Posts Tagged ‘security’

Updates 12-13-2011

So I finally got to catch up with all the WordPress updates.
Every site I manage is now running WordPress 3.3.

All plugins are up to date…
Themes are updated… code has been adjusted to be valid…

I also did a apt-get upgrade and dovecot of course was updated.
svn pull on roundcubemail had some changes…

So the updates end.
Enjoy!

Webmin

I changed webmin around a bit folks.
It can now be accessed from the following address here.

Of course you must have login access to use it of course…

Debian + Apache 2 (CVE-2011-1176)

Debian pushed the apache update finally (get to disable the workaround)
apache2 (2.2.16-6+squeeze1) stable-security; urgency=high
* Fix CVE-2011-1176 in apache2-mpm-itk: If NiceValue was set, the default
with no AssignUserID was to run as root:root instead of the default
Apache
user and group. Closes: #618857

So that should close the issue…
Thanks Debian and Apache for the fix!

SSL Certificate Update

So I finally found a solution for pretty much all of our encryption needs
for Inexistence services and such.

StartSSL provides a free SSL certificate service I have enabled all the
hosts that require SSL with new certificates so guess what this means?

No more stupid SSL connection errors no self signed nightmare.

Enjoy your encryption.
PS. If you would like SSL enabled for some reason on your site please
let me know and I’ll see what I can do (and if it’s even justified).

A little mistake big issue resolved…

Apparently while securing Inexistence (did an audit over the weekend) accounts,
I made an mistake of not adding false to the valid shells so pretty much all email was broken.

This issue has been addressed and all email accounts should work as expected.

If you were expecting an email and didn’t receive it I would email them and request them to resend it.
Thanks to George for the heads up about email being broken.

Sorry about this folks but hey you live and learn.

Once again we return to our normal scheduled program and enjoy!

Cloudflare

Well I add recently converted most of the sites on inexistence to now use cloudflare.
It’s a rather interesting service which has replaced my primary DNS service I used to use everydns.

To break it down for everyone this means better speed as they cache site files for quicker loading.
They also prevent known spambots from even connecting to hosted sites.

For any admin out there I heartily recommend their service as it’s really cost effective to boot.
(We are currently using their free account and it provides so much stuff!)

If you’re using self hosting with WordPress they even provide a plugin for analytics tracking stuff
along with a database optimization feature.
(Though I do automatic database optimization every four hours or so on Inexistence)

Anyways I hope everyone enjoys their just a little bit faster hosting and once again enjoy!

Super Upgrade Mode…

So tonight I finally got to roll the Debian 6.0 (Squeeze) update on Inexistence.
There may be some hiccups for the next few days as I fix anything that it broke.

I also started rolling IPv6 support now.
I will start adding AAAA dns records as I continue to test the functionality of each host.
All AAAA records have been set for all hosts now.

So please be patient if you notice anything break, I will more than likely be made aware
of it as it happens and will fix it as soon as I can…

Thanks and enjoy as always!

Updates to follow below (for any hiccups and their fixes):
2011-02-17
Slight hiccup detected with sendmail: local emailing (aka cron jobs) weren’t working as
expected thanks to submit.mc snafu. Fixed now from my preliminary tests aka all
my cron job emails are coming in.

2011-02-19
Did some changes to apache2 to improve performance and security.

SSH Access…

All SSH access is currently denied for all users as there is a rather evil kernel bug:
Hole in Linux kernel provides root rights

Of course Debian hasn’t patched this in backports yet (which we currently use).
So until this is fixed please drop me a support ticket if you really need shell access.

Otherwise please be patient and I’ll let you know when I lift the ban…

Debian has fixed this with the latest backport kernel upgrade.
Enjoy your shell access again folks!

Updates 06-26-2010

Apt-get upgrades:
apache2 apache2-doc apache2-mpm-prefork apache2-threaded-dev apache2-utils apache2.2-common apt apt-utils base-files cpio gtk2-engines-pixbuf libapache2-mod-perl2 libapr1 libapr1-dev libgtk2.0-0 libgtk2.0-bin libgtk2.0-common libgtk2.0-dev libkpathsea4 libpoppler-glib3 libpoppler3 libssl-dev libssl0.9.8 libxext-dev libxext6 linux-headers-2.6.26-2-amd64 linux-headers-2.6.26-2-common linux-image-2.6.26-2-amd64 linux-libc-dev nano nfs-common nfs-kernel-server openssl python-support tar tla tla-doc tzdata usbutils xserver-xorg-video-intel

Svn updates were pulled of course.
Enjoy!

Updates 06-16-2010

I did another apt-get upgrade mainly bind9 stuff nothing too important.

I installed imapproxy for squirrelmail/roundcubemail you should notice
an increase in speed when using them. (I know I did!)

Svn pulls were also performed tonight (roundcubemail, z-push)
Sadly because of so many changes I had to reset the roundcubemail
SQL database you will have to setup your account stuff again. (Sorry!)

I fixed mimedefang today for some reason it had a fit and prevented
sendmail from doing it’s job properly…

I updated all wordpress plugins on all of the sites I manage.

And I played around with WordPress 3.0 RC3 tonight it’s looking good.

Now friend connect with me via the bar at top and read the site more
often users! All major changes that occur on Inexistence I post here!

End of Line.

Return top