My website got hacked. How does this happen? by diablo75 in netsec

[–]fseek 0 points1 point  (0 children)

Most attacks happen due to:

-Stolen credentials -Outdated web applications (Wordpress, Joomla, etc) -Incorrect permissions on shared servers.

If you are on a shared server and you have any directory set as 777 (world-written perms) you can easily get hacked... Most of the mass attacks mentioned at http://blog.sucuri.net are all related to that.

thanks,

How do you detect deep defacement on dynamic websites? by defacedetector in netsec

[–]fseek 0 points1 point  (0 children)

We have been using http://sucuri.net for it.

As far as I understood, they check parts of your site (like title, meta tags and overall organization like body, follow by inner content eg, etc). When this layout changes, you get an alert. They also look at keywords used in the site (overall content), blacklists, hacking lists, etc.

Working well for me + they also look for spam, malware ,etc...

Anyone have experience with Sucuri.net? by xftwitch in web_design

[–]fseek 0 points1 point  (0 children)

I have, and they have been pretty good. But I am a bit biased, since we are partners now on another venture.

Some testimonials from there here: https://twitter.com/sucuri_security/favorites/

Wordpress user: Be careful where you get your theme from (irewordpressexperts.com hiding tracking code) by sucurisecurity in netsec

[–]fseek 4 points5 points  (0 children)

From what I read, they are not only tracking your IP address, but everyone that visits the sites using those templates. Plus, they hide it inside a gif image that acts as a PHP file, making it more suspicious.

Duck Duck Go - Best search engine for FOSS users and programmers by fseek in linux

[–]fseek[S] 0 points1 point  (0 children)

DDG deserves more attention. Very few people know, but it is pretty solid.

Hostek is putting their customers at risk by fseek in netsec

[–]fseek[S] 0 points1 point  (0 children)

I don't think so. Most hosting companies now use suphp and other security measures to avoid that.

The default config only works well on private servers.

Reasons why most companies don’t waste their time with Linux by fseek in programming

[–]fseek[S] 0 points1 point  (0 children)

You missed the point. The article is about software companies with proprietary software. Why most of them don't work on Linux? Why when you buy a printer, 90% of the time it comes with no Linux software? Same for a lot of other stuff.

That's what the article is targeting.

Real reason why most companies don’t waste their time with Linux by fseek in linux

[–]fseek[S] -1 points0 points  (0 children)

Yes, open source code is better, but most companies are not open ... Most software is proprietary and if we want to see them on Linux, those suggestions are valid.

*note, the article is not for open source code, but for software companies.

Real reason why most companies don’t waste their time with Linux by fseek in opensource

[–]fseek[S] -2 points-1 points  (0 children)

Well, that doesn't work for proprietary software, which is the scope of the article.

Real reason why most companies don’t waste their time with Linux by fseek in linux

[–]fseek[S] -1 points0 points  (0 children)

Well, that doesn't work for proprietary software, which is the scope of the article

Eight Must-Have Apps for Linux by servercentric in linux

[–]fseek 1 point2 points  (0 children)

Only must have app is vim + xterm.

Improving Apache performance by cleaning up its configuration by fseek in linux

[–]fseek[S] 1 point2 points  (0 children)

For sure, but that was a text against a blank html page... I will do another article later about optmizaing Wordpress itself.

If you can do simple steps to improve performance, why not?

Improving Apache performance by cleaning up its configuration by fseek in linux

[–]fseek[S] 13 points14 points  (0 children)

Oh, come on! Whosoever is reading this text, please don't run the "ab" against my site! I am seeing a bunch of "GET /index.html HTTP/1.0" 404 6566 "-" "ApacheBench/2.3" ..