With our promise of adding more services to our portfolio, we have now launched dedicated hosting at our India Datacenter.
Showing posts with label server. Show all posts
Showing posts with label server. Show all posts
Wednesday, March 9, 2016
Sunday, February 8, 2015
BIG FEBRUARY Upto 25% Discount
Big Offer of the Year.
We are excited to announce Big Offer of the Year. Buy any Linux Hosting from us and Get 25% Discount on Total Amount in Your cart.
![]() |
| This Offer is valid for limited Period |
We are also offer Huge Discount on Our Dedicated Servers. Buy your dedicated server from us and GET 5% Discount and 1 Comodo Positive SSL free for lifetime*
![]() |
| For Limited Stock. First Come and First Serve |
Why don't you buy your domain name just at Rs.99/yr.
Buy .PW or .XYZ domain name just at Rs.99 for a year.
![]() |
| BOOK DOMAIN NOW |
We also have many offers.... Just come and Grab your offer Now.
Labels:
cheap .com,
cheap domain registration,
cheap ssl,
Cheap Unlimited Hosting,
Cheap web hosting,
Free domain,
Free domain Registration,
Free SSL,
new gTLDs,
PHP,
server,
SSL,
TLDs,
Web hosting,
web security
Tuesday, January 27, 2015
cPanel, Inc. has released EasyApache 3.28.2 with PHP versions 5.4.37 and 5.5.21.
cPanel, Inc. has released EasyApache 3.28.2 with PHP versions 5.4.37 and 5.5.21. This release addresses vulnerabilities related to CVE-2015-0231, CVE-2014-9427, and CVE-2015-0232 by fixing bug in the Core module, Exif extension, and CGI. We strongly encourage all PHP 5.4 users to upgrade to version 5.4.37 and all PHP 5.5 users to upgrade to version 5.5.21.
AFFECTED VERSIONS
All versions of PHP 5.4 through version 5.4.36
All versions of PHP 5.5 through version 5.5.20
SECURITY RATING
The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs:
CVE-2015-0231 - MEDIUM
PHP 5.4.37
Fixed bug in the Core module related to CVE-2015-0231
PHP 5.5.21
Fixed bug in the Core module related to CVE-2015-0231
Friday, October 24, 2014
SHA-1 Sunsetting, Google, and Your Next Steps.
What is happening, and what was
happening?
The SSL
Industry and the CA/B Forum have planned for the "sunsetting"
(depreciation) of the SHA-1 signing algorithm for quite some time. However,
their plan was mainly formed around Microsoft's desires to phase it out in
2017, alongside the end-of-life for Windows XP. This was widely understood to
be the approved plan for CAs to follow, and the preparation for moving from
SHA-1 to its successor, SHA-2, wouldn't be necessary for many months from now.
However,
Google recently made an announcement, in stark contrast to Microsoft's plan,
that they are implementing their own SHA-1 sunsetting timeline, which will
begin on September 26th 2014.
This
timeline has three distinct stages, which will result in degraded visual
indicators in Google Chrome (padlock, green-bar) for SHA-1 signed certificates
meeting specific criteria (this is discussed in the section "What
certificates are affected?" below).
This means
it is now necessary to educate and assist our partners and customers on how to
make the transition away from SHA-1.
Why?
First, let's
understand what SHA-1 does. Both SHA-1 and its successor, SHA-2, are specific
types of signing algorithms. Signing algorithms are used as part of the
identity validation role that SSL certificates perform. They are mathematical
functions (referred to as a "hash") which, when performed, should
calculate a persistent and unique value for each file. So, for instance, the
Word doc this text is stored in has a unique SHA-1 hash value. If I change a
single part of this file – add an extra period somewhere, change a letter, etc.
– it will produce a different SHA-1 hash value.
When a
certificate is downloaded from a server to the client's browser, a hash is
taken of it. The type of hash taken (SHA-1, SHA-2, MD5, etc.) depends on how
the certificate is signed. The hash calculated by the browser is compared to
the hash value provided by the server, which has been verified by the
Certificate Authority (CA) at the time of issuance. If they match, the identity
of the certificate and server are verified.
