I remember around 2001 - when he started his digital "Jihad" against Bin Laden - his web server was hacked several times with a public FreeBSD telnetd remote root exploit.
I won't deny that you have to give him some respect for being able to pull all these stunts and acquiring the money from investors, however as it seems most if not all projects where at least partly illegal.
I don't know. I'm just on the end-user side. Just a guess from my (pretty limited) understanding of the issue: The grsecurity[1] patch includes PaX[2] that can break a lot of software. e.g. Java and X11 and there are sometimes other unwanted side effects as well. And I've found a blog post stating that the author does not want to maintain a upstream patch[3].
I'd love to see up to date stable grsecurity kernel repositories for the major distributions (ubuntu, debian, rhel/centos) that provide patched versions of the distribution kernel. You can configure most of grsecurity via the sysctl interface. At the moment it is always a bit of hassle to patch & compile a kernel from hand even with the great debian/ubuntu kernel-package.
I don't think I'll use an extra distribution. But something like a hardened LAMP/LAPP stack for shared hosting out of the box in a distribution would be great (I think in terms of easy chrooting of users and php, secure permissions, etc.pp) However, I guess everyone has different needs and there is no one size that fits for all.
I know. I want to know if someone with a kernel >=2.6.39 and applied grsecurity patch can successfully use this exploit or if grsecurity protects from this exploit.
I know exactly what you are talking about. Following a plan can be hard. If you don't have clean socks anymore try to include that into your plan. Say 30min household stuff... nobody will ever see my plan. It is personal, full of probably questionable content for other people, but it is realistic and only when it is realistic you even have a chance to fullfill it.
Also: Iterate. Make a plan for tomorrow, realize tomorrow you are 50% off, ask yourself why...iterate till you can fullfill the plan. Include the stuff that stopped you from fullfilling your original plan, spot problems, experiment with solutions. Beeing honest with yourself can be hard.
And: Only do this for 50-70% of your time. If you plan everything you'll go nuts very soon (At least I do) but don't omit personal goals or problems.
As for the problem of acting on the plan: Think about binary sort... split the problem till you can handle it, then merge the parts. If you don't know how to handle it you can always think about splitting it up.
> It stops our mail server from being used as an open relay though?
From outside of your network yes. If one of the computers inside your network is infected your mail-server will happily deliver the spam mails.
> How does blocking 1 specific port stop the issue anyway?
> They can just change the port they connect on?
I don't know of any SMTP-Server that accepts E-Mail on Ports other than 25. Port 587 requires authentification before sending an E-Mail.
I thought most poeple don't accept E-Mails sent from isp-networks with dynamic ip adresseses. Maybe that's not the case and they try to reduce spam this way.
> I was offering an opinion on how to resolve those issues.
> Changing which port accepts the mail is in my opinion pointless.
Nobody changed any ports. E-Mail is still send to port 25 from mail-servers. But if you are a not a mail-server (e.g. a client in a network) you have to use the submission port and authentificate against your isp/comapany mail-server.
you can still use port 25 on your isp mail gateway but now they can filter and rate-limit your emails.
> It's like saying that most burglars come in through the back door so the government blocks everyones back door, they will just come in the front.
not really. it is good practive to only act as mailserver if you are on a static ip and mx records point to your server. none of this is fullfilled by dynamic isp ip adresses. So this just stops the unwanted practice for good.
I'm quite new to Steve Pavlina writings. So I've checked with Wikipedia to get an idea on his claims.
He already got college credits from high school and studying at Berkeley, this important detail is nowhere found in the article.
I've also found that most of the advice sounds great but is hard to impossible to apply.
He appears to be exceptionally clever but a term paper on math and engineering problems are not written with a 12h marathon on the weekend, at least not on my university.
That's pretty sound advice. However a lot of scripts won't work if you disable exec and co.
some other random ideas for php-security:
If you have to enable some form of option to exec binaries be aware that open_basedir is useless now, because the attacker can just start a python instance and operate under apache user if you are using mod_php
using fastcgi (mod_fcgid or nginx+php-fpm) and restrictive permissions on your directories should at least protect your other users home directories.
another idea is prevent malicous scripts is to firewall apache and php from iptables. there is an iptables module for restricting uid and gid ranges to have access to the outside world. this could at least prevent a trojan dropped in /tmp to connect to their irc-server. but you can also disallow outgoing traffic to port 80, this breaks however all the auto-update features of e.g. wordpress.
A lot of script-kiddie toolkits can also be stopped by not having gcc,wget,python etc.pp available to the user running php.
if you have to host sensitive data on the same host as the php application it's wise to use a jail or at least chroot for php, there are some guides to put a mod_fcgid php into a chroot
and: never ever use the mysql root user for database connectivity!
