<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Digitalquill - My Life and Times &#187; hack</title> <atom:link href="http://www.matthouldsworth.com/tag/hack/feed/" rel="self" type="application/rss+xml" /><link>http://www.matthouldsworth.com</link> <description>Affiliate Marketing, Wordpress Development, DIY and More</description> <lastBuildDate>Thu, 05 Jan 2012 20:53:35 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>Are We Seeing The Worlds First Cyber War?</title><link>http://www.matthouldsworth.com/2010/12/are-we-seeing-the-worlds-first-cyber-war-2/</link> <comments>http://www.matthouldsworth.com/2010/12/are-we-seeing-the-worlds-first-cyber-war-2/#comments</comments> <pubDate>Thu, 09 Dec 2010 20:24:47 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Amazon S3]]></category> <category><![CDATA[Internet]]></category> <category><![CDATA[cyber attack]]></category> <category><![CDATA[cyber war]]></category> <category><![CDATA[cyberwar]]></category> <category><![CDATA[ddos]]></category> <category><![CDATA[denial of service]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[hacking]]></category> <category><![CDATA[malware]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=2617</guid> <description><![CDATA[I will start this post with the clear statement that I am not in anyway supporting, not supporting or involved in anyway with the current reported DDOS on many institutions. This blog post merely comments on what appears to be a new form of war fair with very different targets and very different players. I &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/12/are-we-seeing-the-worlds-first-cyber-war-2/">Continue reading &#187;</a> No related posts.]]></description> <content:encoded><![CDATA[<p>I will start this post with the clear statement that I am not in anyway supporting, not supporting or involved in anyway with the current reported DDOS on many institutions. This blog post merely comments on what appears to be a new form of war fair with very different targets and very different players.</p><p>I will not Link to any of those involved. You can easily Google them if you are interested.</p><p><a
href="http://www.matthouldsworth.com/wp-content/uploads/2010/12/wikileaks.jpg" ><img
class="aligncenter size-medium wp-image-2621" title="wikileaks" src="http://www.matthouldsworth.com/wp-content/uploads/2010/12/wikileaks-300x168.jpg" alt="" width="300" height="168" /></a></p><p>There are several under ground groups that, although have been around for some time now, seem to have mobilized a great deal of support in the Internet community. They have also seemingly being able to gather support from people who would not normally engage in such underground (and questionably legal tactics) . This growing body of support has allowed these groups to cause significant disruption.</p><p>I have been interested to read the back and forth, tit for tat DDOS attacks on some very high profile institutions, and the apparent retaliation attacks by supporters of those organizations or &#8216;governmental&#8217; positions.</p><p>It seems that the current situation is that the following sites have come under attack:</p><p>Wikileaks<br
/> EveryDNS<br
/> Amazon (I assume Amazon S3/Cloud)<br
/> Paypal<br
/> Paypals Blog<br
/> PostFinance<br
/> Anonymous Group<br
/> Swedish Prosecutors<br
/> Senate Lieberman<br
/> Group of Patriots<br
/> OperationPayback<br
/> Lawyer for the Swedish Prosecution<br
/> Sarah Palins site<br
/> MasterCard<br
/> Visa Card<br
/> Twitter</p><p>I am not so sure that this situation is entirely being run by underground internet groups, I am convinced that there is at least some manipulation of the situation by bigger powers interested Governments on both sites I am sure at influencing the process.</p><p>We know that the Israeli secret services were most likely behind the recent Stuxnet worm attack on the Iranian Atomic Energy research systems. This was not your standard Malware worm, it was specifically designed to make centrifuges spin out of control and as such cause actual hardware damage as well as software infection.</p><p>It is highly likely that we are currently witnessing the worlds fist Cyber War, although it is not being conducted directly by governmental agencies it is likely that there is significant pressure been born on both sites, manipulation and even support being given by interested parties.</p><p>Does this show the warfair of the future? it is all to easy for significant damage to be done via cyber attacks, possibly causing more significant damage to a country, economy or business than traditional bombs and bullit warfair.</p><p>We will have to see how this plays out over the next few days, but I do believe that it is a significant development and whatever, and whomever is behind these attacks on both sites I am sure we will see them again, possibly with greater consequences for life as we know it.</p><p>It does raise the issue of security, it turns out that Master card have very little in the way of protection against these kind of attacks. For such a large organisation this is shocking especially considering the type of business they are in.</p><p>There are things that businesses can do to mitigate against these types of issue. As a software project manager, something that I am always talking about is disaster recovery and business continuity plans. It is often thought that these  should solely cover traditional threats such as fire, flooding, earthquakes and other natural disasters, however, the impacts of the 9/11 attacks on the economy at large showed that today we are all interlinked and shock waves will be felt.</p><p>Business continuity plans and disaster recovery should also seriously consider new threats from cyber attacks, viruses, malware, DDOS attacks and from becoming embroiled in controversy as those listed above have been, and what your policy will be in the event that you do.</p><p>No related posts.</p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/12/are-we-seeing-the-worlds-first-cyber-war-2/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Vpsville Review</title><link>http://www.matthouldsworth.com/2010/11/vpsville-review/</link> <comments>http://www.matthouldsworth.com/2010/11/vpsville-review/#comments</comments> <pubDate>Fri, 05 Nov 2010 20:20:52 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Affiliate Marketing]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Web/Mail Servers]]></category> <category><![CDATA[debian]]></category> <category><![CDATA[email server]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[hacked]]></category> <category><![CDATA[linux]]></category> <category><![CDATA[server]]></category> <category><![CDATA[ssh]]></category> <category><![CDATA[ubuntu]]></category> <category><![CDATA[ultrahosting]]></category> <category><![CDATA[virtual hosting]]></category> <category><![CDATA[virtual private server]]></category> <category><![CDATA[vps]]></category> <category><![CDATA[vpsville]]></category> <category><![CDATA[web hosting]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=2172</guid> <description><![CDATA[Regular readers of this blog will know that I have recently moved all my web hosting to a new provider following a devastating hack of one of my dedicated servers which was hosted with Ultrahosting. I had a bad experience with Ultrahosting support and will not be using them again in the future. I have &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/11/vpsville-review/">Continue reading &#187;</a> Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/07/hostgator-25-off-coupon-for-digitalquill-customers/' rel='bookmark' title='Hostgator 25% Off Coupon For Digitalquill Customers'>Hostgator 25% Off Coupon For Digitalquill Customers</a> <small>We have secured a 25% off coupon code for HostGator, readers of this blog and Digitalquill customers can get this 25% discount by using the...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/outlook-is-unable-to-download-folder-null/' rel='bookmark' title='Outlook Is Unable To Download Folder (null)'>Outlook Is Unable To Download Folder (null)</a> <small>We have recently had an issue with outlook 2003 working with a new Courier IMAP Server. Connections would be made to the server and emails...</small></li></ol>]]></description> <content:encoded><![CDATA[<p>Regular readers of this blog will know that I have recently moved all my web hosting to a new provider following a devastating hack of one of my dedicated servers which was hosted with Ultrahosting. I had a bad experience with Ultrahosting support and will not be using them again in the future.</p><p><a
