Time To Update Snort
Feb 20, 2007[url]
View 0 Replies[url]
View 0 RepliesIn WHM I'm trying to sync the server time with the time server. It displays the new time but it doesn't actually apply the new time to the server.
Also via ssh when I run
rdate -s rdate.cpanel.net
it says
rdate: rdate: could not set system time: Operation not permitted
I'm on a virtuozzo VPS.
Recently however it seems they're getting some bad press, most people are blaming growing pains.
As someone who's seen the before and after picture, i thought i'd chime in and actually put some positive notes on these boards, as I know these guys deserve more credit than this! It's one of those situations where if something goes wrong, people complain, if everything is right, not enough people speak up!
Server speed / specs:
one word: fantastic. i now have 2 VPSs with them - one in their new data center. I had moved the 2nd VPS from another host (also very well known on these boards, who I won't mention) where I had been having loads of issues regarding load and IO wait times. Load would spike up to 20+, server would crash, reboot, and this would happen 20+ times a day. Nothing critical on that server. Post-migration, using very very similar specs on futurehosting, and the load has been <0.10 since I started her up 3 days ago.
My current server sees load going up once in a while - during a large scale DOS attack last month the load only went up to 4, with over 1000 TCP connections. I only realized there was an issue as I checked one of my status scripts and noticed the enormous tcp count. I've recently moved to a new VPS on a new node, and load has been incredible, along with responsiveness.
No complaints at all on that front.
Network performance
Their old data center, softlayer, has much to be desired. There has been at least one outage every month so far which lasts in the hours duration. However, FH has made the very wise option of expanding out to a new datacenter and will hopefully slowly phase out softlayer, which has become quite pathetic. Connectivity wise though (speed/bandwidth) - no complaints.
Support
I remember getting a response within minutes months ago. However, that being said, months ago the customer service could only deal with the most basic of problems, and would escalate the issue if it was complicated, which would take time for a response.
FH did go through a growing pains phase a little while ago with regards to customer service - you wouldn't get a response too quick.
However now it seems they have begun improving. They are expanding their support base, and if you deal with the support guys you'll definitely be impressed by how dedicated and "hardcore" they are. Very recently I had a major issue with my server - it got compromised via root and someone wreaked havoc. Some script was installed that basically self-DOS'ed the server and basically killed it.
FH support instantly shut down the server and put me back up on my old server which I had migrated from only a week ago. They thoroughly went through and wiped clean my current server, fully bullet-proofed it and cleaned up the security of it all (something that was not a problem when they set it up - but rather my fault over time as I had disabled some very silly things I shouldn't have...) The guy working on the server, Jim, worked his *** off, pulled an all nighter (he was still responding to my tickets at 9am GMT, which was 4am his time - and I know he's not a night shift guy!). By the end of it all, he put me back onto my current newly-secured server, and was still revving to go, asking me what I wanted and to give him another challenge!
So, to sum this section--
good attitude: check
know-how: check
laziness: none.
I guarantee one thing - the vps company I just moved my 2nd vps from in this situation would not have spent an entire night rebuilding my server the way it was, but would've simply put me back on my old one week image, said "oh well, sorry, bad luck" and moved on.
All in all, my experience with these guys over the past couple of weeks (since the new data center opened) has been nothing short of positive, and I know they're rising out of the slight slump they had gotten themselves into.
I'll submit my URL to the mod to verify this post. And no, I don't work with FH
I'm trying to configure an custom access_log file for an custom file called "extra.php"
How I can make an log file that's log only "extra.php" ....
to replace the current router/firewall/gateway on my home LAN with a lower-end PC running pfSense. (A FreeBSD-based distro with a web GUI for managing pf and the like.)
Since the system will be passing all the network traffic anyway, I'm interested in the possibility of having it watch for anything suspicious. Snort is the obvious choice: I want it to spot incoming/outgoing suspicious network activity.
What I wonder, though, is if there is really a lot of benefit to running this on a home LAN? If it was a big corporate network, I could see wanting it to keep an eye on things, but we only have a handful of machines, and they're all pretty secure.
It'd be running on a ~1 GHz PC with 512 MB RAM... Given that the machine would already be acting as firewall/router, caching DNS server, and running PHP/Apache for the management interface / graph generation, is piling Snort on top of that asking for trouble?
Is anyone using snort?
Does it really block any web based attacks?
I know I can do port scans, and it can alert you to a whole bunch of false positvies, but is it blocking/detecting any serious attacks on your web server?
If so, which rules are the one is alerting on?
I doubt anyone is writing their own rules so what do you think is the best site for Snort rules for a web server which are strong but also do not result in many false positives.
View 4 Replies View RelatedDo many hosters use Snort (intrusion prevention software) on their servers as means to raise security level?
If not Snort, what other intrusion detection/related tools are currently popular?
It would be great to learn the opinion of hosters as well. Early-warning intrusion detection could be very useful in many cases.
Does anyone have snort logging to a mysql database?
I am trying to get that to work so I can view the alerts with BASE.
