Hosting A High Risk Site
Mar 25, 2009What sort of redundancy that is recommended for a high risk site?
My definition of high risk is it will attract more hackers than usual, more DDOS, chances of blocked by ISP and etc.
What sort of redundancy that is recommended for a high risk site?
My definition of high risk is it will attract more hackers than usual, more DDOS, chances of blocked by ISP and etc.
We expect a site on one of our boxes to receive a significantly high level of traffic tomorrow as it is an event that will be covered and has already been covered by the press. The site operator expects > 100,000 hits a second.
It's a PHP page that pulls records from a database and lets people submit a form to insert a record. We have already put a caching script in place so that refreshing the page does not result in doing another database query.
The site was overloading a shared server, and we've moved it to one of our VPS boxes - it's the only VPS on the system at the moment. The box is a Quad Xeon 5410 with 4GB RAM with a 4 10K RPM drives in a RAID5 setup.
We currently have a website for our client developed on ASP.net with SQL
Its a straight forward web application with 2000 visitors per day
The traffic is going too heavy and its now at 130 GB per month
Our Queries :
Can we still have this site on a shared environment ?
If yes, suggest few providers offering high bandwidth
What other alternatives are there?
I own an anime linking site which you guessed it links to anime. I have around 10000 hits a day and would like a vps with litespeed since it's so much faster.
View 7 Replies View RelatedWe have a client that is normally low use. about 200+ hits per day. They are a non-profit, and get TV coverage (like the Today show, Dateline, NBC nightly news, and coming up here soon final 4 news spot) about once a month. When this happens, they get 60k hits a day.
they crash my dedicated server a few times. I have a dual p4 w/ 2 gb of ram. I only have 60 clients on this server, but as they get more coverage, our server cant take this many hits.
do you suggest verio for high traffic video site?
View 3 Replies View RelatedI am writing a financial statement for my business plan and like to know what numbers should I expect from the the host. If the potential traffic will reach 405,000 visitors a month what my requirements for the hosting company should be?
View 9 Replies View Relatedis there anyone knows for a good hosting located in uk,which is allowed : adult site and casino betting online site ?
im looking for vps and dedicated server.
please help me i really need as soon as possible.thx
My video sharing site has high traffic, alexa rate:3,000
My site has 2 servers to split the load. 2 servers share a mysql server. Using rrdns to load the balance.
Server A running mysql 5.0,lighttpd
Server B running lighttpd.
Server B connect to A's mysql database.
During peak time. B can not connect to A's mysql server. It says server not responding. But A still running fine.
When I check mysql log file.
/usr/libexec/mysqld: Forcing close of thread .....
And when run top, the load average is 20.
The spec of Server A
Intel(R) Xeon(TM) CPU 3.06GHz dual core.
2G Ram.
Here is the my.cnf
Quote:
[mysqld]
datadir=/var/lib/mysql
socket=/var/lib/mysql/mysql.sock
# Default to using old password format for compatibility with mysql 3.x
# clients (those using the mysqlclient10 compatibility package).
old_passwords=1
max_connections = 1000
wait_timeout=60
connect_timeout=10
interactive_timeout=120
join_buffer_size=1M
query_cache_size=128M
query_cache_limit=2M
max_allowed_packet=16M
table_cache=1024
sort_buffer_size=2M
read_buffer_size=2M
My question, do I need another maching C to run lighttpd, and just keep mysql on A.
Or I can do some mysql optimization on A.
Also, if my site keeps going, can I have 1 mysql server and 5 http servers?
my domain name expires in July (within 90 days).
It is currently with company A who charge quite a lot to keep it there. I want to move it to company B who are my hosts and with whom I get 1 free domain name.
One added complication is that the domain is in a friends name, but I have logon and can change name to my own any time I want.
Company B said "After it is on our registrar, you will be the only one that can renew it as long as it doesn't expire for longer than 90 days."
This has me worried that because I haven't renewed it withing 90 days that it can be stolen from me. Have I misunderstood or is this a risk?