I'm sure a vanilla linux-distribution is as easy an target as a windows box, if not even easier.
But why don't they use some hardened (grsecurity,selinux) kernel + http://linux-ima.sourceforge.net/ + a default forbid MAC policy + remote logging.
I can't see how this attack vector could be used against such a system.
These are deadly drones. It is probably a lot more work than using a plain windows box. But these machines can kill people. I thought the Military would use state of the art software security system.
No I think there isn't. It is effective and often there is probably no other even mildly realistic way to solve some problem in time (e.g. a bug that is reported in the software bug-tracker)
I missed to make a concise point with that (concentration anyone?) It's more like 'Googling for a solution' became my default behaviour in most parts of my life. Be it education, food, advice... I think this is dangerous at least for me.
Reading good articles like that won't change anything. That's the bitter truth. At least this is the case for me, and probably some other people on the internet.
I'm nowhere near to have myself in full control again but I'm sick of wasting my days and feeling bad over this.
Willpower for me only works when I'm concentrated.
So there is a concentration problem. Being able to concentrate is also a muscle. I'm having a habit of actively avoiding exercising concentration.
Related to programming it's difficult for me:
A problem in my Code appears? I'm starting to Google solutions instead of trying to get a complete understanding of the problem. I'd fool myself into saying: I would look into this but I don't have the time and nobody will pay me for that. Googling and somehow trying to apply the results often works but it gives you an feeling of being unable to create something on it's own.
Then there is this thought: I would like to do something but there are too much people out there that could it better, so why bother trying?
And Instead of spending the days and nights learning and working on something I'm jumping around switching between problems I never fully understood nor am I able to afford the time to understand them...
So it comes down from willpower to concentration and at the moment I'm believing the cause for a lack of these skills is a lack of structure.
Structure for me is planning, planning in advance. Revisiting your plans and having clear ideas about yourself and the surrounding world. So creating structure requires concentration...
It works like a Circulus vitiosus in both ways. If you are structured for a longer time you're concentration and willpower will go up. If you lack concentration your structure get's weaker and concentration will fall, procrastination will rise.
How to solve this problem? Honest question.
(Sorry for hijacking this thread, but I think it is somewhat relevant to productivity and flow to sort these things out)
If I'd like to "hack" a LAMP-Server I certainly wouldn't start by attacking Apache or PHP.
The biggest attack vector are outdated scripts. Once an attacker has access to PHP, he basically has a normal user login. Running PHP as the apache user gives the attacker full read access to all your web-folders.
If I where him, I'd put 2 lines code into the PHP-Webmail script to send me your e-mail logins and from there I can research further...
using fastcgi for php, block/log outgoing traffic per uid/gid, disable sockets for php uids, use suhosin to disallow certain php calls, nosuid,noexec webroot/tmp nothing really protects you against a mildy creative attacker...
I'm a sysadmin for a dozen LAMP shared hosting sites used by non-tech users and keeping these things secure is a major pain in the ass.
especially if your users want to use these riciolous unsecure php scripts. joomla die in a fire...
I'm sorry disabling version numbers is good idea but calling it "securing" your server is idiotic.
I don't think this is true. Apache with mpm_worker and fastcgi for python/php should perform on a typical dedicated server like nginx till the network is saturated. you also have to consider that .htaccess files are quite cpu intensive because the way apache works they are parsed at every request. put your .htaccess config in the config-file disable unused modules and use mpm worker and I bet the difference is negligible. if you have to count every io operation and you run on small memory nginx may make a difference.
Fortran and COBOL are implementations of imperative programming languages. The ideas did not change. You still use while, for, if constructs in your ruby/python/java code.
only another level of abstractions was added now with object principles, you can create your own types, you can use polymorphism
but without an idea of imperative programming you would not be able to use these "new" languages (functional programming left aside)
I think it is the same with science, at least regarding physics - einstein did not proove newton wrong. he just extended his theory so that it would better describe the reality (in this case: what happens when you approach speed of light) but for most calculations newton's formulas are still fine.
I was turned off when I started college why I had to learn so much cs theory, but once you start to understanding the concepts and ideas behind certain things you are (theoretical) able to dissect the latest hype look and understand why things are the way they are.
tl;dr: learn concepts and ideas not specific implementations
If you use ngix + php-fpm: the nginx fastcgi_cache module http://wiki.nginx.org/HttpFcgiModule#fastcgi_cache is really neat and a lot faster than the full-page caching plugins. I also found that an object cache does improve performance a lot for pages that are generated from wordpress, saving tons of database queries.
I won't deny that you have to give him some respect for being able to pull all these stunts and acquiring the money from investors, however as it seems most if not all projects where at least partly illegal.