I followed the instructions but snort is not logging to the DB,
This is a rare issue i have on a RHEL 5.2 + cPanel server.
Server time is:
Tue Nov 11 17:02:51 CST 2008
Squirrelmail time show:
Code:
Last Refresh:
Tue, 5:02 pm
So, that is correct too..
But email arrives with -4 hours time, example:
webmaster@xxx.com 1:03 pm testing email
I already rebooted httpd, exim, and imap server, and the server itself too.. and problem stills.
I got report from webceo that I have some issues. May someone help me fix this?
DNS Lookup: 0.22 sec
Connect time: 0.33 sec
Host ping: 0.10 sec
That mean too slow with the other sites!
I can't get access to a certain site. I always get the page with:
network time out - server at *** takes to long to respons. More people have noticed this and apparently it only happens to people with certain specific providers. And not all the time. Some times they DO get access eventy to they belong to the same ISP. So I guess an ISP isn't blocking access to it otherwise it would be permenantly/The site administrator insists that certain ISP's are blocking his site. He's hosting it on his own server. The domain belongs is registered at namecheap.com.
If an ISP is blocking this site (if that's possible?), that would lead to that 'network timeout' page wouldn't it?
What is the most likely reason for getting a timeout page anyway?
I have a dedicated server specs: AMD 3500+ 64 Bit CPU, 1 GB Ram, 160 GB Sata Drive. For 1 month, CPU load average reaches 40-50 value. This happens about 5-6 times in a day. When I stop httpd service for 30 seconds everything goes normal. I think this is not a DoS attack because it comes systematic, I dont believe no one makes this regularly except bots.
Maybe its a system service or a cronjob but it stops when I turn off httpd service?
How can I be sure about what's making this regularly load?
I also did set up a script which mail me when load average of system goes crazy and restart httpd service. But instant restart is not working to stop load increase.
The server is going down from time to time, every 12 days or so the site hosted there is no longer accesible, everything starts with the site slowing don and down and then is not longer reachable, what we do is to request a power cycle, and with this we start all over again till next power cycle, so on so on, of course, here are my server details and more info on this:
- MySQL - 5.1.41-3ubuntu12.10
- Apache - 2.2.14-5ubuntu8.4
- PHP - 5.3.2-1ubuntu4.9
- operating system: Ubuntu Server 10.04 LTS
After some time emailing the support guys to barely check about what's going on, we received an email with a few things:
1.- found a few errors that likely would cause issues with Apache. The first error is:
[Mon Feb 04 05:03:10 2013] [error] mod_fcgid: fcgid process manager died, restarting the server and the next error is:
[Mon Feb 04 14:32:34 2013] [error] server reached MaxClients setting, consider raising the MaxClients setting ...
Both these errors seem to indicate that you have a process that is running out of control on your server. We were unable to determine what script on your site is running caused your connections to be maxed out however it does appear that before these errors were generated there was a WordPress plugin referenced in your access logs...
2.- Additionally during our review we did find that your error log for mercadodedinerousa.com is 45 GB's which is excessively large and can cause problems when Apache is trying to write a such a large file.
3.- The majority of the errors being logged are:
[Wed Feb 06 12:12:31 2013] [error] [client 200.76.90.5] Options FollowSymLinks or SymLinksIfOwnerMatch is off which implies that RewriteRule directive is forbidden: /var/www/vhosts/mercadodedinerousa.com/httpdocs/index.pl, referer: [URL]
I bought a new server ...
It had 2GB RAM, 2.8 GHz processor ,NIC fast Ethernet , 500GB HD.
Window server 2003 standard x64.
4 ip.
The ip ping but I cannot connect to server using remote desktop.
Is this problem related to firewall, or the network it self.
What if NO down time for VPS?
1. CPU (with Mainboard)
2. RAM
3. HDD
4. SMPS
5. others
with ALL things redundant
** currently my sites (on VPS) are down since couple of hours.. and God knows when they will be live again!
one day later, if I run the following command again, the command is same as the one run by the first time.
rsync -avz username@IP:/home/asite/public_html/ /home/asite/public_html/
does it mean rsync will just check and copy the newer folders and files from the last copy?
I have the same server for 3 years...Over that time I've been reducing the number of sites i have..
Is it time to downgrade?
The spec is below.... On a positive side It's been up for almost 500 days so it's reliable.
Would i be better with a high spec reseller account or a smaller managed server rather than spending $220 per month. I spend at the moment.
I'd even consider paying the same i pay now if i could get a faster more upto date server
2 processors: 2.8ghz pentiums
Ram 2gb
2 160 gb hdd's backup drive has used 96gb
Bandwidth used/available this month 50gb/1200gb
host 100 domains busiest is a forum with 500 members
already moved Moved all videos to Amazon S3
I have big problem, In my HyperVM i've change time to EUROPA/Sarajevo but in WHM still going 24 hours in forward. Please help me to resolve this. This is very important...