href="http://www.matthouldsworth.com/wp-content/uploads/2010/11/vpsville.gif" ><img
class="aligncenter size-full wp-image-2175" title="vpsville" src="http://www.matthouldsworth.com/wp-content/uploads/2010/11/vpsville.gif" alt="" width="127" height="38" /></a></p><p>I have been using VPSville for some time for my domain network and other projects and have always been impressed with their service.</p><p>I have signed up for two of their Semi dedicated vps servers which they call &#8216;Megacity&#8217; one to host my mail server and another to host my affiliate websites.</p><p>The VPSville control panel is very easy to use and fully functional, you can easily create new servers, reboot, gain SSH access, change passwords, monitor bandwidth and many other features.</p><p>They provide 25% discount on repeat custom. I currently have 10 VPS servers with them and two of the semi-dedicated servers. Discounts are also available if you may for 3, 6 or 12 months upfront.</p><p>Their prices go from £3.75 for their smallest server which they call Village with 64mb guaranteed RAM (burst to 128) 100GB Bandwidth and 5GM of disk space, up to £47.25 for their Megacity 3 Semi-Dedicated servers which 2Gb of RAM bursting to 4gb and 3000Gb Bandwidth and 160Gb of disk space.</p><p>They have Data centers in the UK, US and Canada, but appear to be a Canadian company. I have only used the London Data centre but have had no trouble with them at all.</p><p>I can not comment about support as I have had no reason to use support for anything, but if I do I will update this post with the results.</p><p>They take various forms of payment, the most critical one for me is Paypal as most of my business goes through Paypal. The only one comment I would make is that when buying a new server I can not seem to find the subscribe via Paypal option only a one off payment option, however, when you go into the existing account you can expand the payment options and create a Paypal subscription.</p><p>Another key advantage for me is that they do not have any fixed term contracts, you can pay month to month. This means that if I need a server for a project I can create one to use as a development server for £3.75 for a month and then kill it when I move the project onto my main web server.</p><p><a
rel="nofollow" href="http://www.matthouldsworth.com/goto/http://www.vpsville.ca" >Click here</a> and use the coupon code <strong>SP25</strong> to get started with <a
rel="nofollow" href="http://www.matthouldsworth.com/goto/http://www.vpsville.ca" >VPSville</a></p><div
id="_mcePaste" style="left: -10000px; overflow: hidden; width: 1px; position: absolute; top: 0px; height: 1px;">Gyprock Thermaline</div><p>Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/07/hostgator-25-off-coupon-for-digitalquill-customers/' rel='bookmark' title='Hostgator 25% Off Coupon For Digitalquill Customers'>Hostgator 25% Off Coupon For Digitalquill Customers</a> <small>We have secured a 25% off coupon code for HostGator, readers of this blog and Digitalquill customers can get this 25% discount by using the...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/outlook-is-unable-to-download-folder-null/' rel='bookmark' title='Outlook Is Unable To Download Folder (null)'>Outlook Is Unable To Download Folder (null)</a> <small>We have recently had an issue with outlook 2003 working with a new Courier IMAP Server. Connections would be made to the server and emails...</small></li></ol></p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/11/vpsville-review/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>11 Ssh Security Tips</title><link>http://www.matthouldsworth.com/2010/09/11-ssh-security-tips/</link> <comments>http://www.matthouldsworth.com/2010/09/11-ssh-security-tips/#comments</comments> <pubDate>Wed, 22 Sep 2010 18:32:19 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Linux]]></category> <category><![CDATA[Web/Mail Servers]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[hacked]]></category> <category><![CDATA[hacking]]></category> <category><![CDATA[linux]]></category> <category><![CDATA[security]]></category> <category><![CDATA[ssh]]></category> <category><![CDATA[ubuntu]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=1811</guid> <description><![CDATA[In another post following on from the recent server hacks that I have suffered. I have been researching server security. SSH security is something that I have always been fairly strong on, but I wanted to check I was doing everything possible. Here is a list of things that you should do to improve the &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/09/11-ssh-security-tips/">Continue reading &#187;</a> Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/outlook-is-unable-to-download-folder-null/' rel='bookmark' title='Outlook Is Unable To Download Folder (null)'>Outlook Is Unable To Download Folder (null)</a> <small>We have recently had an issue with outlook 2003 working with a new Courier IMAP Server. Connections would be made to the server and emails...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/disk-space-monitor-bash-script-for-linux/' rel='bookmark' title='Disk Space Monitor Bash Script For Linux'>Disk Space Monitor Bash Script For Linux</a> <small>Having setup the media storage and samba shares on the network at home, I do loose some control via windows of monitoring the space left...</small></li></ol>]]></description> <content:encoded><![CDATA[<p>In another post following on from the recent server hacks that I have suffered. I have been researching server security. SSH security is something that I have always been fairly strong on, but I wanted to check I was doing everything possible. Here is a list of things that you should do to improve the security for SSH on your server.</p><p><strong>1. Disable SSH if you do not need it<br
/> </strong></p><p>If you do not need ssh then disable it as it is always a vulnerability. If you are running a desktop/laptop with Ubuntu on it then remove ssh</p><p><code>apt-get  remove openssh-server</code></p><p><strong>2. Do not allow root login</strong></p><p>The root user is the master user on your server, it gives access to everything and permissions to do anything on your server. If that gets hacked it is the worst possible scenario for your server.</p><p>Why risk allowing people to do brute force attacks on the root user? Make sure that you stop root from being able to directly access SSH.</p><p>Edit the /etc/ssh/sshd_config file and change:</p><p><code>PermitRootLogin yes</code></p><p>to</p><p><code>PermitRootLogin no</code></p><p>Then restart ssh by running /etc/init.d/ssh restart</p><p>You will then have to SU from another user to become root or even better use the sudo command before executing root commands.</p><p><strong>3. Restrict the users who can access the server via SSH</strong></p><p>In addition to the above, you can restrict SSH access to your server to a limited number of users. In my case, I have only two users that can access the server via SSH, mine and the hosts support user.</p><p>Edit the /etc/ssh/sshd_config file and add:</p><p><code>AllowUsers username1 username2 </code></p><p>to the bottom of the file</p><p>Then restart ssh by running /etc/init.d/ssh restart</p><p><strong>4. Don&#8217;t use obvious usernames </strong></p><p>As with everything, we are trying to make things a little harder for hackers. If you use an obvious or well known username, you are open to brute force attacks on that username. So don&#8217;t use obvious users.</p><p><strong>5. Use Secure passwords</strong></p><p>Make sure that your users password is secure, use alpha numeric passwords with mixed case and try to use special characters in your password.</p><p><strong>6. Change the default ssh port</strong></p><p>On the same theme as changing the default settings, you should change the default ssh port.</p><p>Edit /etc/ssh/sshd_config</p><p>and change where it says &#8216;port 22&#8242; to a port number of your choice.</p><p>Then restart ssh by running /etc/init.d/ssh restart</p><p><strong>7. Keep OpenSSH up-to-date</strong></p><p>Make sure that you keep your whole system up-to-date especially OpenSSH</p><p>apt-get update<br
