hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : Major Security Probs
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

Major Security Probs

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 12-27-2004, 03:42 PM
infernus infernus is offline
WHT Addict
 
Join Date: May 2004
Posts: 122

Major Security Probs


Ive been having some security probs over the last month, and a look at netstat -a appears quite frightening.
Really im looking for someone who will voluntarily help me clean my server of all the insecurities and possible intrusions, so i can start over securing my server properly.
If anyone wouldnt mind lending a hand, PM me here!
Thx alot

Reply With Quote


Sponsored Links
  #2  
Old 12-27-2004, 04:05 PM
cDedicated.com cDedicated.com is offline
Temporarily Suspended
 
Join Date: Nov 2003
Posts: 350
you can email to CEO of linuxdominicana.com his email is: linuxdominicana@gmail.com

he can help you.
will not sure if its free.. but i know they provide full security test for 15$ one time.

Reply With Quote
  #3  
Old 12-27-2004, 05:57 PM
CybexHost CybexHost is offline
Web Hosting Master
 
Join Date: Aug 2003
Location: USA
Posts: 1,030
Good, trusted server security is not free. I'd suggest spending the money necessary to keep your systems in good order.

__________________
CybexHost.com - Shared and Reseller Hosting Solutions on cPanel/WHM Linux Servers
ModernTweak.com - Discount ModernBill Licenses, Hosted Installations, and Professional Services
:: Pay for your discount ModernBill license with PayPal
:: admin[at]cybexhost.com :: AIM: CybexH

Reply With Quote
Sponsored Links
  #4  
Old 12-28-2004, 04:28 AM
infernus infernus is offline
WHT Addict
 
Join Date: May 2004
Posts: 122
I just cleared off a script which was connecting to several IRC servers, functioning as bots.... they had been running as user 'nobody'
Im going to use nessus to completely security scan the server, then patch accordingly.
Anything else i should look into?

Reply With Quote
  #5  
Old 12-28-2004, 04:35 AM
Steven Steven is offline
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,552
Chances are if they were running as nobody, then it was an exploited php script, and nessus is not going to tell you anything.

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #6  
Old 12-28-2004, 04:42 AM
infernus infernus is offline
WHT Addict
 
Join Date: May 2004
Posts: 122
nessus scans for cgi vulnerabilities. Anyways, if this is the case then i will be checking my (insert name of program that lets cgi and php scripts run as the user instead of nobody, i forgot the name ^_^) configuration.

Reply With Quote
  #7  
Old 12-28-2004, 04:43 AM
Steven Steven is offline
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,552
yes but it wont check every domain, and cgi is normally ran as a user not nobody, which leaves php to be the problem.

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
  #8  
Old 12-28-2004, 04:47 AM
infernus infernus is offline
WHT Addict
 
Join Date: May 2004
Posts: 122
SuExec is the name:

Notes: suexec allows cgi scripts to run with the user's id. It will also make it easier to track which user has sent out an email. If suexec is not enabled, all cgi scripts will run as nobody.

Does this not include php?

Reply With Quote
  #9  
Old 12-28-2004, 04:55 AM
Steven Steven is offline
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,552
No, you would have to isntall phpsuexec / suphp for php

__________________
Steven Ciaburri | Proactive Linux Server Management - Rack911.com | 1.855.RACK911
System Administration Extraordinaire

Managed Dedicated Servers, Linux Server Management, Disaster Recovery, Server Security Audits

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
StopTheHacker Launches Version 3.7 of Website Security Tool Web Hosting News 2013-02-04 18:40:30
Half of UK Firms Failing to Heed Security Breach Warnings, says Bunker Study Web Hosting News 2012-06-13 14:47:51
Web Host Webzilla Receives PCI DSS 1.2.1 Certification Web Hosting News 2012-02-07 17:12:58
Cloud Security Firm Dome9 Adds Group-Based Firewall Policy Management Function Web Hosting News 2012-01-25 12:41:56
Security Firm CloudPassage Joins Rackspace Cloud Tools Program Web Hosting News 2011-06-20 20:42:55


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?