Test Your Server Security
Jun 3, 2008Is there any script or method where I can test my server security?
View 2 RepliesIs there any script or method where I can test my server security?
View 2 RepliesI have Parallels Plesk 12.0.18 with CentOS 6.5 (Final)
WAF is On, with Atomic Basic ModSecurity rule set.
I was wondering if my sites were protected and I went to the Atomic wiki.
When I run a test from a non-whitelisted system following these instructions (STEP 10) [URL].... I always receive 404 error with all of my sites.
I also tested with:
[URL]...
Results: The sites load normally. (the call not even appears in the logs)
I've unistalled and reinstalled mod_security several times with the same results.
Is there any "official" way to check if WAF is protecting Plesk 12?
I asked same question in Atomic forum and they said:
you'd need to ask parallels about this, we made the ruleset available to them, but they implemented it using their own design. They might not be using 403 error codes like we do.
We are a small development team mostly coding in php/mysql as an unpaid hobby. Anyways yesterday our test server had hardware problems and to get a decent new one would be $300. Well this seems a lot to ask for someone that does get any compensation for it. So we are looking for some cheap way of providing a test server. We need at least a way that provides svn, apache w/ php and mysql. We tried to use the webserver, but the head dev didnt like the idea. Any suggestions?
The three devs are in charge of wcreplays.com .
it possible to test own server in my home(only to test)
iam haveing centos 5.4 with vmware
need 2mpbs for testing it be good i think so
but only i haveing issue is ip(iam useing dynamic ips
it anyway to test as local server with dynamic ips?
What is the best way to test the speed of a server?
CPU/processing wise, and not bandwidth wise?
I'm trying to test my colocated webserver's bandwidth. I found speed test links such as this one: [url]
If I just run this on from my colocated web server, would the result be credible?
Although I think these tests are designed for dsl/cable subscribers.
way to test the speed of your web host? If the answer is ping, what is a good response time to look for?
View 7 Replies View Relatedwhich site can do that job? when i plan to buy a dedicated server,
i want to test speed like my customers worldwide.
Let's say you ordered new server,do you make active same moment(install httpd server and all other components)or you running test before like memory and hardware test? If yes,which programs you would recommend to test fully hardware?
View 2 Replies View RelatedI have LAMP -server running and I was wondering how to test it's performance.
So is there any good tools for that? I'm interest how many http queries my server could handle etc.
Here are the Servers IPs which are all located @ Malaysia but different datacenter:
Server 1:
Data Center: Brickfield
IP: 202.75.55.188
Server 2:
Data Center: Jaring
IP: 202.190.175.218
Server 2:
Data Center: Cyberjaya
IP: 202.71.103.132
My host keeps telling me that it is my connection but my server keeps getting slower and slower. how can I actually test it?
View 3 Replies View Relatedi set a new server with some setting,
i want to test if it can handle how many connection or burst bandwidth,
i want to use other server(s) to test with it,
can i use any way to do this work?
i just buyed a dedicated server with 100mbps dedicated port..
how can i test the traffic on port to see is is realy working on 100mbps?
I have a problem. to buy dedicated server but I don't really know what to buy. I need some kind of stress test for server so that I can be assured that my website won't crash when it will be on front page of digg. Does something like that even exists?
View 7 Replies View RelatedI have a question getting the setup of my DNS and email server working correctly.
In my mailserver, lets say I set the SMTP server to mail.BLUE.com. Through my DNS, I set an MX record for mail.BLUE.com and I set an A record for mail.BLUE.com to 1.1.1.1.
I create different domains on my mail server and give each an IP address. BLUE.com is 1.1.1.1. RED.com is 2.2.2.2. GREEN.com is 3.3.3.3.
Each domain is setup in my DNS as a forward lookup zone. Each domain has an MX record (mail.domain_name.com) and a A record (pointing mail.domain_name.com to it's IP address). There are other records of course... but they're not important for my question.
When I want to check or send mail from BLUE.com I use mail.BLUE.com. When I want to check or send mail from RED.com I use mail.RED.com. I do this for all my email accounts.
But, when I check dnsstuff.com on any domain besides BLUE.com, it tells me the following:
****************************
mail.RED.com claims to be host mail.BLUE.com [but that host is at 1.1.1.1 (may be cached), not 2.2.2.2].
****************************
Now... this can send and receive mail just fine... but I think this may cause issues when it comes to SPAM settings (some servers may consider our mail SPAM because we're "pretending" to be a different mail server).
So... here's my question... what's the best way to set everything up to run multiple sites and email accounts on one server?
How can I use 1 SMTP mail server (BLUE.com) and get my other domains to pass the dnsstuff.com test?
Can any one tell me, How to perform speed test on my VPS...
View 1 Replies View RelatedIs there a website/tool/software I can use for testing my web server performance?. I need a server based solution because I don't have enough bandwith to run it from my pc.
