UK Host With A Penchant For Security
Feb 23, 2009
While I'm quite happy with my current host for most of my projects, I'm in need of a host with slightly more sensible security policies.
By that I mean one that comes with:
- SSH and SFTP from a DYNAMIC IP address (lots of stupid hosts only allow SFTP from static IPs, for "security reasons", requiring users to use FTP instead..dumb dumb dumb)
- IMAP/POP3 over SSL (TLS)
I don't need a whole lot of storage (roughly 5GB) or much monthly bandwidth, but I will need to be able to serve rather large multimedia files (neither pr0n nor copyright material, no worries).
View 0 Replies
ADVERTISEMENT
Mar 27, 2009
For you, what a webmaster must do to prevent get hacked?
View 14 Replies
View Related
Apr 4, 2008
I run a web hosting company and one of my servers is a LAMP server running CentOs 5. A user of mine has a Joomla installation running to manage his website and he has run into the following problem that I am puzzled by.
When Joomla adds a component or module to itself, or when a user uses the Joomla upload functionality, Joomla will add the new files under the user name "apache". This makes sense as it is the apache service running PHP that is actually creating the files.
However, when he FTP's into the account to modify these files, he doesn't have the appropriate permissions to do so as he doesn't have a root level login, just permissions on his home directory which is the site. Any help would be much appreciated.
Also, does anyone know how to change the owner/group of a directory and all of its sub directories in Linux without changing the actual permissions? I.e. some of the files in the folder have different permissions (0644 as apposed to 0755) than its parent but if I do a top down user/group change on the folder it will change everything in that folder to 0755.
View 10 Replies
View Related
Apr 11, 2008
I'm configuring a website for a client who has moved their web hosting to downtownhost, but is keeping their email hosting with their current provider. They do not want to configure an MX entry on DTH to autoforward email back to their current provider because they don't want their email to pass through DTH.
In order to do this, do I keep the nameserver entries on the current provider the same, and configure an http redirect to point to DTH? Or is there something else I should configure on the current provider?
View 4 Replies
View Related
May 21, 2009
I'm wondering if you can tell me something about your experience with a host/server in a different country or overseas.
My webpage will be mostly frequented by Australians.
What do you think is the advantage and the disadvantage of having a host in your own country and having one overseas?
I'm thinking about stability, traffic speed, peak hours in different time zones, customer service, ....
What are your experiences?
View 13 Replies
View Related
Aug 3, 2008
I was with Blue Host and their support and service was pretty bad. Servers going down all the time, and chat support was terrible. Then I moved to Host Monster and received the same kind of service/support. I later then figured out that Blue Host and Host Monster is runned by the same people. For example, I opened up a tech support ticket with Host Monster and then they replied signing their signature with Blue Host. So I got the same service: terrible tech support and servers kept going down. Now I'm looking for a new web hosting. I a few people here gave Host Gator some good reviews. I hope Host Gator is not run be the same people that runs Blue Host and Host Monster.
View 15 Replies
View Related
Jul 8, 2008
Does anyone have a preference for Host Excellence compared to Blue Host?
Do you think their basic offers are the same?
This is for just a couple of simple domains and sites to be hosted.
View 8 Replies
View Related
May 27, 2008
with this being my first website goddady's website tonight or there blog site plan seem pretty good as I do not know how to build a professional looking website nor do I have a knowledge of HTML. Are there other hosts that offer better services such as these?
Also I would want to register with 1&1 as to register privately is free but with godaddy it costs around $15 and I've heard of godaddy stealing persons domains when they haven't even expired yet i.e. familyAlbum.com?
Is it allowed for instance to register my domain name with 1&1 and host my site with godaddy?
View 7 Replies
View Related
Jul 16, 2009
I have regarding hosting/designing my application. Users of my website upload highly sensitive files to the server. I'll use SSL but will that be enough since the files are not encrypted on the server. I tried to encrypt the files but that is adding a huge overhead.
