see somebody sent mail by my email!  
2)Unfortunately,Yahoo,Gmail & orkut do not get any information about last login and last log out.
But i see many simple forum's software give to user this info.
3) Iranian government has forbidden many websites so in iran many people use VPN for access to filtered websites ( censored websites).
Some person in Iran selling VPN account and we set IP and get some setting info for creating an VPN account.(tunneling)
4)I heard all Iranin ISP is controled  by political police of Iran.
************
Q1) Is there any famous and secure email provider that:
a) after login i can see my last logout and last login in my panel like vbulletin?
b) I can capture  LOG, so i can see in what date&time in what person sent mail by my account?
C) Is there any email provider that in login check CPU ID or other hardware ID and if these are legal and belong to that user, login possible?
Q2) Can  Owner of VPN access to secure information of useres?
Q3) Is there any technical method  that an ISP can access to email and other account of users?
for example Cookie robbing or listenning?
Q4)If i buy Satellite receiving and my sending provider is an Iranian ISP.
security will be better?
	
	View 0 Replies
  
    
	ADVERTISEMENT
    	
    	
        Oct 3, 2006
        I have two domains that I haven't set email up for yet. One is hosted on a good plan that uses cPanel. The other has some not-so-user-friendly interface.
Either case, I haven't set up email because I don't know what to seperate between truth and fiction. I know of the front end measures of cloaking an email link to your site using hex or some other hack so it doesn't show up to spiders and bots.
I also heard a rumor that using generic "webmaster@" on any domain is a surefire way for these bots to spam through. So is that true? Should I name my link like "thiswebmaster@" instead ? (or to that effect?)
What can I do to prevent too much (relatively speaking I guess) spam coming in?
	View 0 Replies
    View Related
  
    
	
    	
    	
        Mar 31, 2007
        security email service for some business email at mynamedomain.com. Can you recommend such service that is impossible to hack?
I use Mail 2 client (Mac OS X). Does it have security options?
	View 4 Replies
    View Related
  
    
	
    	
    	
        Apr 4, 2008
        I run a web hosting company and one of my servers is a LAMP server running CentOs 5. A user of mine has a Joomla installation running to manage his website and he has run into the following problem that I am puzzled by.  
When Joomla adds a component or module to itself, or when a user uses the Joomla upload functionality, Joomla will add the new files under the user name "apache".  This makes sense as it is the apache service running PHP that is actually creating the files.  
However, when he FTP's into the account to modify these files, he doesn't have the appropriate permissions to do so as he doesn't have a root level login, just permissions on his home directory which is the site.  Any help would be much appreciated.  
Also, does anyone know how to change the owner/group of a directory and all of its sub directories in Linux without changing the actual permissions?  I.e. some of the files in the folder have different permissions (0644 as apposed to 0755) than its parent but if I do a top down user/group change on the folder it will change everything in that folder to 0755.
	View 10 Replies
    View Related
  
    
	
    	
    	
        May 28, 2015
        I'm having difficulty sending an email to another email address (with a different domain) which is on the same VPS.The trouble is, on the other domain's VPS control panel, within the DNS settings, the MX records have been pointed externally (to an exchange server). Their email is turned off. But bizarrely, their mailbox is full. 
It seems as though Plesk is ignoring the MX records, and sending MY email internally to the OTHER domain's mailbox on the same VPS.How do I get Plesk to send my mail to the correct EXTERNAL MX records?
	View 4 Replies
    View Related
  
    
	
    	
    	
        Jul 18, 2009
        I had a email address I deleted on my server (postfix on Debian 4), but to my surprise the server still recieves email for the address!
(I have manually tried sending a email to the address and it comes througt).
I have deleted the address from the /etc/postfix/virtual file and restarted postfix. 
What could I have forgotten?
	View 7 Replies
    View Related
  
    
	
    	
    	
        Feb 13, 2007
        One of my customers asked me if is possible technically to offer free email services.
Since he's going to launch a big portal he want to offer such things later, for all users.
Now, there are problems as:
a) if there is any possibility to compress emails similar with GMAIL or YahooMail or so, because i can't imagine the email is uncompressed
b) how can be handled email boxes over multiple (mail ?) servers if the HDD space needed would be larger than for one server HDD ?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Oct 27, 2009
        I am having an email issue and I can not resolve.  I am hoping for some assisstance here.
One of my local clients are not able to email each other in their office. (About 10 employess I believe)
They are using Outlook mail client, and using ISP's SMTP server.  They are able to send/recieve email to other users externally, but not intenally.
Using webmail works perfectly fine.
I spoke with my host and the said everything is working fine.  I checked with the ISP to see if they are blocking the IP address on the SMTP server.  They said they were not.
I have a personal account on the same server and tried to send email to another local email account, and it did not work either.  Tried to send email to my clients email and they did not recieve anything.
I am on the same ISP as my client, so Im still not sure if its the ISP or not.
	View 11 Replies
    View Related
  
