141 karma · joined March 10, 2009
1) Register 'Anti-Sec ' with Free Mail Provider 2) Claims to Full Disclosure 3) ???? 4) PROFIT.
brilliant
OpenSSH <= 5.2 zero day exploit code
Unfortunately I also had no idea about the concept of security patches and, to this day, I still have no idea how I should have gone about getting security updates for Slackware (I switched to Debian and never looked back). The result was some script kiddie got root and started to use my box to start scanning for more vulnerable samba installations to break.
My response was to unplug all of the network cables and have a poke around to see what he'd been up to. I took a full backup of the box and then re-installed it from scratch as I couldn't trust it.
I learned that you should always look at what ports you have open (`netstat -lpn` is my favourite command for this) and that there are some times when a firewall might be of use (I'm not a fan of firewalls on anything other than gateway boxes).
Assuming that "XX days" === 'less than 100 days', I totally agree.
We use a six month password cycle at work, and I think that's reasonable as it only takes me a few days to remember a password that I use tens of times a day. If it's a password that I use less frequently or a change is mandated more frequently, then I would do the same as Bruce and use something more obvious or only make small changes to the password each time.
"Last modified: $Date: 2005/04/15 06:38:18 $" explains a lot.
http://news.ycombinator.com/item?id=648806 (LxLabs boss found hanged after vuln wipes websites) same story on the register
and
http://news.ycombinator.com/item?id=648788 (Hack wipes out data for 100,000 sites)
and
http://news.ycombinator.com/item?id=646451 (VAServ 'hacked' - all web sites and hosted VMs down)
http://news.ycombinator.com/item?id=648788 (Hack wipes out data for 100,000 sites)
and
http://news.ycombinator.com/item?id=646451 (VAServ 'hacked' - all web sites and hosted VMs down)
http://securityreason.com/wlb_show/WLB-2009060016
"Kloxo (Previously Lxadmin) The most flexible software on this planet. From Kloxo HostInaBox, World's lightest and the most efficient webhosting platform, to Kloxo Enterprise, which can manage 100s of thousands of domains on hundreds of servers."
It's 'flexible' a euphemism for 'full of holes'?
Can anyone edit the URL for me?
I can't recommend sSMTP enough to anyone that doesn't want to maintain a mail server. All UNIX systems should be able to send mail and this is very much still the case on modern Linux systems, but this is often overlooked.
I do, however, agree that 20 minutes down-time for a hardware failure is impressive. I wonder if they just yanked the disks from one box and jammed them in a spare?
Why don't you think that the Linux vendors won't support this? I can see it taking some time to be introduced, but there'll be a lot of corporate customers out there who would be interested in this and, as long as the process of generating a new patch doesn't take too long, I can't see any reason why this process can't be used by the commercial Linux vendors.
I agree with you that costs to Virgin Media should be quite low, as they own all of their infrastructure and most of it has been in place for 20 years or more.
The problem for the ADSL ISPs in the UK is BT. There are some IPSs which have installed their own equipment in BT's telephone exchanges and hence only pay BT for use of the 'last mile', but most of the ISPs in this country have to pay BT for not only the 'last mile', but also for the hundred or so miles before that. BT charges the ISPs based on how much bandwidth they consume, so for the majority of Internet users in the UK, the amount of bandwidth they consume is an important cost to their ISP.