If so would I be better advised to renew it in my friends name wth company A?
I'm a Windows guy and can little or nothing about Linux. How big risk do I take if I'm using a Linux VPS and never update/patch the kernel?
I'm using CentOS 5 and LxAdmin. I can update the control panel, but I can not update/patch the kernel since I have no knowledge how I do that.
I'm using a unmanaged plan, so no help there.
Some of my sites are running Wordpress, but I'm always using the lates WP installation. I not using any other plugins that WG2, Gallery2, and remove max width.
Nobody except me have access to the VPS, and I have no other FTP accounts or something like that on the VPS.
I have no other scripts or any kind of dynamic pages on my VPS.
What kind of risk do I have here?
I'm currently having plans to cancel my second VPS that's using Win2003, and only use Linux in the future. I can cut my monthly expensive with 50% that way, but do I take a big risk doing it that way?
A customer has requested we install a pear package called crypt_blowfish for there website which sells items.
What exactly is it? Is there any risk in installing the extension?
Ive not heard of it myself before
I'm trying to find at least three web hosting companies to choose from to host a Joomla websites on a shared server. Would consider dedicated if the deal was right. I have a friend of mine who wants to create a church website, and is looking for the best deal. I use Netfirms which I have never had an issue with, but I didn't want to be bias, and would like give him other options to choose from.
Is there a good WebHosting Review site, I could check out, or maybe someone could recommend their top three. I reading threw the forums here and I noticed there are not that many complaints with Hostgator. Again, I just want to see if there was anything out there better.
At present I run SSH on a different port then normal to protect root. This has worked for two years, but with discovering that cPanel finally support SFTP without shell access needed, I want to finally turn off FTP and require SFTP. The problem is the port I am using. Since it's a random port I have been secured against root attacks (well nothing has shown up). I am with LiquidWeb which is fully managed. So I guess they take care of allot of prevention.
This is what I am thinking of doing. move SSH back to port 22 (I only host a few friends sites and want to be hosting 20 accounts by end of year to cover my costs). Then disabled root password and require SSH keys. Would this be strong as secure as running SSH on a high #port or am I fooling myself.
I could also add in for good measure restricting root SSH/SFTP (yes I prefer SFTP for file management as I am legally blind and using Transmit+BBEdit is allot easier for me for editing files). The problem with restricting to certain IP's, is that Shaw charges $30/month more for a static IP and I also am at my moms 25% of the time (and she is also with Shaw). I think the XXXX.vs.shawcable.net is static but I am not 100% sure.
I really do want to kill FTP so that only port 80 is the only non SSL port open.
There are always people who would like to know what the php settings are on the server. Is it a security risk to share the phpinfo.php file on a website, with anybody who visits that website, able to view it?
View 4 Replies View RelatedA friend of mine owns a hosting company and a client of his asked to have mbstring and mysqli installed. What he wants to know is , is there any security risks if he does install that on his server?
Also, he wants to know, if there is not, what how does he go about installing that on the server?
Does writing large files (ie, 10GB backups in one archive) cause any risk of damaging a linux filesystem?
View 1 Replies View RelatedDuring my poking around performance tips I found the DELAY_KEY_WRITE option (and innodb_flush_log_at_trx_commit = 0 for innodb)
which supposedly for mysql will disable the immediate disk flush for every transaction written and instead update only once every second at most?
One thing I've never had to restart on my vps is mysql, it's been great. So is this safe to turn on? Am I risking corruption? Will the performance gain be worth it with only a 16M cache?
I need to put a proposal for a client who has 20 TB data storage (files/images).
Will propose PHP/mysql - mysql for meta data of files and other authentication etc. Application/mysql could just be ~10 MB.
The storage would increase (incrementally) ~ 1 TB per year.
And data needs stored at a different place for Disaster Recovery point of view.
Need to figure storage costing.