/> apt-get upgrade</p><p><strong>8. Always use ssh protocol 2</strong></p><p>Most modern versions of linux will already be configured to run with ssh protocol 2 by default but it is always worth checking</p><p>edit /etc/ssh/sshd_config</p><p>and check the protocol line says 2 and NOT 1</p><p>Protocol 2</p><p>Protocol 1 is vulnerable to man-in-the-middle attacks</p><p>Then restart ssh by running /etc/init.d/ssh restart</p><p><strong>9. Idle timeout</strong></p><p>The idle timeout terminates an ssh session after a given period of inactivity. This is especially useful to prevent vulnerabilities from unattended ssh sessions. This is not as much a hack, but an opportunist but it is worth considering depending on your situation.</p><p>edit /etc/ssh/sshd_config</p><pre>ClientAliveInterval 300
ClientAliveCountMax 0
Then restart ssh by running /etc/init.d/ssh restart<strong>
</strong></pre><p><strong>10. Use Keys</strong></p><p>A safe method of securing your SSH is by using keys. I will not go through the detailshere as they have been done before but take a look at the following tutorials:</p><p>http://www.ibm.com/developerworks/linux/library/l-keyc.html</p><p>http://www.cyberciti.biz/faq/ssh-password-less-login-with-dsa-publickey-authentication/</p><p>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/</p><p><strong>11. Stop brute force attacks</strong></p><p>Brute force attacks are where a hacker keeps trying a username with different passwords until they find one that matches. You can use software such as <a
rel="nofollow" href="http://www.matthouldsworth.com/goto/http://www.fail2ban.org/" >fail2ban</a> or <a
rel="nofollow" href="http://www.matthouldsworth.com/goto/http://www.cyberciti.biz/faq/block-ssh-attacks-with-denyhosts/" >DenyHosts</a></p><p>Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/outlook-is-unable-to-download-folder-null/' rel='bookmark' title='Outlook Is Unable To Download Folder (null)'>Outlook Is Unable To Download Folder (null)</a> <small>We have recently had an issue with outlook 2003 working with a new Courier IMAP Server. Connections would be made to the server and emails...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/disk-space-monitor-bash-script-for-linux/' rel='bookmark' title='Disk Space Monitor Bash Script For Linux'>Disk Space Monitor Bash Script For Linux</a> <small>Having setup the media storage and samba shares on the network at home, I do loose some control via windows of monitoring the space left...</small></li></ol></p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/09/11-ssh-security-tips/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Twitter Hacked</title><link>http://www.matthouldsworth.com/2010/09/twitter-hacked/</link> <comments>http://www.matthouldsworth.com/2010/09/twitter-hacked/#comments</comments> <pubDate>Tue, 21 Sep 2010 12:56:05 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Internet]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[hacked]]></category> <category><![CDATA[internet]]></category> <category><![CDATA[twitter]]></category> <category><![CDATA[website]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=1814</guid> <description><![CDATA[So its not just my site that gets hacked&#8230; Twitter are currently hacked with big blue letters across the screen and something trying to work through logged in users to send direct messages and tweets Related posts: WordPress 3.1 Release And And Digitalquill Plugin Updates Regular users of WordPress will already be aware that version &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/09/twitter-hacked/">Continue reading &#187;</a> Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/02/wordpress-3-1-release-and-and-digitalquill-plugin-updates/' rel='bookmark' title='WordPress 3.1 Release And And Digitalquill Plugin Updates'>WordPress 3.1 Release And And Digitalquill Plugin Updates</a> <small>Regular users of WordPress will already be aware that version 3.1 code named &#8216;Reinhardt&#8217; has just been released. This is the 14th release of WordPress...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/can-you-sell-a-house-via-adwords/' rel='bookmark' title='Can You Sell A House Via Adwords?'>Can You Sell A House Via Adwords?</a> <small>I have been doing quite a bit of Google Adwords work in the last few weeks for the company I work for. I will post...</small></li><li><a
href='http://www.matthouldsworth.com/2011/02/simonstone-hall-wedding-brochur/' rel='bookmark' title='Simonstone Hall Wedding Brochure'>Simonstone Hall Wedding Brochure</a> <small>Many of the regular readers will already be aware of our history with Simonstone Hall in Hawes North Yorkshire. We were engaged there in 2007,...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/smart-phones-and-the-future-of-seo-2/' rel='bookmark' title='Smart Phones And The Future Of Seo'>Smart Phones And The Future Of Seo</a> <small>I have just got myself a nice HTC Desire HD Smart phone on Orange, and although I have always had smart phones ever since the...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/elegant-themes-premium-wordpress-themes/' rel='bookmark' title='Elegant Themes &#8211; Premium WordPress Themes'>Elegant Themes &#8211; Premium WordPress Themes</a> <small>I have just started working on some wordpress sites and have discovered Elegant Themes, I know that you are going to say why buy premium...</small></li></ol>]]></description> <content:encoded><![CDATA[<p>So its not just my site that gets hacked&#8230; Twitter are currently hacked with big blue letters across the screen and something trying to work through logged in users to send direct messages and tweets</p><div
id="attachment_1816" class="wp-caption aligncenter" style="width: 260px"><a
href="http://www.matthouldsworth.com/wp-content/uploads/2010/09/Image00251.jpg" ><img
class="size-full wp-image-1816 " title="Twitter Hacked" src="http://www.matthouldsworth.com/wp-content/uploads/2010/09/Image00251.jpg" alt="Twitter Hacked" width="250" /></a><p
class="wp-caption-text">Twitter Hacked</p></div><p>Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/02/wordpress-3-1-release-and-and-digitalquill-plugin-updates/' rel='bookmark' title='WordPress 3.1 Release And And Digitalquill Plugin Updates'>WordPress 3.1 Release And And Digitalquill Plugin Updates</a> <small>Regular users of WordPress will already be aware that version 3.1 code named &#8216;Reinhardt&#8217; has just been released. This is the 14th release of WordPress...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/can-you-sell-a-house-via-adwords/' rel='bookmark' title='Can You Sell A House Via Adwords?'>Can You Sell A House Via Adwords?</a> <small>I have been doing quite a bit of Google Adwords work in the last few weeks for the company I work for. I will post...</small></li><li><a
href='http://www.matthouldsworth.com/2011/02/simonstone-hall-wedding-brochur/' rel='bookmark' title='Simonstone Hall Wedding Brochure'>Simonstone Hall Wedding Brochure</a> <small>Many of the regular readers will already be aware of our history with Simonstone Hall in Hawes North Yorkshire. We were engaged there in 2007,...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/smart-phones-and-the-future-of-seo-2/' rel='bookmark' title='Smart Phones And The Future Of Seo'>Smart Phones And The Future Of Seo</a> <small>I have just got myself a nice HTC Desire HD Smart phone on Orange, and although I have always had smart phones ever since the...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/elegant-themes-premium-wordpress-themes/' rel='bookmark' title='Elegant Themes &#8211; Premium WordPress Themes'>Elegant Themes &#8211; Premium WordPress Themes</a> <small>I have just started working on some wordpress sites and have discovered Elegant Themes, I know that you are going to say why buy premium...</small></li></ol></p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/09/twitter-hacked/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>20 Tips To Increase WordPress Security</title><link>http://www.matthouldsworth.com/2010/09/20-tips-to-increase-wordpress-security/</link> <comments>http://www.matthouldsworth.com/2010/09/20-tips-to-increase-wordpress-security/#comments</comments> <pubDate>Mon, 20 Sep 2010 17:54:35 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Amazon S3]]></category> <category><![CDATA[General]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Web/Mail Servers]]></category> <category><![CDATA[Wordpress]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[hacked]]></category> <category><![CDATA[security]]></category> <category><![CDATA[web]]></category> <category><![CDATA[web server]]></category> <category><![CDATA[website]]></category> <category><![CDATA[wordpress]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=1790</guid> <description><![CDATA[I have recently been blogging about how my web servers have been compromised. I am fairly sure that the attackers gained access to the server via WordPress. I use WordPress as the backbone to 90% of my sites, this being so it is critically important that it is secure. I have therefore been researching methods &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/09/20-tips-to-increase-wordpress-security/">Continue reading &#187;</a> Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/07/wordpress-3-2-released-i-hope-you-are-ready/' rel='bookmark' title='WordPress 3.2 Released I Hope You Are Ready!'