I won't deny that you have to give him some respect for being able to pull all these stunts and acquiring the money from investors, however as it seems most if not all projects where at least partly illegal.
33 karma · joined May 19, 2011
I won't deny that you have to give him some respect for being able to pull all these stunts and acquiring the money from investors, however as it seems most if not all projects where at least partly illegal.
1: http://en.wikipedia.org/wiki/Grsecurity
I don't think I'll use an extra distribution. But something like a hardened LAMP/LAPP stack for shared hosting out of the box in a distribution would be great (I think in terms of easy chrooting of users and php, secure permissions, etc.pp) However, I guess everyone has different needs and there is no one size that fits for all.
In the features list they state:
/proc/pid filedescriptor/memory protection
But I'm unaware how they implemented that.Also: Iterate. Make a plan for tomorrow, realize tomorrow you are 50% off, ask yourself why...iterate till you can fullfill the plan. Include the stuff that stopped you from fullfilling your original plan, spot problems, experiment with solutions. Beeing honest with yourself can be hard.
And: Only do this for 50-70% of your time. If you plan everything you'll go nuts very soon (At least I do) but don't omit personal goals or problems.
As for the problem of acting on the plan: Think about binary sort... split the problem till you can handle it, then merge the parts. If you don't know how to handle it you can always think about splitting it up.
</endofpseusoselfhelp>
good luck!
From outside of your network yes. If one of the computers inside your network is infected your mail-server will happily deliver the spam mails.
> How does blocking 1 specific port stop the issue anyway? > They can just change the port they connect on?
I don't know of any SMTP-Server that accepts E-Mail on Ports other than 25. Port 587 requires authentification before sending an E-Mail.
I thought most poeple don't accept E-Mails sent from isp-networks with dynamic ip adresseses. Maybe that's not the case and they try to reduce spam this way.
> I was offering an opinion on how to resolve those issues. > Changing which port accepts the mail is in my opinion pointless.
Nobody changed any ports. E-Mail is still send to port 25 from mail-servers. But if you are a not a mail-server (e.g. a client in a network) you have to use the submission port and authentificate against your isp/comapany mail-server.
you can still use port 25 on your isp mail gateway but now they can filter and rate-limit your emails.
> It's like saying that most burglars come in through the back door so the government blocks everyones back door, they will just come in the front.
not really. it is good practive to only act as mailserver if you are on a static ip and mx records point to your server. none of this is fullfilled by dynamic isp ip adresses. So this just stops the unwanted practice for good.
He already got college credits from high school and studying at Berkeley, this important detail is nowhere found in the article.
I've also found that most of the advice sounds great but is hard to impossible to apply.
He appears to be exceptionally clever but a term paper on math and engineering problems are not written with a 12h marathon on the weekend, at least not on my university.
Can anyone recommend serious advice?
some other random ideas for php-security:
If you have to enable some form of option to exec binaries be aware that open_basedir is useless now, because the attacker can just start a python instance and operate under apache user if you are using mod_php
using fastcgi (mod_fcgid or nginx+php-fpm) and restrictive permissions on your directories should at least protect your other users home directories.
another idea is prevent malicous scripts is to firewall apache and php from iptables. there is an iptables module for restricting uid and gid ranges to have access to the outside world. this could at least prevent a trojan dropped in /tmp to connect to their irc-server. but you can also disallow outgoing traffic to port 80, this breaks however all the auto-update features of e.g. wordpress.
A lot of script-kiddie toolkits can also be stopped by not having gcc,wget,python etc.pp available to the user running php.
if you have to host sensitive data on the same host as the php application it's wise to use a jail or at least chroot for php, there are some guides to put a mod_fcgid php into a chroot
and: never ever use the mysql root user for database connectivity!
But why don't they use some hardened (grsecurity,selinux) kernel + http://linux-ima.sourceforge.net/ + a default forbid MAC policy + remote logging.
I can't see how this attack vector could be used against such a system.
These are deadly drones. It is probably a lot more work than using a plain windows box. But these machines can kill people. I thought the Military would use state of the art software security system.
I really guess I have to look after my feelings. Something went wrong along the way and now I'm struggling.
Yes, but not if you want to learn something. Then it is disastrous because you skip the "actually solving something" part.
I missed to make a concise point with that (concentration anyone?) It's more like 'Googling for a solution' became my default behaviour in most parts of my life. Be it education, food, advice... I think this is dangerous at least for me.
Reading good articles like that won't change anything. That's the bitter truth. At least this is the case for me, and probably some other people on the internet.
I'm nowhere near to have myself in full control again but I'm sick of wasting my days and feeling bad over this.
Willpower for me only works when I'm concentrated.
So there is a concentration problem. Being able to concentrate is also a muscle. I'm having a habit of actively avoiding exercising concentration.
Related to programming it's difficult for me:
A problem in my Code appears? I'm starting to Google solutions instead of trying to get a complete understanding of the problem. I'd fool myself into saying: I would look into this but I don't have the time and nobody will pay me for that. Googling and somehow trying to apply the results often works but it gives you an feeling of being unable to create something on it's own.