    
	
    	
    	
        May 19, 2007
        I setup mail piping with Exim so that e-mails sent to a specific account be forwarded to my PHP script. It's not working properly, because when I send a mail to this account, it's bounced by the mailer daemon:
Code:
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
 pipe to |/home/user/public_html/support/parse.php
   generated by support@mydomain.com
   local delivery failed
In my /etc/valiases/domain.com file I have:
Code:
support@mydomain.com: "|/home/user/public_html/support/parse.php"
*: :blackhole:
What can be causing the error? 
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jul 16, 2009
        I have regarding hosting/designing my application. Users of my website upload highly sensitive files to the server. I'll use SSL but will that be enough since the files are not encrypted on the server. I tried to encrypt the files but that is adding a huge overhead. 
My first question is - is it a good idea to store the files on the server rather than a database? My other question is regarding hosting; I'm thinking of building my own server and host it in a colo. Is colo more secure than dedicated hosting? Currently i'm still in the process of developing my App and my environment is Windows Server 2008/SQL Server 2005.
	View 13 Replies
    View Related
  
    
	
    	
    	
        Feb 9, 2007
        Is there any problems with having duplicate rules in different files as I have downloaded some rules and am going to make them all into one file to give me the best protection, but this is going to take time and I really need some sort of protection now
	View 2 Replies
    View Related
  
    
	
    	
    	
        Aug 25, 2007
        after install ConfigServer Firewall i get the following ...
ConfigServer Security & Firewall - csf v2.89 >>
PHP Check >>
Check php for register_globals >>
WARNING >> You should modify the PHP configuration (usually in /usr/local/lib/php.ini) and set:
register_globals = Off
unless it is absolutely necessary as it is seen as a significant security risk
must i modify it?or not? put in ur consideration i tried to download it to modify an error occured!
	View 2 Replies
    View Related
  
    
	
    	
    	
        Aug 24, 2007
        I am on a shared server account with Lunar Pages basic hosting plan.  
The only script file I have up running is db Masters FormM@iler.  It runs on Cpanel.  I deleted whatever other scripts I could find on my server.  The site is just basic html pages with jpgs and a gif.
Is there much else I really need to do to secure the server or is that more in Lunar Pages' hands?  
If there is still more I can do to secure the server, and is it a small amount that's easy to do or would it be wise to just hire someone else to put in a few hours making sure everything is truly set up securely? 
	View 5 Replies
    View Related
  
    
	
    	
    	
        Apr 23, 2007
        I have a vps that has been exploited, and the hosting company is giving me advise on what to do to fix the security problems, but i need a good server administrator/company to help me with this. can anyone recommend a company that will go thru my server, 
	View 8 Replies
    View Related
  
    
	
    	
    	
        Mar 27, 2007
        I'm inheriting a website that is currently a mess. It was designed in Joomla, but everything about the site by the original designer, is completely a mess. Files weren't placed in their proper directory hiearchy, the site has been hacked into a few times...basically a big headache.
I'm willing to learn and my first goal is the redesign the site. Currently, I'm looking at choosing a CMS or just rebuilding it in Joomla. The problem is that the site is a big part of the business, so any down time is not good.
I have some questions I hope you experienced folks can help me with...
Does CMS choice have any bearing on whether or not its a security vulnerability? If so, which one's are "less a target" of getting hit?
I just want to design the site from scratch and make it secure as possible from suggestions on various forums. I don't want to be a security admin, but is that what I'll end up having to do to run a site like this?
What are my options between "doing it myself" vs "hiring a third party"?
The company is right now in a tween stage. Fast growth but not enough to hire a security guy, based on my talks with the CEO. I disagree with this, but what can I do in the meantime to plug the site holes?
I'm almost wanting to go commercial so I don't have all the headaches, but the company wants to save money. What can be done in those situations?
Before I go out and spend money on books, what do you recommend I buy to start getting my feet wet in what may become a future in IT security?
This is from someone who's just inherited a dedicated server with a swiss cheese website. What is the first order of business for someone who is in the dark and will not get much support in regards to spending more money?
how do I secure my site "on my own"?
	View 5 Replies
    View Related
  
    
	
    	
    	