>WordPress 3.2 Released I Hope You Are Ready!</a> <small>WordPress 3.2 has been released this morning, I hope that you are ready! As I mentioned in my review of the release candidate of WordPress...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/feather-wordpress-theme-review/' rel='bookmark' title='Feather WordPress Theme Review'>Feather WordPress Theme Review</a> <small>Elegant themes have just launched another wordpress theme &#8216;Feather&#8217;, this is great news for me as I have only been a member of Elegant themes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/mistakes-with-network-active-plugins-on-wordpress-multi-site/' rel='bookmark' title='Mistakes With Network Active Plugins On WordPress Multi-site'>Mistakes With Network Active Plugins On WordPress Multi-site</a> <small>Several days ago I was working on a network of WordPress sites I have setup, all using WordPress Multi Site, not an especially strange setup,...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/amazon-import-plugin-for-wordpress-live-demo-now-working/' rel='bookmark' title='Amazon Import Plugin For WordPress Live Demo Now Working'>Amazon Import Plugin For WordPress Live Demo Now Working</a> <small>I have just put the Live Demo of the Amazon import Plugin for WordPress Live again. I had hope to get this done yesterday, however,...</small></li></ol>]]></description> <content:encoded><![CDATA[<p>I have recently been blogging about how my web servers have been compromised. I am fairly sure that the attackers gained access to the server via WordPress.</p><p>I use WordPress as the backbone to 90% of my sites, this being so it is critically important that it is secure. I have therefore been researching methods to make those installs more secure. Here is what I have found:</p><p><strong>The Obvious:</strong></p><p><strong>1. Keep up-to-date</strong></p><p>Always use the latest version of Wordpres, there is no excuse not to, WordPress now has an inbuilt update feature which is very simple to use. Make sure that you use the latest version of WordPress, All plugins and all themes, even if those plugins or themes are not active.</p><p><strong>2. Admin User</strong></p><p>Although WordPress 3.x allows you to  choose your WordPress admin username, many people still use &#8216;admin&#8217; especially if you have upgraded from older version of WordPress and have a pre-existing user.</p><p>The problem with this is that it is known by hackers who can try and use brute force attacks on your password. If they do not know your username they have to do a brute force attack on both your username and password and get them to match and as such the likelihood of getting the correct combination is reduced</p><p>Change your admin user to something else using the SQL command:</p><p>UPDATE wp_users SET user_login = &#8216;YourChosenUser&#8217; WHERE user_login = &#8216;Admin&#8217;;</p><p><strong>3. Use a secure password</strong></p><p>I use http://strongpasswordgenerator.com/to create strong passwords. Make sure you do not use dictionary words as many brute force attacks use dictionaries to work through tries on your password.</p><p>Tips are to use numbers and letters, mixes case and some characters.</p><p><strong>4. Add Keys to the wp-config.php file</strong></p><p>WordPress 3.x does this for you, but it is worth checking that you have the keys completed in your wp-config.php file. It should look something like:</p><pre>define('AUTH_KEY',        '19[9lL.u~lwAMWEv-HwZ+@Fm{1FP+&lt;jDgcq|GMF|G@Oklq_w;ftPlsXO@|S^4');</pre><pre>define('SECURE_AUTH_KEY', 'JiSUZrIM5T!7$z;rcS];qL&gt;L L)c@,Tqe~B=#M=V,Wgb:&gt;F|h$d0g55)!_9Ol-');</pre><pre>define('LOGGED_IN_KEY',   'm~ v--9/-l+9=[$VD($&lt;o-Afz(8uxH[p4yaVnTR3Zf5mbV6PUdu3W?J|Wr8/:`e');</pre><pre>define('NONCE_KEY',       '%i.WRYyslvZ.C*Np5L5S27t4 ihJF,HMhy~$aEKV0#=/`I~$o-Mu&lt;revq/fIhb+e');</pre><pre>define('AUTH_SALT',        '[J&amp;pERV+!rfO6|n0OzNo5g7 P .cOia|{^4A$Ol4w`([o-JC3:|D3nTXDx4S9H');</pre><pre>define('SECURE_AUTH_SALT', '%P)h3cUD=EX/2z+EY@/~i;%TjlB(EL]RB]N,B)7Tr+Rw(L2:i(V+N+VS5i2Obu0I');</pre><pre>define('LOGGED_IN_SALT',   'n|yRYtIi#y5Q|-3|Y~-y]f0t|1n,aE7M@ubchoibda?RDdeCwRC|~e)-d?u*JJMc');</pre><pre>define('NONCE_SALT',       'w|1+voiV-[q5,F3,M@wOLvOJJz*&gt;&amp;3Ui9drlQ{Q&gt;Ls2|#lZVzA46?&amp;+6&amp;Vrgg1x');</pre><p><strong>The Not-So Obvious</strong></p><p><strong>5. Database setup - user, password, and database</strong></p><p>Make sure you create a database for each blog, if one is compromised you do not want it affecting any other sites you may have on your server.</p><p>Make sure you create a username for each of the installs, do not share them between wordpress installs and DO NOT USE ROOT!</p><p>The user should be a limiuted userm grant it SELECT, INSERT, UPDATE privileges.<br
/> mysql&gt; GRANT SELECT, INSERT, UPDATE ON wordpress.* TO 'wordpress'@'localhost' IDENTIFIED BY 'newpassword';<br
/> mysql&gt; FLUSH PRIVILEGES;</p><p>Make sure that your user only has local access to your database, so that it can not access your database remotely.</p><p><strong>6. Do not use default wp_ table prefixes</strong></p><p>Don't use the default wp_ prefix to table names. This method is useful but should not be relied upon for a security fix, one a hacker has got as far as being able to conduct SQL injections or other hack then this method will not prevent them getting further for very long, but it will keep them guessing. Do not use the default wp_ prefix instead use a random one.</p><p>This is rather more difficult if you are trying to secure a site that has already been setup, but you can use the <a
rel="nofollow" href="http://www.matthouldsworth.com/goto/http://wordpress.org/extend/plugins/wp-security-scan/" >WP Security Plugin</a> to do this</p><p><strong>7. SSL for wp-admin</strong></p><p>SSL connections are far more secure than normal http connections so, force SSL for admin add the line define('FORCE_SSL_ADMIN', true); to your wp-config.php file Options All -Indexes to your .htaccess file</p><p><strong>8. Allow access to your wp-admin from one IP Address</strong></p><p>Although this method worries me, due to loosing access to my files I have implemented it to see how it goes. If you have a static IP address you can Secure the wp-admin files from being edited. By default all but the wp-config.php file can be edited via the wordpress admin area.</p><p>If you add a .htaccess file to your wp-admin folder and add the following:</p><p>Order Deny,Allow<br
/> Allow from xx.xx.xx.xx<br
/> Deny from all</p><p>This will then only allow you to edit those files from the IP address specified</p><p>You can use other options in the IP address such as:</p><p>A (partial) domain-name - Example: Allow from apache.org<br
/> A full IP address - Example: Allow from 10.1.2.3<br
/> A partial IP address - Example: Allow from 10.1<br
/> A network/netmask pair - Example: Allow from 10.1.0.0/255.255.0.0<br
/> A network/nnn CIDR specification - Example: Allow from 10.1.0.0/16</p><p><strong>9. Deny access to the wp-config.php file</strong></p><p>Perhaps a safer method than the above would be to specifically deny access to your wp-config.php file, thus keeping your database username and password more secure.</p><p>Add the following line to you r.htaccess file in the root of your site</p><p>&lt;FilesMatch ^wp-config.php$&gt;deny from all&lt;/FilesMatch&gt;</p><p><strong>10. Move wp-config.php file to a directory below the one it is currently in </strong></p><p>for example if your is the is setup as such:</p><p>/var/www/domain.com/htdocs/Site files here</p><p>you can move the wp-config.php file to below the htdocs folder i.e.</p><p>/var/www/domain.com/</p><p>WordPress will handle this change automatically and allow you to have the wp-config.php file below the web root which is a great deal more secure.</p><p><strong>11. Add Apache Level security to wp-admin</strong></p><p>AuthType Basic<br
/> AuthName "Domain.com WordPress Admin"<br
/> AuthUserFile /var/www/domain.com/.auth/.htpasswd<br