Please give me some pointers:
a) How to find high storage hosting provider?
b) Has any one experimented with Cloud Computing, and if so any ball park potential costing? I attempt S3 and could not figure costing.
c) or any other suggestion.
company that can offer me super fast php hosting. It will be large loads with upto 20 php requests a second, the load is so much that i am currently running mysql on a dedicated mysql server.
View 14 Replies View RelatedMy company are looking for a web hosting solution, that can handle sometime spike of 4000 connections at a time and not really a lots of Data transfers. Lets say 150 GB per month.
View 3 Replies View RelatedIm currently with host gator and have nothing but amazing things to say but i have a music streaming website and its eating up bandwith like crazy but at least the cpu usage of the shared hosting is not that high but i will definitley pass my 2 terabyte mark within the month. My question is even on the dedicated hosting plans on host gator they still dont offer a lot of bandwith so does anyone know any very reliable and good companies that offer a LOT of bandwith for a moderate price. I was looking at liquid web dedicated which offers 3 terabytes as i hear their super reliable and professional
View 7 Replies View RelatedI did a quick search on this and could not see it as already being posted
It seems quite a clever but simple idea - remove a lot of the oxygen from the air to help reduce the risk of fire. What do those of you operating your own facilities make of this? Is anyone already doing this?
[url]
I see in the maillogs a number of errors lots of different Certificate Authorities - and some I really did NOT expect to see here:
[root@web48002 admin]# grep ' certificate verification failed for' /usr/local/psa/var/log/maillog | wc -l
998
[root@web48002 admin]# grep ' certificate verification failed for' /usr/local/psa/var/log/maillog | head
Aug 19 00:04:45 web48002 postfix/smtp[28115]: certificate verification failed for inbound.hsaforamerica.com.netsolmail.net[206.188.198.64]:25: untrusted issuer /C=US/O=Equifax/OU=Equifax Secure Certificate Authority
[Code] ....
How/where do we edit our CA file under Postfix - and why is the standard one installed by PPA not including some of these VERY MAJOR CAs?!?
I would like instructions on how to edit this in a manner that it will not get overwritten by some PPA update or yum update.
Other than Rackspace, can the good folks here recommend some data-centers that have experience in handling the following solutions:
SAN (F/C, 10Gbps), 9TB usable capacity, complete redundancy, and real-time mirroring to an additional SAN in a separate geographic location.
redundant Brocade SAN switches
Servers: Quad processors, quad core, 48GB RAM, 8x146GB SAS Drives, multiple 1Gbps NICs
VMWare installations and handling.
Load balancers (preferably Brocade)
Dedicated L3 switches
I'm not just looking at providing this, but someone who can truly manage it 24/7 - management from VMWare and SAN perspective.
I saw some niche datacenters, but ran into the following problems:
(a) singular location.
(b) support for VMWare and SAN provided during business hours only
(c) no prior experience in real-time SAN replication / VMWare, Oracle/MS-SQL Replication.
quality shared hosting solution for a WordPress-powered multi user blog. The blog currently has around 1000 posts, 5000 comments and around 2000 unique visitors every day, but those numbers will grow grow exponentially in future, so the hosting in question needs to be expandable since I will eventually have to move to a dedicated server.
Right now, however, I want a quality US-based hosting company that has good connection to EU, with fast support and basic features: PHP5, MySQL5, shell access, ~10GB HD space and ~50-100GB traffic.
First and foremost I am looking for quality and am prepared to pay as much as $25-30 per month.
I have a dedicated server currently hosted over by Aplus.NET
I have a 3000 GB Monthly Transfer limit and we have been going over this limit for the past few months. This has resulted in a large sum of overage fees.
I am looking to go to another hosting company that is just as good as Aplus.NET, if not better... with a better traffic rate. A friend told me about Choopa.com and I wanted to know how good of a company they were. What are some other top reliable hosting companies with premium servers and that specialize in unmetered bandwidth?
I'd like to get your recommendations on how I should approach this problem. I posted this in another part of the forum, but I feel that this is a more appropriate place for it.