View 3 Replies View RelatedI have used e2fsck on linux server hard disk (CentOS 5.0) and the result :
=================================
Warning! /dev/sda2 is mounted.
Warning: skipping journal recovery because doing a read-only filesystem check.
/dev/sda2 contains a file system with errors, check forced.
Pass 1: Checking inodes, blocks, and sizes
Deleted inode 19137773 has zero dtime. Fix? no
Pass 2: Checking directory structure
Pass 3: Checking directory connectivity
Pass 4: Checking reference counts
Pass 5: Checking group summary information
Block bitmap differences: -(16332803--16332804) -(16332823--16332826) +(16345421--16345424) +16347209
Fix? no
Free blocks count wrong for group #498 (25950, counted=25949).
Fix? no
Free blocks count wrong (37023218, counted=37023216).
Fix? no
Inode bitmap differences: -19137773
Fix? no
Free inodes count wrong (19162546, counted=19162545).
Fix? no
/dev/sda2: ********** WARNING: Filesystem still has errors **********
/dev/sda2: 137806/19300352 files (2.3% non-contiguous), 1556879/38580097 blocks
=================================
I don't know the exact meaning of the displayed result , does it mean bad sectors? How much the e2fsck is reliable? Is there any better Linux utility to check bad sectors on Western Digital HDD?
When I restart my server all my domains opens at apache test page. Suspending and reactivating any domain fixes all domains.
View 4 Replies View RelatedWINDOWS SERVER Plesk Panel version 12.0.18
Error: Test the database server connection failed:
mysqlnd cannot connect to MySQL 4.1+ using the old insecure authentication. Please use an administration tool to reset your password with the command SET PASSWORD = PASSWORD('your_existing_password'). This will store a new, and more secure, hash value in mysql.user. If this user is used in other scripts executed by PHP 5.2 or earlier you might need to remove the old-passwords flag from your my.cnf file
I freshly installed Plesk 12.0 on Ubuntu 14.04. Everything works accept the MySQL database creation.
When I try to create one, i get this error :
error: the test connection to the database server has failed because of network problems: connection refused...
I'm running CentOS 5.x and DirectAdmin and wondering how to do the following:
- Disable compilers and other known binaries. Should I chown WGET 550?
- Prevent Shell Fork Bombs
- Best way to create partitions for tmpfs, tmp since my host forgot them?
- Any other tips on securing a DA based server? (I already have taken care of the whole SSH side of things)
One one of our (linux) servers spammers are king. they apparently can control anything and place spam links throughout the files.
For example spammer inserts Iframes either above or below HTML tags. (some step57 related type of virus/trojan as it seems)
Our programmer did not find where the problem is in our applications, yet he is not a security expert.
Our server admin company made us install phpuexec, we apparently have been checked on the server end and have mod_security, but we still don't know what's going on...spam continues.
Trying to determine what I want to put on my server for security. I have secured my /tmp, /var/tmp, and /dev/shm. I am now contemplating mod_evasive, mod_security, and/or APF Firewall.
1.) Should I install all three, or will APF Firewall, provide the same or similar security as mod_security, or vice versa?
2.) Will they all work together without conflicts?
3.) Does installing these services have any affect on overall server performance?
4.) Any other services you might recommend installing and why?
I have recently installed and configured my webserver. Since I think security is very important I am curious for recommendations, tips, etc.
My server:
-CentOS 4.4 (installed by provider)
-Apache 2.0.52
-Php 4.3.9
-MySql 4.1.20
-No FTP
-Mod_security is running
The firewall that comes with CentOS is switched on and allows the following ports: http, ssh, smtp.
I have installed sendmail, but it is turned off by default. I need it approx. 3 times a week for 15 minutes or so and will turn it on then.
I have barely any budget so hardware firewalls etc. aren't an option.
Furthermore it's a basic server, just like my knowledge, so advanced things like IDS aren't an option.
i want to know how can they make the directory ( u--------- )
take a look on this php shell
[url]
what i mean is they make the directory secure against any phpshell with that trick and they hide the hard disk space
how can i make this
my apache is 1.3.37 and i using fc5 and i have mod_security and cfs
I am considering renting a server, but got one question first.
If I sign up for one unmanaged root server with a control panel, from a provider. And just put my website on the server, and let it run there.
Is that a security risk? Is it easy for people to hack into my server, or anything like that?
My server has been hacked, I need you please to help learn about Unix server security to protect my server.
View 6 Replies View RelatedI have a dedicated server which I access via remote desktop.
The firewall is not enabled. What kind of security should I have on my server?
Ive read that if I enable Windows Firewall my remote desktop connection will be blocked & this will mean me having to contact the server company via phone etc.
Does any body recommend we3cares server management services?
I need a very simple server management and hardening job and dont want to pay much. (not for a hosting company)