/> Require user domainAdmin</p><p>htpasswd -cm /var/www/domain.com/.auth/.htpasswd domainAdmin</p><p><strong>12. Blacklist ip addresses</strong></p><p>Edit the .htaccess file in the root of your site and add the following:</p><p>&lt;Limit GET POST PUT&gt;<br
/> order allow,deny<br
/> allow from all<br
/> deny from 123.456.789<br
/> deny from 93.121.788<br
/> deny from 223.956.789<br
/> deny from 128.456.780<br
/> &lt;/LIMIT&gt;</p><p>Add the ip address of the visitor you want to ban, you can add multiple deny from xxx lines to ban multiple addresses.</p><p>This may not be as useful unless you are actively monitoring your logs, but it can be useful if you get a great deal of SPAM comments from one user.</p><p>You can also use the <a
rel="nofollow" href="http://www.matthouldsworth.com/goto/http://www.bad-neighborhood.com/login-lockdown.html" >Lockdown plugin</a> to record all failed attempts to access your wordpress admin. You can then add the IP address to the ban list.</p><p><strong>13. Stop WordPress serving anything other than images from the wp-content/uploads folder</strong></p><p>You can secure the wp-content/uploads directory to stop it serving anything other than images</p><p>Order Allow,Deny<br
/> Deny from all<br
/> &lt;filesMatch  "\.(jpeg|jpg|gif|png|js|css)$"&gt;<br
/> Allow from all<br
/> &lt;/filesMatch&gt;</p><p>Remember if you want to include other file types in your WordPress posts you will have to add them to the list for example a pdf document, you would add pdf to the 'files' line.</p><p><strong>14. Stop SQL injection attacks</strong></p><p>Although WordPress should already do this for your you can ensure that you stop SQL injection attacks. SQL injection attacks are where malicious users use forms on your site to add code to database records.</p><p>Add the following to the .htaccess file in the root of your website.</p><p>Options +FollowSymLinks<br
/> RewriteEngine On<br
/> RewriteCond %{QUERY_STRING (\&lt;|%3C).*script.*(\&gt;|%3E) [NC,OR]<br
/> RewriteCond %{QUERY_STRING GLOBALS(=|\[|\%[0-9A-Z]{0,2) [OR]<br
/> RewriteCond %{QUERY_STRING _REQUEST(=|\[|\%[0-9A-Z]{0,2)<br
/> RewriteRule ^(.*)$ index.php [F,L]</p><p><strong>15. Remove your WordPress version</strong></p><p>Sounds crazy but you should really do this. If hackers find a vulnerability in a particular build of WordPress then they will use search engines to find sites using that version and then exploit that vulnerability.</p><p>edit functions.php file of your theme and add the following line to it remove_action('wp_head', 'wp_generator');</p><p><strong>16. Stop search engines indexing any of your WP- folders</strong></p><p>add the following to your robots.txt file:</p><p>Disallow: /wp-*</p><p>This in combination with not allowing browsing of these folders will stop those files from being accessed.</p><p><strong>17. Lockdown Plugin to stop brute force attacks</strong></p><p>Using the <a
rel="nofollow" href="http://www.matthouldsworth.com/goto/http://www.bad-neighborhood.com/login-lockdown.html" >Lockdown plugin </a>to ban addresses after a certain number of failed login attempts will help prevent brute force attacks.</p><p><strong>18. Use WordPress Firewall plugin</strong></p><p>I have blogged before about the default set of plugins that I install, this is one of them, make sure you get it installed as it protects you against some of these holes especially SQL injection attacks.</p><p><strong>19 File permissions</strong></p><p>Here is a quick run down of some file permissions to check for your wordpress install are as follows:</p><p>../ 0755<br
/> ../wp-includes 0755<br
/> ../.htaccess 0644<br
/> index.php 0644<br
/> js/ 0755<br
/> ../wp-content/themes 0755<br
/> ../wp-content/plugins 0755<br
/> ../wp-admin 0755<br
/> ../wp-content 0755</p><p>On linux command line run 'chmod 0755 wp-includes -R' for example, or you can use your ftp client.</p><p>All my servers have ftp disabled as this is another potential security hole.</p><p><strong>20. Backup, Backup, Backup</strong></p><p>Ok this is not strictly a security fix, but it the worse happens it will help you to recover. Make sure you back everything up, WordPress install, uploaded files and critically the database. I use <a
rel="nofollow" href="http://www.matthouldsworth.com/goto/http://wordpress.org/extend/plugins/backwpup/" >BackWPup </a>which can up your data to Amazon S3. Very cheap method of keeping secure backups of your blog., or to FTP.</p><p>It is worth pointing out that if your site is hacked make sure you check all the files in the backup you are using before you restore. If a backup has run after the hack then any malicious files may be present in the backup.</p><p>If you are in this situation use the backup for your database and for any uploaded files and get a fresh copy of WordPress and any plugins.</p><p><strong>Note:</strong></p><p>Even with all these methods you may still be vulnerable, holes in your web server security, holes in plugins that you use or any number of factors could allow you to be compromised, but with these methods you are gaining more of the upper hand in the battle against hackers.</p><p>As a WordPress plugin developer I am looking into the possibility of creating a plugin that does some if not all of these methods for you or at least checks them and gives you advice as to how to improve the security. During this research I have found many plugins out there that claim to do this, some work better than others, indeed some do not work at all, but none are comprehensive and as such I think I will attempt to code one up that will do or check this list of 20 tips.</p><p>Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/07/wordpress-3-2-released-i-hope-you-are-ready/' rel='bookmark' title='WordPress 3.2 Released I Hope You Are Ready!'>WordPress 3.2 Released I Hope You Are Ready!</a> <small>WordPress 3.2 has been released this morning, I hope that you are ready! As I mentioned in my review of the release candidate of WordPress...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/feather-wordpress-theme-review/' rel='bookmark' title='Feather WordPress Theme Review'>Feather WordPress Theme Review</a> <small>Elegant themes have just launched another wordpress theme &#8216;Feather&#8217;, this is great news for me as I have only been a member of Elegant themes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/mistakes-with-network-active-plugins-on-wordpress-multi-site/' rel='bookmark' title='Mistakes With Network Active Plugins On WordPress Multi-site'>Mistakes With Network Active Plugins On WordPress Multi-site</a> <small>Several days ago I was working on a network of WordPress sites I have setup, all using WordPress Multi Site, not an especially strange setup,...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/amazon-import-plugin-for-wordpress-live-demo-now-working/' rel='bookmark' title='Amazon Import Plugin For WordPress Live Demo Now Working'>Amazon Import Plugin For WordPress Live Demo Now Working</a> <small>I have just put the Live Demo of the Amazon import Plugin for WordPress Live again. I had hope to get this done yesterday, however,...</small></li></ol></p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/09/20-tips-to-increase-wordpress-security/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>New Web Servers</title><link>http://www.matthouldsworth.com/2010/09/new-web-servers/</link> <comments>http://www.matthouldsworth.com/2010/09/new-web-servers/#comments</comments> <pubDate>Sun, 19 Sep 2010 12:25:06 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Linux]]></category> <category><![CDATA[Virtualisation]]></category> <category><![CDATA[Web/Mail Servers]]></category> <category><![CDATA[debian]]></category> <category><![CDATA[email]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[hacked]]></category> <category><![CDATA[mail server]]></category> <category><![CDATA[ubuntu]]></category> <category><![CDATA[web server]]></category> <category><![CDATA[websites]]></category> <category><![CDATA[wordpress]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=1781</guid> <description><![CDATA[The last two months have been a real problem for my web hosting. I have blogged here before about how I have been hacked. This last week the server has hacked again and phishing software installed. I was in the process of setting up a new server anyway but this has put the pressure on &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/09/new-web-servers/">Continue reading &#187;</a> Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/outlook-is-unable-to-download-folder-null/' rel='bookmark' title='Outlook Is Unable To Download Folder (null)'>Outlook Is Unable To Download Folder (null)</a> <small>We have recently had an issue with outlook 2003 working with a new Courier IMAP Server. Connections would be made to the server and emails...</small></li><li><a