Then there is this thought: I would like to do something but there are too much people out there that could it better, so why bother trying?
And Instead of spending the days and nights learning and working on something I'm jumping around switching between problems I never fully understood nor am I able to afford the time to understand them...
So it comes down from willpower to concentration and at the moment I'm believing the cause for a lack of these skills is a lack of structure.
Structure for me is planning, planning in advance. Revisiting your plans and having clear ideas about yourself and the surrounding world. So creating structure requires concentration...
It works like a Circulus vitiosus in both ways. If you are structured for a longer time you're concentration and willpower will go up. If you lack concentration your structure get's weaker and concentration will fall, procrastination will rise.
How to solve this problem? Honest question.
(Sorry for hijacking this thread, but I think it is somewhat relevant to productivity and flow to sort these things out)
The biggest attack vector are outdated scripts. Once an attacker has access to PHP, he basically has a normal user login. Running PHP as the apache user gives the attacker full read access to all your web-folders.
If I where him, I'd put 2 lines code into the PHP-Webmail script to send me your e-mail logins and from there I can research further...
using fastcgi for php, block/log outgoing traffic per uid/gid, disable sockets for php uids, use suhosin to disallow certain php calls, nosuid,noexec webroot/tmp nothing really protects you against a mildy creative attacker...
I'm a sysadmin for a dozen LAMP shared hosting sites used by non-tech users and keeping these things secure is a major pain in the ass.
especially if your users want to use these riciolous unsecure php scripts. joomla die in a fire...
I'm sorry disabling version numbers is good idea but calling it "securing" your server is idiotic.
/rant
http://nbonvin.wordpress.com/2011/03/14/apache-vs-nginx-vs-v...
Fortran and COBOL are implementations of imperative programming languages. The ideas did not change. You still use while, for, if constructs in your ruby/python/java code.
only another level of abstractions was added now with object principles, you can create your own types, you can use polymorphism
but without an idea of imperative programming you would not be able to use these "new" languages (functional programming left aside)
I think it is the same with science, at least regarding physics - einstein did not proove newton wrong. he just extended his theory so that it would better describe the reality (in this case: what happens when you approach speed of light) but for most calculations newton's formulas are still fine.
I was turned off when I started college why I had to learn so much cs theory, but once you start to understanding the concepts and ideas behind certain things you are (theoretical) able to dissect the latest hype look and understand why things are the way they are.
tl;dr: learn concepts and ideas not specific implementations
http://en.wikipedia.org/wiki/THTR-300
http://juwel.fz-juelich.de:8080/dspace/bitstream/2128/3136/1... [50+ page PDF outlining the problems]
After skimming through the guide again, I also found that certain security related aspects are not included. There is no discussion about sensible ressource limits and other topics.
I found the guides from the german BSI (a goverment agency for information security) much better. https://www.bsi.bund.de/EN/Publications/publications_node.ht...
> 1.1.2 Minimize Software to Minimize Vulnerability
I agree on yum. If the attacker has root and can run yum. It is too late.
In regards to user mode applications: If you have wget, python, gcc on a php-only shared hosting server and your security depends of open_basedir (bad idea, don't do this) these usermode applications give you access to all data on the server.
> 2.1.1.1 Disk Partitioning
> nobody has ever been saved from having a 4GB /var/log partition
This is just plain wrong. If there is no disc-space left all kinds of strange error beginn to appear - e.g. your emails are not beeing delivered, apache fails with strange errors, users can't login. Imagine an attacker that wants to DoS you and he managed to fill your logs with excessive data.
> 2.1.1.2 Boot Loader Configuration
> Oh my god, HOW could we possibly be secure without a password to BOOT OUR MACHINE. The damn disks and boot partition aren't even encrypted, guys! This is useless!
It is not. I can boot from my USB thumbdrive and my private toolbox is now part of of the network (I can hijack the MAC and IP-Adress of the computer in question, can do arp-spoofing. If they use an old version of nfs I can even gain access to all files on the nfs server, because older nfs versions trust the client. And I can doing this likely without beeing noticed.
2.3.5 Protect Physical Console Access
Again. I'm into GRUB and and I can edit the linux-boot entry and add init=/bin/bash and voila I'm root on the machine. Without having to open the computer.
> 2.5.3.1 Disable Support for IPv6 unless Needed
IPv6 is still not largely deployed and it is a possible attack vector you can easily avoid unless you need it. I don't see a problem with this approach.
2.5.4.1 How TCP Wrapper Protects Services
It is another onion-ring in your security scheme. You should only permit hosts that require connections with your system. It is part of a bigger picture not the whole strategy.
3.5.1 Disable OpenSSH Server if Possible
Why not? E.g. I managed to sniff/can have a look at your E-Mail and you are so stupid to send plaintext account data around (happens all the time). Without access to OpenSSH I can't easily login into your server.
They just show a lot of possible attack vectors you can focus on. Taken alone every point mentioned here sounds kind of useless to implement. But if you combine all these ideas and implement them across your network/your server you have better security.
I can't understand why you ridicule this suggestions, they all are important depending on the context.