View 5 Replies View Relatedfrom: domaintools.com
Host IP Address Ping Time
1. 206.71.148.249 Timed Out
2. 206.71.148.249 206.71.148.249 126.20ms
3. 206.71.148.249 206.71.148.249 82.35ms
4. 206.71.148.249 Timed Out
5. 206.71.148.249 206.71.148.249 87.01ms
6. 206.71.148.249 Timed Out
7. 206.71.148.249 Timed Out
use: Enotch Networks
this issue from networks (enotch) or from my ISP?
because enotch staff said my ISP problem!
I'm just wondering what exactly "CPU Time" is, I have searched Google and checked Wikipedia but still do not really understand. The main reason this is bugging me is that MySQL on our database server seems to have a very high "CPU Time" usage.
This is the top part of the output from "top", with MySQL shown:
Code:
[mike@mysql1 ~]$ top
top - 20:26:05 up 222 days, 16:14, 1 user, load average: 2.04, 2.90, 2.36
Tasks: 95 total, 1 running, 94 sleeping, 0 stopped, 0 zombie
Cpu(s): 27.1%us, 12.1%sy, 0.0%ni, 60.2%id, 0.3%wa, 0.0%hi, 0.2%si, 0.0%st
Mem: 2074276k total, 1990828k used, 83448k free, 163012k buffers
Swap: 4192956k total, 60k used, 4192896k free, 1410448k cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
26826 mysql 25 0 483m 324m 5504 S 238 16.0 363300:21 mysqld
1 root 15 0 2064 592 508 S 0 0.0 0:01.24 init
2 root RT -5 0 0 0 S 0 0.0 1:13.13 migration/0
3 root 36 19 0 0 0 S 0 0.0 0:00.00 ksoftirqd/0
4 root RT -5 0 0 0 S 0 0.0 0:00.00 watchdog/0
5 root RT -5 0 0 0 S 0 0.0 0:01.17 migration/1
6 root 34 19 0 0 0 S 0 0.0 0:00.00 ksoftirqd/1
7 root RT -5 0 0 0 S 0 0.0 0:00.00 watchdog/1
8 root RT -5 0 0 0 S 0 0.0 5:34.93 migration/2
9 root 34 19 0 0 0 S 0 0.0 0:00.00 ksoftirqd/2
I have mi server in the planet. But I am not very happy with the support you give.
That's why I want to know what is the appropriate time for the response of a ticket?
30 minuts?
1 Hour?
2 hours?
3 hours?
4 hours?
8 hours?
12 hours
1 day?
What is a reasonable expectation for how long a host should take to reload an OS?
Read on for my story if you want details behind my questions...
Due to a logical but unfortunately incorrect mistake on my part, we ordered a dedicated Windows server with a 64-bit OS. We just found out that the 64-bit OS isn't compatible with a software package and we needed to get the 32-bit OS reloaded in a hurry.
I understand that urgency on my part doesn't necessarily mean it's an urgency on their part, but I am also paying additional for the server reload. I submitted a ticket with the hosting company yesterday around 7PM to get it reloaded ASAP. As of 9AM this morning I didn't hear anything from them one way or another so I signed in to my hosting account only to find that they left a reply to my ticket asking to confirm that I really indeed want a reload with the selected reload options. I never received any type of an email notification of the reply. I was a little miffed that I didn't get any e-mail, but oh well so I confirmed that was indeed what I wanted.
At 10:30 I get an e-mail asking me to reconfirm that my server's physical specs and there is a discrepancy on the memory installed as their records were outdated and showed 1/2 what was really installed. I have to contact my account exec to get that straightened out and I finally get notified that the reload has started around 11:30AM.
I was originally told informally 3-4 hours in a support chat. Here it is 12+ hours after the reload supposedly started and I have heard nothing from them. I tried checking at 5:30PM tonight before I left work what the status was, but the lady I spoke with just repeated the message I got at 11:30AM saying things were underway and that she couldn't give me an ETA on when things would be finished.
Am I unreasonable in thinking 24 hours after I submit the ticket with an priority of "ASAP" is too long? I'll cut some slack for the miscommunication on confirming that I indeed want a reload but even then it's been 12+ hours after they said that they have started and the server when down.
Do you consider resolution time guarantee when choosing a host?
What resolution time guarantee does your host offer?
Is one hour resolution ok?
This is what webhostgiant.com offer as their support resolution time.
[url]
Does is possible to disable ftp capabilities of several websites run by cron at some specified time of the day? then re-enable it automatical at a certain time also?
View 7 Replies View RelatedI want to find a web host and i have a couple of specifics that I'd like. Obviously I want the lowest cost for a relatively reliable service. I am looking to get started in my own web development/design business so I want to use this server as a development environment for myself as well as a deployment environment for potential clients.
I want to have SSH access to my space, the ability to host without buying a domain (at first, ill want to get one later), a good number of MySQL databases.
Some things that would be nice would be the ability to resell space for clients, not absolutely necessary though.
Are there any solutions that anyone here could suggest for me? What are some pitfalls and things I should watch out for? What else could I look to take advantage of?
What's an acceptable time for rebooting a machine?
I send an email to midphase to get my machine rebooted and I wait nearly half an hour. Even put 911.
Pacifirack would have got it done in under 5 minutes