When is this happening?
Google's
policy involves three distinct steps, the first beginning on September 26th. On
this date, only customers with SHA-1 signed certificates expiring in 2017 are
affected. However, the amount of affected certificates will expand in November,
and again in Q1 2015. The full details on what certificates are affected is in
the below section, "The Nitty Gritty."
What certificates are affected?
Monday, September 29, 2014
Bash Code Injection Vulnerability via Specially Crafted Environment Variables (CVE-2014-6271, CVE-2014-7169)
Red Hat has been made aware of a vulnerability affecting all versions of the bash package as shipped with Red Hat products. This vulnerability CVE-2014-6271 could allow for arbitrary code execution. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue.
Update: 2014-09-29 05:00 UTC
Malware is circulating that exploits this vulnerability. For more details, see this article.
Update: 2014-09-26 05:15 UTC
Red Hat has become aware that the patch for CVE-2014-6271 is incomplete. An attacker can provide specially-crafted environment variables containing arbitrary commands that will be executed on vulnerable systems under certain conditions. The new issue has been assigned CVE-2014-7169.
Updated bash packages that address CVE-2014-7169 are now available for Red Hat Enterprise Linux 5, 6, and 7, Red Hat Enterprise Linux 4 Extended Life Cycle Support, Red Hat Enterprise Linux 5.6 Long Life, Red Hat Enterprise Linux 5.9 Extended Update Support, Red Hat Enterprise Linux 6.2 Advanced Update Support, and Red Hat Enterprise Linux 6.4 Extended Update Support, and Shift_JIS for Red Hat Enterprise Linux 5 and 6. See alsoResolution for Bash Code Injection Vulnerability via Specially Crafted Environment Variables (CVE-2014-6271, CVE-2014-7169) in Red Hat Enterprise Linux.
Diagnostic Steps
Red Hat Access Labs has provided a script to help confirm if a system is patched against to the Shellshock vulnerability. You can also manually test your version of Bash by running the following command:
$ env 'x=() { :;}; echo vulnerable' 'BASH_FUNC_x()=() { :;}; echo vulnerable' bash -c "echo test"
If the output of the above command contains a line containing only the word
vulnerable you are using a vulnerable version of Bash. The patch used to fix this issue ensures that no code is allowed after the end of a Bash function.Thursday, September 11, 2014
Java based Cross platform malware targeting Apache Tomcat servers in the wild
Takashi Katsuki, a researcher at Antivirus firm Symantec has discovered a new cyber attack ongoing in the wild, targeting an open-source Web server application server Apache Tomcat with a cross platform Java based backdoor that can be used to attack other machines.
The malware, dubbed as "Java.Tomdep" differs from other server malware and is not written in the PHP scripting language. It is basically a Java based backdoor act as Java Servlet that gives Apache Tomcat platforms malicious capabilities.
Because Java is a cross platform language, the affected platforms include Linux, Mac OS X, Solaris, and most supported versions of Windows. The malware was detected less than a month ago and so far the number of infected machines appears to be low.
You may think that this type of attack only targets personal computers, such as desktops and laptops, but unfortunately that isn’t true. Servers can also be attacked. They are quite valuable targets, since they are usually high-performance computers and run 24x7.
Java worm seeks out for the system having Apache Tomcat installed-running and then attempts to log-in using the password brute-force attack using combinations of user names and passwords.
After installation, the malware servlet behaves like an IRC Bot and able to receive commands from an attacker. Malware is capable of sending-downloading files from the system, create new processes, update itself, can setup SOCKS proxy, UDP flooding i.e. Can perform massive DDoS Attack.
They have mentioned that the command-and-control servers have been traced to Taiwan and Luxembourg. In order to avoid this threat, ensure that your server and AV products are fully patched and updated.
Source: TheHackerNews.com
Sunday, May 25, 2014
DDoS attacks using SNMP amplification on the rise !
Attackers are increasingly abusing devices configured to publicly reply to SNMP (Simple Network Management Protocol) requests over the internet to amplify distributed denial-of-service attacks.