href='http://www.matthouldsworth.com/2011/07/wordpress-3-2-released-i-hope-you-are-ready/' rel='bookmark' title='WordPress 3.2 Released I Hope You Are Ready!'>WordPress 3.2 Released I Hope You Are Ready!</a> <small>WordPress 3.2 has been released this morning, I hope that you are ready! As I mentioned in my review of the release candidate of WordPress...</small></li></ol>]]></description> <content:encoded><![CDATA[<p>The last two months have been a real problem for my web hosting. I have blogged here before about how I have been hacked. This last week the server has hacked again and phishing software installed. I was in the process of setting up a new server anyway but this has put the pressure on again.</p><p>I have setup two new servers, one dedicated to email and the other to the webserver. I have still to setup all the mailboxes and websites, but if you are seeing this post then you are viewing this blog on the new web server.</p><p>The race is on over the next couple of days to setup all the websites again and get the DNS updated to the new IP addresses for both the A and MX records.</p><p>I think Debian 4 had significant vulnerabilities, recently the repros were all archived indicating that the developers had dropped support for it. I have therefore moved to a far more up-to-date OS in Ubuntu 10.04. I have other servers and VPS servers already running Ubuntu 10.04 so there is no problem with that at all. It is just the work involved in setting everything up again.</p><p>Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/outlook-is-unable-to-download-folder-null/' rel='bookmark' title='Outlook Is Unable To Download Folder (null)'>Outlook Is Unable To Download Folder (null)</a> <small>We have recently had an issue with outlook 2003 working with a new Courier IMAP Server. Connections would be made to the server and emails...</small></li><li><a
href='http://www.matthouldsworth.com/2011/07/wordpress-3-2-released-i-hope-you-are-ready/' rel='bookmark' title='WordPress 3.2 Released I Hope You Are Ready!'>WordPress 3.2 Released I Hope You Are Ready!</a> <small>WordPress 3.2 has been released this morning, I hope that you are ready! As I mentioned in my review of the release candidate of WordPress...</small></li></ol></p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/09/new-web-servers/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Time For A New Web Server</title><link>http://www.matthouldsworth.com/2010/09/time-for-a-new-web-server/</link> <comments>http://www.matthouldsworth.com/2010/09/time-for-a-new-web-server/#comments</comments> <pubDate>Fri, 10 Sep 2010 19:54:42 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Affiliate Marketing]]></category> <category><![CDATA[Hardware]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Web/Mail Servers]]></category> <category><![CDATA[debian]]></category> <category><![CDATA[email server]]></category> <category><![CDATA[email web server]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[linux]]></category> <category><![CDATA[mx]]></category> <category><![CDATA[phishing]]></category> <category><![CDATA[spam]]></category> <category><![CDATA[ubuntu]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=1735</guid> <description><![CDATA[I run several web servers, some dedicated to clients, some dedicated to specific projects I have running, and one for the affiliate projects I run. I also have one dedicated to running my mail server. The latter two have been suffering from numerous malicious attacks. The email server was hacked a couple of months ago &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/09/time-for-a-new-web-server/">Continue reading &#187;</a> Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/06/a-time-for-a-change-self-employment-and-full-time-affiliate/' rel='bookmark' title='A Time For A Change &#8211; Self Employment And Full Time Affiliate'>A Time For A Change &#8211; Self Employment And Full Time Affiliate</a> <small>I am writing this post on Holiday in the Yorkshire Dales, we have a fantastic cottage in Carperby, with stunning views over Wensleydale. I am...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/outlook-is-unable-to-download-folder-null/' rel='bookmark' title='Outlook Is Unable To Download Folder (null)'>Outlook Is Unable To Download Folder (null)</a> <small>We have recently had an issue with outlook 2003 working with a new Courier IMAP Server. Connections would be made to the server and emails...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/home-computer-network-finally-finished/' rel='bookmark' title='Home Computer Network Finally Finished'>Home Computer Network Finally Finished</a> <small>Recently I have posted about my tribulations with setting up my perfect network at home. A quick re-cap is that we have two Windows Media...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/media-centre-and-network-storage-solution/' rel='bookmark' title='Media Centre And Network Storage Solution'>Media Centre And Network Storage Solution</a> <small>I have spent the past week moving 100&#8242;s of terabytes of data from disk to disk, trying to find the best solution for the central...</small></li></ol>]]></description> <content:encoded><![CDATA[<p>I run several web servers, some dedicated to clients, some dedicated to specific projects I have running, and one for the affiliate projects I run. I also have one dedicated to running my mail server.</p><p>The latter two have been suffering from numerous malicious attacks. The email server was hacked a couple of months ago and since then it has not been quite right, even though I have spent a great deal of time trying to fix it, emails are still getting spammed and the level of spam getting through and being delivered to mailboxes is very high. Some mailboxes seem to be affected more than others.</p><p>My Linux box running my affiliate websites was hacked yesterday, I was alerted by someone to the problem, and since then GoDaddy have contacted me saying that one of the domains registered with them has been compromised. Fortunately I already had a root SSH session open to the server, running a &#8216;who&#8217; command showed another active SSH session. It appeared they had created themselves another user on the system.</p><p>I say fortunately I had a root session open as it turned out that they had changed the root ssh password.</p><p>I am not sure how they got in but they have corrupted several of my sites and installed Phishing scripts. I have removed everything and I am in the process of repairing the damage, but I do think that it is time to start afresh with a new server for both my MX and affiliates projects servers.</p><p>The current servers are both Debian 4 and as such are now out of date in terms of their OS so I would be better off starting with a new server running the latest version of Ubuntu.</p><p>The only problem with it is I have 100&#8242;s of affiliate websites running on that server and quite a number of domains and mailboxes managed by the MX server. The time involved in this, changing DNS, setting up the domains and mailboxes will be quite considerable and at the moment I really do not have the time to dedicate to this.</p><p>Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/06/a-time-for-a-change-self-employment-and-full-time-affiliate/' rel='bookmark' title='A Time For A Change &#8211; Self Employment And Full Time Affiliate'>A Time For A Change &#8211; Self Employment And Full Time Affiliate</a> <small>I am writing this post on Holiday in the Yorkshire Dales, we have a fantastic cottage in Carperby, with stunning views over Wensleydale. I am...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/how-to-check-if-you-are-ready-for-wordpress-3-2/' rel='bookmark' title='How To Check If You Are Ready For WordPress 3.2'>How To Check If You Are Ready For WordPress 3.2</a> <small>If you have ready my previous post about a first view of WordPress 3.2, you will have noted that there are some significant requirements changes...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/outlook-is-unable-to-download-folder-null/' rel='bookmark' title='Outlook Is Unable To Download Folder (null)'>Outlook Is Unable To Download Folder (null)</a> <small>We have recently had an issue with outlook 2003 working with a new Courier IMAP Server. Connections would be made to the server and emails...