My first question is - is it a good idea to store the files on the server rather than a database? My other question is regarding hosting; I'm thinking of building my own server and host it in a colo. Is colo more secure than dedicated hosting? Currently i'm still in the process of developing my App and my environment is Windows Server 2008/SQL Server 2005.
View 13 Replies
View Related
Feb 9, 2007
Is there any problems with having duplicate rules in different files as I have downloaded some rules and am going to make them all into one file to give me the best protection, but this is going to take time and I really need some sort of protection now
View 2 Replies
View Related
Aug 25, 2007
after install ConfigServer Firewall i get the following ...
ConfigServer Security & Firewall - csf v2.89 >>
PHP Check >>
Check php for register_globals >>
WARNING >> You should modify the PHP configuration (usually in /usr/local/lib/php.ini) and set:
register_globals = Off
unless it is absolutely necessary as it is seen as a significant security risk
must i modify it?or not? put in ur consideration i tried to download it to modify an error occured!
View 2 Replies
View Related
Aug 24, 2007
I am on a shared server account with Lunar Pages basic hosting plan.
The only script file I have up running is db Masters FormM@iler. It runs on Cpanel. I deleted whatever other scripts I could find on my server. The site is just basic html pages with jpgs and a gif.
Is there much else I really need to do to secure the server or is that more in Lunar Pages' hands?
If there is still more I can do to secure the server, and is it a small amount that's easy to do or would it be wise to just hire someone else to put in a few hours making sure everything is truly set up securely?
View 5 Replies
View Related
Apr 23, 2007
I have a vps that has been exploited, and the hosting company is giving me advise on what to do to fix the security problems, but i need a good server administrator/company to help me with this. can anyone recommend a company that will go thru my server,
View 8 Replies
View Related
Mar 27, 2007
I'm inheriting a website that is currently a mess. It was designed in Joomla, but everything about the site by the original designer, is completely a mess. Files weren't placed in their proper directory hiearchy, the site has been hacked into a few times...basically a big headache.
I'm willing to learn and my first goal is the redesign the site. Currently, I'm looking at choosing a CMS or just rebuilding it in Joomla. The problem is that the site is a big part of the business, so any down time is not good.
I have some questions I hope you experienced folks can help me with...
Does CMS choice have any bearing on whether or not its a security vulnerability? If so, which one's are "less a target" of getting hit?
I just want to design the site from scratch and make it secure as possible from suggestions on various forums. I don't want to be a security admin, but is that what I'll end up having to do to run a site like this?
What are my options between "doing it myself" vs "hiring a third party"?
The company is right now in a tween stage. Fast growth but not enough to hire a security guy, based on my talks with the CEO. I disagree with this, but what can I do in the meantime to plug the site holes?
I'm almost wanting to go commercial so I don't have all the headaches, but the company wants to save money. What can be done in those situations?
Before I go out and spend money on books, what do you recommend I buy to start getting my feet wet in what may become a future in IT security?
This is from someone who's just inherited a dedicated server with a swiss cheese website. What is the first order of business for someone who is in the dark and will not get much support in regards to spending more money?
how do I secure my site "on my own"?
View 5 Replies
View Related
Feb 26, 2007
I noticed that my vps had utilized 250 gig of traffic in one day [i average 5 gig per MONTH] with cpu usage of close 100%; my hosting company pinpointed one php file which had allowed an outside varibale to be placed in "include" function so that the outside php code was being run;
Is there any program/scripts that can immediately email me if cpu usage stays high
the nic card is being utilized too much memory usage exceed certain levles this way, i would know i have been hijacked in time and try to find the culprit i use knownhost with cpanel/linux mysql and php.
View 5 Replies
View Related
Jul 21, 2007
i have an unix server [don't know what version i think it's FreeBSD ]
[url]
and i use WS_FTP to upload the files to my server.. but i have a big problem all my files are encrypted with some problems but when people use getrigh browser or some kind off program to acess my server instead of a normal browser it appears the list of files i have upload and they can download them and when i set password for images etc it's all safe, but people can't acess parts of the site without password... i want to know if there's some way of protect my file without interfering with the normal browser acess.