        Feb 26, 2007
        I noticed that my vps had utilized 250 gig of traffic in one day [i average 5 gig per MONTH] with cpu usage of close 100%; my hosting company pinpointed one php file which had allowed an outside varibale to be placed in "include" function so that the outside php code was being run; 
Is there any program/scripts that can immediately email me if  cpu usage stays high 
the nic card is being utilized too much memory usage exceed certain levles this way, i would know i have been hijacked in time and try to find the culprit i use knownhost with cpanel/linux mysql and php.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Jul 21, 2007
        i have an unix server [don't know what version i think it's FreeBSD ]
[url]
and i use WS_FTP to upload the files to my server.. but i have a big problem  all my files are encrypted with some problems but when people use getrigh browser or some kind off program to acess my server instead of a normal browser it appears the list of files i have upload and they can download them  and when i set password for images etc it's all safe, but people can't acess parts of the site without password... i want to know if there's some way of protect my file without interfering with the normal browser acess. 
	View 9 Replies
    View Related
  
    
	
    	
    	
        Jul 24, 2007
        when we run server with shared hosting. we mostly facing issue os security like c9shell scripts.. as well as ppl hacked database or changed index.html. we do enable php open base dir as well as mo security firewall we do search which user is using find command who is uploading file... but is there any other way to secure server for such hacking issue..
	View 5 Replies
    View Related
  
    
	
    	
    	
        Mar 26, 2007
        I have run rkhunter and got message saying that /bin/dmesg [BAD]
# rpm  -qf  /bin/dmesg
util-linux-2.12a-16.EL4.20
# rpm  -V  util-linux-2.12a-16.EL4.20
.M......    /usr/bin/chsh
It looks like RPM damaged? How can I confirm it? 
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jul 10, 2007
        When securing a vps system, do things like Enable Shell Fork Bomb/Memory Protection use much memory or any other secuirty measure?
	View 3 Replies
    View Related
  
    
	
    	
    	
        Oct 31, 2007
        We have a e-commerce web site that has  the latest shopping cart software ( that is known to be secure) ssl cert, etc.
We got a call today from a guy who says that he used his brand new card on our web site and that the card was stolen and used on anothoer site within hours. We have checked every file on the web site, logging into serevr root and checking everything and cant find any evidence of a hack or security breach of any kind.
can someone recommend a  reliable company that can go in and check things out for us to see if they can find anny security issues, or evidence of a breach? There must be a company out there that does this sort of thing
	View 4 Replies
    View Related
  
    
	
    	
    	
        Apr 8, 2008
        I am conducting some research into potential risks that web hosts have to deal with on a daily basis. What potential security risks are there for web hosts ? And how do they overcome these issues?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Jun 7, 2009
        For security reason I have these php functiosn disabled:
show_source, system, shell_exec, exec, popen, proc_open, procopen, passthru
Can anyone please tell me whether if it will prevent shell scripts from working?
They can still upload the shells but cant read/write/execute commands in 777 directories?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Jul 16, 2009
        I want to setup a Windows 2003 security policy to filter traffic.
I want to let most of the world through to port 80 so maybe just ban a few nuicance IP's.
But then I have a POP / IMAP server, VPN, SMTP, etc that I want to block all but UK IP addresses.
I know I can do this through the MMC snap in but this is 1000's of IP's.
Is there a way I can import a list/range of IP's that I want to block from a country IP database?
	View 14 Replies
    View Related
  
    
	
    	
    	
        Oct 9, 2009
        I have a Linux server in which i have two NIC's one is for the LAN and other is for the Internet
[root@nebula etc]# ifconfig
eth0      inet addr:192.168.1.101  Bcast:192.168.1.255  Mask:255.255.255.0
          
eth1      inet addr:192.168.1.102  Bcast:192.168.1.255  Mask:255.255.255.0
          
How can i test security between the Internet Nic and the LAN Nic to be sure no security leaks exist. 
I can only access the server remotely no GUI but can install packages.
	View 4 Replies
    View Related
  
    
	
    	
    	
        Mar 23, 2009
        I am getting more into it and looking for the best way to harden it and secure it. Also some information about what processes to turn off and how to better setup my IP Tables.
	View 8 Replies
    View Related
  
    
	
    	
    	
        Apr 24, 2009
        So I've been using WHMCS for a while, and there's something I'm a little concerned about with the whole keeping customers credit cards for recurring payments.  
I've downloaded a backup copy of the database and I see that the passwords and credit card information is encrypted. That's all nice and handy but the CC hash is also stored right in the configuration file. That means that if someone gains access to the server and just grabs the database + config file they would then be able to view all that info correct?  Maybe someone who knows a little more about WHMCS can tell me if this is correct or not? 
	View 1 Replies
    View Related