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/home-computer-network-finally-finished/' rel='bookmark' title='Home Computer Network Finally Finished'>Home Computer Network Finally Finished</a> <small>Recently I have posted about my tribulations with setting up my perfect network at home. A quick re-cap is that we have two Windows Media...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/media-centre-and-network-storage-solution/' rel='bookmark' title='Media Centre And Network Storage Solution'>Media Centre And Network Storage Solution</a> <small>I have spent the past week moving 100&#8242;s of terabytes of data from disk to disk, trying to find the best solution for the central...</small></li></ol></p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/09/time-for-a-new-web-server/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Linux And Open Source Is Inherently Insecure</title><link>http://www.matthouldsworth.com/2010/06/linux-and-open-source-is-inherently-insecure/</link> <comments>http://www.matthouldsworth.com/2010/06/linux-and-open-source-is-inherently-insecure/#comments</comments> <pubDate>Mon, 07 Jun 2010 20:15:01 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Linux]]></category> <category><![CDATA[Web/Mail Servers]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[bugs]]></category> <category><![CDATA[debian]]></category> <category><![CDATA[flaws]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[hacked]]></category> <category><![CDATA[hacking]]></category> <category><![CDATA[linux]]></category> <category><![CDATA[open source]]></category> <category><![CDATA[security]]></category> <category><![CDATA[ubuntu]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=1402</guid> <description><![CDATA[The title of this blog post will be a scandal in many people’s eyes; however, I will justify what I mean later in this post. In the technical circles there are many that continually bash the big commercial software companies, Microsoft, Apple, Adobe and so on for producing software that contains bugs and security flaws &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/06/linux-and-open-source-is-inherently-insecure/">Continue reading &#187;</a> Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/05/disk-space-monitor-bash-script-for-linux/' rel='bookmark' title='Disk Space Monitor Bash Script For Linux'>Disk Space Monitor Bash Script For Linux</a> <small>Having setup the media storage and samba shares on the network at home, I do loose some control via windows of monitoring the space left...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/open-house-for-viewings-saturday-28th-may/' rel='bookmark' title='Open House For Viewings Saturday 28th May'>Open House For Viewings Saturday 28th May</a> <small>We are having an open house for viewings at our property on Belvedere road in Hessle, Saturday 28th May between 2pm and 4pm. If you...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/house-for-sale-open-day-belvedere-road-in-hessle-west-hull/' rel='bookmark' title='House For Sale Open Day Belvedere Road In Hessle West Hull'>House For Sale Open Day Belvedere Road In Hessle West Hull</a> <small>We are holding an open day at hour house that is for sale in Hessle, West Hull, East Yorkshire. If you are looking for a...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/home-computer-network-finally-finished/' rel='bookmark' title='Home Computer Network Finally Finished'>Home Computer Network Finally Finished</a> <small>Recently I have posted about my tribulations with setting up my perfect network at home. A quick re-cap is that we have two Windows Media...</small></li></ol>]]></description> <content:encoded><![CDATA[<p>The title of this blog post will be a scandal in many people’s eyes; however, I will justify what I mean later in this post.</p><p>In the technical circles there are many that continually bash the big commercial software companies, Microsoft, Apple, Adobe and so on for producing software that contains bugs and security flaws and to some extent rightly so, in an ideal world software that is released should be perfect, however, this is almost impossible to achieve.</p><p>I am recently recovering one of my servers for another hack, and as you may have gathered from the subject of this post, this server was not a Windows server but a Debian Linux software. While trawling through the logs trying to find how and where they got in, I started to think, I have four dedicated servers, two Microsoft (windows 2000 and windows 2003) and two Linux (Debian and Ubuntu 8.x), and you know what, the Linux boxes have been hacked more times than I care to count and to date the windows boxes have never been hacked, they have been subjected to a denial of service attack (DOS) but never actually hacked.</p><p>This is not due to the use of the servers either; all my servers are used for similar things, indeed the windows boxes host more websites in total than the Linux ones.</p><p>You are going to come back and tell me that with the move to Ubuntu, Debian is no longer recommended or being actively developed, and that Ubuntu 8.x is old, and you would be completely right, however, Windows 2000 is 10 years old, much older than the version of Debian I am using and is in much the same situation. One can not be expected to move hundreds of websites simply to upgrade from a distro that the open source community has chosen to drop.</p><p>As a project manager on a large software development project (circa £3 million) I know very well the problems faced by software companies in producing fault free software. The amount of times that we have released a new version of our software only to find that a change to feature Z has actually broken something in feature A that we developed 3 years ago. It is the inherent problem with large software projects, to maintain the balance between testing and actually getting to the software released.</p><p>Risk management is key, we operate a system where the company critical aspects of the software have more rigorous testing than those within the bells and whistles functions that if broken would not jeopardies the running of the company.</p><p>I therefore recognise the difficulties faced by both software companies and the open source community; however, in our little software development team we have to answer to the company board as to why we have released buggy software, fortunately for us our Managing Director understands these difficulties.</p><p><strong>Open source software has no commercial liability</strong></p><p>Open source software has no commercial liability to keep it in check, by this I mean that the large software companies such as Microsoft have a commercial standing to maintain, share holders to answer to and balance sheets to tally. If they release bad software, all that is put into jeopardy, their commercial standing is damaged and as such they will do everything in their power to ensure that their software is as faultless as possible, and when faults are found that they patch them.</p><p>Open source software has no such commercial checks to keep it in line, and the very nature of community development results in a free for all in development with no management or corporate responsibility keeping it in check. This results in software that maybe fantastically feature rich and cleaver but just does not deliver the secure and stable environment now let alone in the future when the community chooses at a whim to drop that particular distro.</p><p>As both an web master and web host security is the most important aspect of my business. Down time for servers costs money, I am therefore considering my strategic position at this time.</p><p>It is something that I have often said, open source is not free, and perhaps the cost of the windows server license is actually worth it in comparison to the cost of the down time.</p><p>Simply because it is free just does not cut it anymore, if Linux and open source are to get to the standing that they want to, if they are to take a larger proportion of the desktop market, if they are to continue to establish themselves in the web hosting and server industries they need to become rather more commercially aware and commercially structures to deliver the stable secure systems that corporations and business require.</p><p>Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/05/disk-space-monitor-bash-script-for-linux/' rel='bookmark' title='Disk Space Monitor Bash Script For Linux'>Disk Space Monitor Bash Script For Linux</a> <small>Having setup the media storage and samba shares on the network at home, I do loose some control via windows of monitoring the space left...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/open-house-for-viewings-saturday-28th-may/' rel='bookmark' title='Open House For Viewings Saturday 28th May'>Open House For Viewings Saturday 28th May</a> <small>We are having an open house for viewings at our property on Belvedere road in Hessle, Saturday 28th May between 2pm and 4pm. If you...</small></li><li><a