Problem:
How to handle large amounts of traffic with for a social network website? If a user uploads a photo or video, how does it become accessible on all of the server? If traffic is expected to be about 500,000 visitors a day, how many machines do you think I should use?
Possible Solution:
I've come up with the following possible infrastructure.
One load balancer. The load balancer has 3 PHP/Apache servers behind it. Behind each of the PHP/Apache servers is a (slave) MySQL server, from which data is read. Behind the slave MySQL servers, there is 1 master MySQL server, which handles all of the database writes. The master MySQL and slave MySQL servers are synced up, so data is up to date.
The actual photo and video files are not stored in the database, only the links to them is stored in the database (to keep the database small). The photo and video reside in a central location (like a SAN or NAS), which is accessible by all of the 3 PHP/Apache webservers.
Questions:
1. How many machines do you think will be able to handle photo and video uploads for 500,000 visitors a day?
2. Is having a SAN with Terabytes of RAIDED disk space an available option?
3. If a SAN or NAS is not an option, does anyone have any ideas on how to make sure all of the web servers have access to the same photos and videos? Is rsync a viable solution?
4. Which hosting provider do you think I should go with?
5. Is clustering what I need? What is clustering and how will it address my concerns?
I'd like to get your recommendations on how I should approach this problem.
Problem:
How to handle large amounts of traffic with for a social network website? If a user uploads a photo or video, how does it become accessible on all of the server? If traffic is expected to be about 500,000 visitors a day, how many machines do you think I should use?
Possible Solution:
I've come up with the following possible infrastructure.
One load balancer. The load balancer has 3 PHP/Apache servers behind it. Behind each of the PHP/Apache servers is a (slave) MySQL server, from which data is read. Behind the slave MySQL servers, there is 1 master MySQL server, which handles all of the database writes. The master MySQL and slave MySQL servers are synced up, so data is up to date.
The actual photo and video files are not stored in the database, only the links to them is stored in the database (to keep the database small). The photo and video reside in a central location (like a SAN or NAS), which is accessible by all of the 3 PHP/Apache webservers.
Questions:
1. How many machines do you think will be able to handle photo and video uploads for 500,000 visitors a day?
2. Is having a SAN with Terabytes of RAIDED disk space an available option?
3. If a SAN or NAS is not an option, does anyone have any ideas on how to make sure all of the web servers have access to the same photos and videos? Is rsync a viable solution?
4. Which hosting provider do you think I should go with?
5. Is clustering what I need? What is clustering and how will it address my concerns?
Is there any conventional wisdom on WHT about which shared hosting providers have highly reliable email service?
The provider I have now has very good web hosting service but their email services tend to bitbucket far too much mail for comfort. Reliable delivery and reception for the half a dozen emails I might send/receive a day (it's a personal use site) is I hope not too much to ask without needing to pay and arm and a leg for the privilege.
creating a setup that will host a site which is expected to receive 50-60K visitors in the first few hours after its launch. The site is membership based and the backend (member system) runs on PHP5-MySQL5.
Here is what I have thought of until now.
Site's sales page (which also happens to be the first page that visitors hit) hosted with Amazon S3 service. All public media files are off loaded to amazon S3 service to keep the number of requests on the hosted setup to minimum.
At the front we can have a high performance firewall like Cisco ASA 5520 followed by two dedicated load balancers in Active/Active state.
Behind the load balancers we have 3 front end servers acting as web-servers. These have SAS disks, 4GB RAM, RAID 1 setup, Dual Xeon Quad core processors each.
Behind the front end servers - we have a dedicated load balancer for the database cluster.
The database cluster consists of 3 Storage/API nodes and one of the front end servers acts as the management node. Each storage node has 8GB RAM, Dual Xeon Quad core processors, 4x RAID 10, SAS setup.
The private network is on a GigaLan.
Do you see any possible/obvious flaw in this design or anything that should be added/subtracted from the setup?