This amplification technique, which is additionally known as reflection, can on paper work with any protocol that's vulnerable to science (Internet Protocol) address spoofing and might generate giant responses to significantly smaller queries. Attackers can craft requests that seem to originate from the science address of their intended victim in order to trick servers that accept requests over such protocols from the internet to flood the victim with information.
Many DDoS attacks within the past year have used misconfigured DNS (Domain Name System) and NTP (Network Time Protocol) servers for amplification. However, devices that support SNMP, a protocol designed to allow the observation of network-attached devices by querying info about their configuration, may be abused if the SNMP service is directly exposed to the internet. SNMP-enabled devices with such configurations are often found each in home and business environments and embody printers, switches, firewalls and routers.
This amplification technique, which is additionally known as reflection, can on paper work with any protocol that's vulnerable to science (Internet Protocol) address spoofing and might generate giant responses to significantly smaller queries. Attackers can craft requests that seem to originate from the science address of their intended victim in order to trick servers that accept requests over such protocols from the internet to flood the victim with information.
Many DDoS attacks within the past year have used misconfigured DNS (Domain Name System) and NTP (Network Time Protocol) servers for amplification. However, devices that support SNMP, a protocol designed to allow the observation of network-attached devices by querying info about their configuration, may be abused if the SNMP service is directly exposed to the internet. SNMP-enabled devices with such configurations are often found each in home and business environments and embody printers, switches, firewalls and routers.
Labels:
security,
server,
vps,
Web hosting,
web security
Thursday, May 15, 2014
Choosing the correct Dedicated Server
Choosing the correct
Dedicated Server Makes Business Sense
“Someone can always do your job a little
better or faster or cheaper than you can.”- Seth Godin
The selling guru’s statement echoes the emotions of this
trends in business. Most webmasters feel growing pains after they ought to
expand from their existing setup to a bigger one. But, the pinch or the impact
actually strikes when a rival offers the same service with better deals and
quicker speed on-line. Your rival has most likely captive onto an avid server.
A Dedicated Server Brings
your Business Up to speed
Dedicated server hosting usually involves one pc that is
dedicated towards the needs of a specific network. By having a server that's
dedicated towards hosting, storing information or perhaps communication with
other computers, businesses have the advantage of area, time and future
resources. Here’s a look at the advantages of getting an avid server.
Dedicated or shared?
Managed dedicated server hosting is practically viable
despite being slightly dearer than shared server hosting. when it comes to the
decision-making process for a shared server or an avid server, check for
factors which will make it easier for your business to propel ahead. we give a
elaborate run-down of the distinction between dedicated and shared servers.
Choosing the one:
Choosing between an avid server and a shared one ought to be
practically easy. In a trial to decide on convenience and low cost, most
businesses opt to escort shared servers. Yet, despite the cost facet, there area
unit some definite benefits of getting dedicated servers. So, if you are aiming
to choose an avid server instead of a shared server, then, look out for these
factors to improve your higher cognitive process. Here’s what ought to inspect
in your server:
- · Check the compatibility of the OS in your server. Also, the open source stack involves ought to be vetted out for Ruby on Rails, Linux or perhaps an Apache/php/mysql server.
- · By preferring the technology stack, you'll assess the quantity of RAM that you simply want for your design.
- · To traumatize performance problems, its best that you simply choose an avid server like those offered by recognized server suppliers just like the ones at the icloudJunction.
- · In order to host pictures, videos or any other transmission options like flash applications, its best to decide on a server that offers the optimal information measure and disc space.
- · Check for monthly costs and setup costs. Compare the rates for software licensing, upgrades and components, with the exception of other management plans and extra services.
Featuring amongst the top of the lists of the most effective
suppliers of dedicated servers is the icloudJunction. Compared to relatively
sensible suppliers like Godaddy.com, icloudJunction is additional well-liked for
the subsequent three reasons:
Flexibility:
icloudJunction dedicated servers area unit designed to suit the needs of these
involved in web hosting for personal use or for any business.