href='http://www.matthouldsworth.com/2011/05/house-for-sale-open-day-belvedere-road-in-hessle-west-hull/' rel='bookmark' title='House For Sale Open Day Belvedere Road In Hessle West Hull'>House For Sale Open Day Belvedere Road In Hessle West Hull</a> <small>We are holding an open day at hour house that is for sale in Hessle, West Hull, East Yorkshire. If you are looking for a...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/home-computer-network-finally-finished/' rel='bookmark' title='Home Computer Network Finally Finished'>Home Computer Network Finally Finished</a> <small>Recently I have posted about my tribulations with setting up my perfect network at home. A quick re-cap is that we have two Windows Media...</small></li></ol></p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/06/linux-and-open-source-is-inherently-insecure/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>A Return To Blogging</title><link>http://www.matthouldsworth.com/2010/01/a-return-to-blogging/</link> <comments>http://www.matthouldsworth.com/2010/01/a-return-to-blogging/#comments</comments> <pubDate>Tue, 26 Jan 2010 20:19:10 +0000</pubDate> <dc:creator>Digitalquill</dc:creator> <category><![CDATA[Affiliate Marketing]]></category> <category><![CDATA[Blogging]]></category> <category><![CDATA[General]]></category> <category><![CDATA[google]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[maried]]></category> <category><![CDATA[sql injction]]></category> <category><![CDATA[time]]></category> <category><![CDATA[Wedding]]></category> <guid
isPermaLink="false">http://www.matthouldsworth.com/?p=296</guid> <description><![CDATA[Well it has been some time since I last posted, during that time allot of water has gone under the bridge. It was back at the end of February last year that I wrote my last blog post on this site. Shameful I know, but I have been battling against Google and others for the &#8230;</p><p><a
class="more-link block-button" href="http://www.matthouldsworth.com/2010/01/a-return-to-blogging/">Continue reading &#187;</a> Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/07/google-page-rank-monitor-software/' rel='bookmark' title='Google Page Rank Monitor Software'>Google Page Rank Monitor Software</a> <small>About two years ago I wrote a script that would check the Google Page Rank of all my sites on a monthly basis and record that Page...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/problogger-secrets-for-blogging-your-way-to-a-six-figure-income-review/' rel='bookmark' title='Problogger &#8211; Secrets For Blogging Your Way To A Six Figure Income &#8211; Review'>Problogger &#8211; Secrets For Blogging Your Way To A Six Figure Income &#8211; Review</a> <small>I have both the first and second editions of this great book from Darren Rowse and Chris Garrett, Secrets for Blogging your way to a...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/post-publishing-check-list-for-bloggers/' rel='bookmark' title='Post Publishing Check List For Bloggers'>Post Publishing Check List For Bloggers</a> <small>This article was inspired by a blog post I tweeted by ProBlogger, which chimed accord with something that I have been doing for some time....</small></li><li><a
href='http://www.matthouldsworth.com/2012/01/build-my-page-rank-review/' rel='bookmark' title='Build My Page Rank Review'>Build My Page Rank Review</a> <small>I have been using Build My Page Rank for three months now, I did not want to post this review any earlier as I wanted...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/blogging-from-android-smartphone/' rel='bookmark' title='Blogging From Android Smartphone'>Blogging From Android Smartphone</a> <small>I have just download the WordPress app for android onto my HTC desire hd. It only has a very simple interface. You can&#8217;t modify permalinks...</small></li></ol>]]></description> <content:encoded><![CDATA[<p>Well it has been some time since I last posted, during that time allot of water has gone under the bridge.  It was back at the end of February last year that I wrote my last blog post on this site. Shameful I know, but I have been battling against Google and others for the length of that time.</p><p>This and my other blog Earning From Affiliates was hacked and links to spyware added to the bottom of some of my sites, I assume this was some form of SQL injection attack on a vulnerability in WordPress.</p><p>As soon as I found this problem (hours after it happened) the site was cleaned, repaired and wordpress upgraded to fix the vulnerability, however by that time Google has showing a warning about the sites. No problem, all I should need to do is use the Google Webmaster tools to contact Google and ask them to re-check the site and remove the warnings. No&#8230; not that easy at all, emails and messages to Google went without a response. Weeks turned into months and I got fed up with the mess and was about to simply bin the sites when I thoughts I would have one more try and what do you know the warnings were removed and all is now back to normal running.<br
/> It has meant that the sites have been without updates for so long that their readers have probably long gone, any ranking in Google or other search engines has been damaged if not set back to zero so I am effectively starting afresh, although I do have the advantage that both sites still have their content, which is all self written unique content.</p><p>I have been busy over the last year, I was married in August to the wonderful and beautify Cheryl, her and our Daughter Eva are my life.</p><p>I have also been working on other projects, mainly software projects relating to Affiliate marketing, which have been much more successful that I could ever have hoped.</p><p>I will post more details about those projects in the coming days, but for now I just wanted to add a note to say I was back and I will be trying to find the time to post regularly and put some effort into these sites.</p><p>Related posts:<ol><li><a
href='http://www.matthouldsworth.com/2011/07/google-page-rank-monitor-software/' rel='bookmark' title='Google Page Rank Monitor Software'>Google Page Rank Monitor Software</a> <small>About two years ago I wrote a script that would check the Google Page Rank of all my sites on a monthly basis and record that Page...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/problogger-secrets-for-blogging-your-way-to-a-six-figure-income-review/' rel='bookmark' title='Problogger &#8211; Secrets For Blogging Your Way To A Six Figure Income &#8211; Review'>Problogger &#8211; Secrets For Blogging Your Way To A Six Figure Income &#8211; Review</a> <small>I have both the first and second editions of this great book from Darren Rowse and Chris Garrett, Secrets for Blogging your way to a...</small></li><li><a
href='http://www.matthouldsworth.com/2011/06/post-publishing-check-list-for-bloggers/' rel='bookmark' title='Post Publishing Check List For Bloggers'>Post Publishing Check List For Bloggers</a> <small>This article was inspired by a blog post I tweeted by ProBlogger, which chimed accord with something that I have been doing for some time....</small></li><li><a
href='http://www.matthouldsworth.com/2012/01/build-my-page-rank-review/' rel='bookmark' title='Build My Page Rank Review'>Build My Page Rank Review</a> <small>I have been using Build My Page Rank for three months now, I did not want to post this review any earlier as I wanted...</small></li><li><a
href='http://www.matthouldsworth.com/2011/04/blogging-from-android-smartphone/' rel='bookmark' title='Blogging From Android Smartphone'>Blogging From Android Smartphone</a> <small>I have just download the WordPress app for android onto my HTC desire hd. It only has a very simple interface. You can&#8217;t modify permalinks...</small></li></ol></p>]]></content:encoded> <wfw:commentRss>http://www.matthouldsworth.com/2010/01/a-return-to-blogging/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