View 9 Replies
View Related
Jul 24, 2007
when we run server with shared hosting. we mostly facing issue os security like c9shell scripts.. as well as ppl hacked database or changed index.html. we do enable php open base dir as well as mo security firewall we do search which user is using find command who is uploading file... but is there any other way to secure server for such hacking issue..
View 5 Replies
View Related
Mar 26, 2007
I have run rkhunter and got message saying that /bin/dmesg [BAD]
# rpm -qf /bin/dmesg
util-linux-2.12a-16.EL4.20
# rpm -V util-linux-2.12a-16.EL4.20
.M...... /usr/bin/chsh
It looks like RPM damaged? How can I confirm it?
View 2 Replies
View Related
Jul 10, 2007
When securing a vps system, do things like Enable Shell Fork Bomb/Memory Protection use much memory or any other secuirty measure?
View 3 Replies
View Related
Oct 31, 2007
We have a e-commerce web site that has the latest shopping cart software ( that is known to be secure) ssl cert, etc.
We got a call today from a guy who says that he used his brand new card on our web site and that the card was stolen and used on anothoer site within hours. We have checked every file on the web site, logging into serevr root and checking everything and cant find any evidence of a hack or security breach of any kind.
can someone recommend a reliable company that can go in and check things out for us to see if they can find anny security issues, or evidence of a breach? There must be a company out there that does this sort of thing
View 4 Replies
View Related
Jun 16, 2008
If you had to chose either Host Gator or Hawk Host which would you go with and why? Don't bring any other hosts into consideration just compare these two. This would be for a standard website, forum, and a few downloads if it makes a difference...nothing too fancy.
View 14 Replies
View Related
Dec 12, 2007
I have just made a personal website using photoshop, html, css and php. My site contains an index page, a gallery page with 8 photos, a contact page with a form and an extra page with some quotes. I am planning to use a paid host for the first time. Based on feedbacks from some of my sitepoint friends, I decided to go in for shared hosting. I thought of using Hostdogs.com as they have the option of a monthly billing cycle. I thought that I have the option of changing my host after a month if I am not happy with them. I have also read a lot about Hostgator.com. A lot of sitepoint members seem hooked to it.
1. Can anyone give an opinion as to which host I should go in for? Hostdogs also give a free domain. Is there any reason I should go in for Hostgator instead of Hostdogs?
2. One more question, I have heard that once I have a site running, I can earn money through the advertisements placed on it? How do I place advertisements on my site?
3. One last and very important question is whether it is right to go in for shared hosting at this point of time. I just read this
Quote:
When you look for a suitable host, be sure to check out the amount of bandwidth that will be available to your site. Even a site that doesn't require a great deal of data transfer per month could run slowly if you're hosted on a shared server; particularly if you are on the same server as a more popular or bandwidth-intensive site.
The more sites hosted on a server, the more likely they are to compete with each other for available resources, including bandwidth. This is why you may notice a reduction in server response times during busy periods, or during a sudden peak in traffic at a busier site on a server that you share.
This made me wonder whether I should go in for shared hosting. But then mine is a personal home page which may not have so much of traffic.
4. What does the paragraph below mean? How does one handle ones registration manually?
Self-Management (no cost)
Select this option if you prefer to handle your registration manually.Your web host can establish service with any Top-Level Domain (TLD), international or domestic.
View 24 Replies
View Related
Dec 31, 2007
I will be setting up a site which uses ASP.NET 1.1. I know versions 3.0/3.5 are available, but they are not yet V2.0 compliant. Anyway thst is not the issue - just context.
Would like your advice as to whether it would be better to host this site with a company who looks as though they are specialising in ASP; such as DiscountASP, or Softsyhosting, or go with a general Windows hoster such as Steadfast, Fluidhosting, or 3Essentials?