Fair prices: If
you thought that dedicated server web hosting is pricey business, move removed
from the other suppliers and inspect the latest offerings from icloudJunction.
Reliable and bankable
support: when it comes to the near zero period of time and around the clock
support, then it’s time that you simply enter the support staff at the
icloudJunction.
“As the statistics show, sixty two of all websites in Alexa prime 10k
by traffic area unit hosted on Dedicated Servers."
Lastly, the selection of the best server is it dedicated or
shared ought to be determined solely the conditions people who area unit unique
to your business or personal use. Don’t hesitate to explore for the best
distributor of servers that follow the conditions based on your requirements.
Thursday, May 1, 2014
Secure your LAMP based VPS and Dedicated Web Servers
The Internet has given United States the ability to shop for product, create payments etc instantly from the comfort of our own homes. but beside these advantages, there's Associate in Nursing underlying cyber security threat at hand. it had been recently unconcealed that quite 360 million stolen Credit Cards accounts were up purchasable on the cyber black market. With many similar incidents like this returning to the fore within the past, it's essential to make sure that you simply keep crucial info regarding your customers’ secure and save yourself many bucks in shopper lawsuits.
We’ve place along slightly guide to assist you scale back the chance of your your LAMP based mostly servers from obtaining hacked. LAMP is one in all the foremost popularly used Application Stacks. It stands for UNIX system, Apache, PHP and MySQL.
Mitigate the risks of your servers being attacked
The Apache net Server is one in all the foremost normally used net Servers. but like most different software package, it needs acceptable settings, observance and maintenance to protect against vulnerabilities. during this post, we are going to cowl each General pointers that you simply will follow to secure your server, additionally as bound specific steps that you simply ought to address to mitigate the injury caused by such attacks.
General Security pointers to be followed for securing your net Server
- Sign up for updates and announcements from the net Server listing.
- Upgrade to the newest version whenever there's Associate in Nursing update.
- Install solely the modules you need and disable excess ones.
- Make sure you log all admin level accesses with date, times and usernames
- Do not show your server version or OS version in error messages.
For Servers with Apache:
1. Hide the Apache Version variety, and different sensitive info
It is essential to cover the Apache Version variety your server is running, additionally as different sensitive info. you'll try this by following the straightforward steps listed below.
Add or Edit the subsequent 2 directives in your httpd.conf file
ServerSignature Off
ServerTokens Prod
The ServerSignature seems on the lowest of pages generated by apache like 404 pages, directory listings, etc.
The ServerTokens directive is employed to see what Apache can place within the Server hypertext transfer protocol response header. By setting it to Prod it sets the hypertext transfer protocol response header as follows:
Server: Apache
2. certify apache is running underneath its own user account and cluster
When Apache is put in, the default user is ready as “nobody”. but if there different applications that additionally run because the user no one on your system, then a compromise of apache can even compromise different installations. it's best to feature a separate user “apache” and so modify the subsequent directives in httpd.conf to run apache because it own user.
User apache
Group apache
3. make sure that files outside the net root directory aren't accessed.
It is continually smart apply to limit access for files outside the net root directory to take care of security and make sure that these files square measure solely accessed by folks that have to be compelled to access them.
<Directory />
Order Deny,Allow
Deny from all
Options None
AllowOverride None
</Directory>
<Directory /html>
Order Allow,Deny
Allow from all
</Directory>
Order Deny,Allow
Deny from all
Options None
AllowOverride None
</Directory>
<Directory /html>
Order Allow,Deny
Allow from all
</Directory>
Note that as a result of we tend to set “Options None” and “AllowOverride None “this can shut down all choices and overrides for the server. You currently got to add them expressly for every directory that needs Associate in Nursing choice or Override.
4. shut down directory browsing, Follow symbolic links and CGI execution
You can try this with Associate in Nursing choices directive within a Directory tag.
