-
mod_security book review
Posted on 10.01.2010 17:23 in Security231 views, 1 comment(s) , add a commentSome time ago Packt Publishing published a book about mod_security. Since I use mod_security very actively to protect servers, I decided to get this book and write a review.
Here it is.
-
Let's do something stupid!
Posted on 22.11.2009 23:33 in Security736 views, 8 comment(s) , add a commentLet's try some stupid HTTP requests to my server
For example, this... -
Persisting Korean spider, hack attempts
Posted on 14.10.2009 10:03 in Security550 views, No comments , add a commentAfter yesterday's incident with a stupid bot, I thought I might give you more insight on what happens on the Net...
-
Microsoft's msnbot acts crazy
Posted on 13.04.2009 20:12 in Security323 views, No comments , add a commentToday I saw a number of requests from various Microsoft Addresses with msnbot/20b as user agent.
This msnbot behaves wrong. It requests sites that neither existed, nor exist, nor will ever exist on this server. Here is an example (caught by mod_security2)...
-
A grave mistake with passwords
Posted on 25.02.2009 07:26 in Security443 views, 3 comment(s) , add a commentOne grave security–related mistake that I saw twice this month was related to passwords.
You are aware of the TYPO3 vulnerability that allows attackers to read localconf.php file. Lots of sites were attacked and hackers got passwords to some of them.
There is one thing that could make matters much worse and let hackers to exercise a full control over your web site. This thing is: using the same user name and password pair for both MySQL database and ssh login.
It may sound incredible but it is truth. Some people (and even some hosting...
-
A hammer for my DNS
Posted on 17.02.2009 19:55 in Security1718 views, 15 comment(s) , add a commentMy DNS in under attack for two weeks already. Details inside.
-
Toata dragostea mea pentru diavola
Posted on 15.02.2009 17:49 in Security7221 views, 17 comment(s) , add a commentAfter the recent security issues with TYPO3 I keep an especially close watch on my servers' mod_security logs. jumpurl atacks come from many IP addresses and they are already bore me. However today I saw something new and interesting...