I know nothing about ASP, so I don't know whether it is not at all neccessary to have a host specifically knowledgable about it, as I am unlikely to ever have problems with it, OR; I will most certainly have to address ASP issues sometime, so it would be essential to have support who really knows ASP.
View 11 Replies
View Related
Apr 8, 2008
I am conducting some research into potential risks that web hosts have to deal with on a daily basis. What potential security risks are there for web hosts ? And how do they overcome these issues?
View 6 Replies
View Related
Jun 7, 2009
For security reason I have these php functiosn disabled:
show_source, system, shell_exec, exec, popen, proc_open, procopen, passthru
Can anyone please tell me whether if it will prevent shell scripts from working?
They can still upload the shells but cant read/write/execute commands in 777 directories?
View 6 Replies
View Related
Jul 16, 2009
I want to setup a Windows 2003 security policy to filter traffic.
I want to let most of the world through to port 80 so maybe just ban a few nuicance IP's.
But then I have a POP / IMAP server, VPN, SMTP, etc that I want to block all but UK IP addresses.
I know I can do this through the MMC snap in but this is 1000's of IP's.
Is there a way I can import a list/range of IP's that I want to block from a country IP database?
View 14 Replies
View Related
Oct 9, 2009
I have a Linux server in which i have two NIC's one is for the LAN and other is for the Internet
[root@nebula etc]# ifconfig
eth0 inet addr:192.168.1.101 Bcast:192.168.1.255 Mask:255.255.255.0
eth1 inet addr:192.168.1.102 Bcast:192.168.1.255 Mask:255.255.255.0
How can i test security between the Internet Nic and the LAN Nic to be sure no security leaks exist.
I can only access the server remotely no GUI but can install packages.
View 4 Replies
View Related
Mar 23, 2009
I am getting more into it and looking for the best way to harden it and secure it. Also some information about what processes to turn off and how to better setup my IP Tables.
View 8 Replies
View Related
Apr 24, 2009
So I've been using WHMCS for a while, and there's something I'm a little concerned about with the whole keeping customers credit cards for recurring payments.
I've downloaded a backup copy of the database and I see that the passwords and credit card information is encrypted. That's all nice and handy but the CC hash is also stored right in the configuration file. That means that if someone gains access to the server and just grabs the database + config file they would then be able to view all that info correct? Maybe someone who knows a little more about WHMCS can tell me if this is correct or not?
View 1 Replies
View Related
Apr 20, 2009
I'm running CSF on a Cpanel server and have questions about new features in CSF
Apache Check
Check Apache weak SSL/TLS Ciphers (SSLCipherSuite)
Results
Cipher list []. Due to weaknesses in the SSLv2 cipher you should disable SSLv2 in WHM > Apache Configuration > Global Configuration > SSLCipherSuite > Add -SSLv2 to SSLCipherSuite and/or remove +SSLv2. Do not forget to Save AND then Rebuild Configuration and Restart Apache, otherwise the changes will not take effect in httpd.conf
Can someone explain this in laymen terms? I know this is new in Cpanel. I'm already running Apache 2.2, PHP 5.2.9 with suPHP enabled and mod_security as well (these rules: [url]
Also, what exactly are these CSF checks?
Check csf PT_SKIP_HTTP option
This option disables checking of processes running under apache and can limit false-positives but may then miss running exploits
Check csf SAFECHAINUPDATE option
This option closes a window of opportunity that opens when dynamic chain updates occur
View 3 Replies
View Related
Jul 5, 2009
I am facing some major SPAM problems.
I am a web host from the city of Kolkata, India.
Almost 95% of my clients are from my city - others are also known to me. I know many of them face to face - there are very little chances that any of them are SPAMMER.
Still my server IP is blacklisted - several times in last 1 year - I changed my datacenter - but the problem still persists.
View 10 Replies
View Related