If you would like to show off all choices merely use:
Options None
If you simply need to show off some, separate every choice with an area in your choices directive:
Options -ExecCGI -FollowSymLinks -Indexes
5. Install modsecurity
ModSecurity is Associate in Nursing Apache add on module which might sight and stop hypertext transfer protocol attacks. It will are available in extremely handy in preventing SQL injections just in case your developers forget to feature input validation or determine and block info revealing problems like unseaworthy elaborate error messages, social insurance Numbers or mastercard Numbers. Follow these steps to put in mod-security
On CentOS:
yum install mod_security
On Ubuntu:
apt-get install mod_security.
service httpd restart
6. Disable any excess modules
There square measure many modules that square measure enabled on your Apache net Server that you simply might not want. to look for modules put in run:
grep LoadModule httpd.conf
Here square measure some modules that square measure generally enabled however usually not needed:
mod_imap
mod_include
mod_info
mod_userdir
mod_status
mod_cgi
mod_autoindex.
To disable them add a # check in front of them.
You can additionally bear the Apache module documentation and disable or alter any that you simply want.
7. Lower the Timeout worth
The default Timeout directive is ready to three hundred seconds. Decreasing this worth help’s mitigating the potential effects of a denial of service attack.
Timeout 45
8. Limit massive requests
In order to mitigate the consequences of a denial of service attack, limit the number of body that may be sent in Associate in Nursing hypertext transfer protocol request. If you are doing not have massive uploads then you'll limit this to 1Mb via the below directive.
LimitRequestBody 1048576
Application and Database Security
SQL injection is another common method of extracting knowledge from poorly coded websites. Here is however you'll forestall it and different such attacks.
- Ensure your Applications like Joomla, WordPress, Drupal etc square measure upto date.
- Subscribe to Bug updates and Vulnerability reports.
- Try and avoid world writable 777 permissions your files or folders.
- Regularly check for viruses or infections by scanning your net package.
- If you're victimization MySQL or MariaDB run the mysql secure installation script.
- If your application needs you to store wind like username, passwords, mastercard knowledge etc. then make sure that all communication is encrypted by employing a Digital Certificate.
For servers with PHP:
1. Run PHP as a separate User
It is suggested to put in php as a separate user than as Associate in Nursing Apache Module. If you put in php as Associate in Nursing Apache Module then php can run with the apache user permission and any compromise of a vulnerable php script will cause a server wide compromise.
A better way to install php would be with php-fpm a fastcgi method manager that permits you to run and manage php scripts as a separate user.
2. Use the POST methodology to pass vital parameters like credit card info
Many developers already recognize this. PHP has 2 ways to pass variable info via a type the GET methodology and also the POST methodology. the foremost vital distinction between these ways is that the GET methodology makes your pass info visible to everybody via a URL whereas POST methodology doesn't. thence sensitive info like usernames, passwords must always be passed via the POST methodology.
3. continually Validate type and Text Input
Cross web site scripting and SQL injection will each be prevented if type or file input is valid.
Cross web site scripting permits a hacker to run malicious code on your server by merely uploading a file with malicious code in it to be run on the server and SQL injection permits a hacker to urge access to your info by injecting malicious queries in your type to urge info info like table name. an easy thanks to validate php code is found at
4 . Hide the PHP version
Open php.ini and add the subsequent
Vim /etc/php.ini
expose_php = Off
5.Log all php errors to a file and not on the web site
display_errors = Off
log_errors = On
error_log = /var/log/httpd/php_error.log
For servers with MySQL or MariaDB:
1. Run MySQL Secure Install
After putting in MySQL run the mysql_secure_installation script.
sudo /usr/bin/mysql_secure_installation
This script can prompt you to feature a mysql root secret, lock root access to localhost and take away any unwanted infos just like the take a look at database.
2. Secure MySQL users and database
Log into your MySQL Server and make sure that all MySQL users have a secret and delete any unwanted user. Grant access to solely those databases that the individual users would use.
Following the steps elaborate on top of, you'll go an extended method in making certain that your customer’s knowledge remains secure. within the next article i'll add detail steps on UNIX system OS and Firewall Security.
Let us recognize if these techniques were useful by effort a comment below
Subscribe to:
Posts (Atom)





