SkyHorse.Org

ModSecurity 2.5 : a book by Magnus Mischel

December 10th, 2009 SkyHorse

ModSecurity 2.5 book cover

ModSecurity 2.5 book cover

When I received ModSecurity 2.5 by Magnus Mischel through the post I was expecting a decent, thick and technically focused book on setting up and configuring obscure areas of ModSecurity.
On reading it I was pleasantly surprised to find how practical, direct and friendly it was (it even has its own section explaining what “Regular Expressions” are), so this is not just for the expert user, but beginner sys admin too.
The book guides you through all the steps to setting up ModSecurity 2.5 in your apache server, from installation to setting up basic and advanced rules. It also takes a look at real-life examples which is a definite must read as its the hardest part for anyone starting to use the tool.
At £30.99 (£21.99 for e-book version) its a good investment for everyone thinking about or already using ModSecurity to protect apache web servers.

Language English
Paperback 280 pages [191mm x 235mm]
Release date November 2009
ISBN 1847194745
ISBN 13 978-1-847194-74-9
Author(s) Magnus Mischel
Topics and Technologies Open Source, Linux Servers
Published by Packt Publishing

DeliciousFacebookTwitterLinkedInShare/Bookmark
Tags: apache, book, hacking, mod-security, modsecurity, Security

Related posts:

  • Fixing open DNS servers
  • Major flaw on the DNS Internet architecture discovered
  • modsec.sh updated

Posted in Uncategorized | No Comments »

Major flaw on the DNS Internet architecture discovered

July 8th, 2008 SkyHorse

Conspiracy fans unite: the worlds major Internet vendors sent their engineers out for secret meetings at the microsoft campus for the past few months to tackle the biggest flaw on the internet’s architecture since it began.

The issue resides on the obiquituous DNS system responsible for directing applications to the right servers when they request a URL. Although there is yet no evidence of this flaw being exploited, it will not take long for black hat hackers to use it to direct you to their own servers when you try to open your online banking or check your emails.

All major vendors will be releasing fixes to their systems at the same time, as to minimise the chances of such rogue practicies happening, something unheard of which clearly shows the gravity of the situation.

More detail at http://securosis.com/2008/07/08/dan-kaminsky-discovers-fundamental-issue-in-dns-massive-multivendor-patch-released/
Dan’s website where you can check for the vulnerability: http://www.doxpara.com

DeliciousFacebookTwitterLinkedInShare/Bookmark
Tags: DNS, hacking, Security

Related posts:

  • Fixing open DNS servers
  • ModSecurity 2.5 : a book by Magnus Mischel
  • modsec.sh updated

Posted in Computing | No Comments »

Web Host Company hacks into their own client’s accounts

October 4th, 2006 SkyHorse

This has to be the most disgusting marketing strategy since the dawn of forehead tattoos:
Dedicated Hosting Companies » Blog Archive » Hacked by my host! Be Careful!

Who’s watching the watchers?

DeliciousFacebookTwitterLinkedInShare/Bookmark
Tags: hacking, hacking, hosting, marketing, Security

Related posts:

  • Fixing open DNS servers
  • modsec.sh updated
  • WordPress is hacked: All Upgrade to 2.1.2

Posted in hacking, hosting | No Comments »

Fixing open DNS servers

September 28th, 2006 SkyHorse

Ok, there seems to be a *lot* of posts and threads about this issue and I think a simple page is appropriate.

Lets start with the problem. Check the report for your domain here: http://www.dnsreport.com/tools/dnsreport.ch?domain=YOUR_DOMAIN_HERE.COM

An open DNS server is one that replies to a query about a domain it is not responsible for, to anyone who asks for it. For starters, that is just a waste of processing time, but it can be worse if it is used for flooding. See, since a DNS query is (much!) smaller in number of bytes than a DNS response, if it is spoofed it can be used to perform a DoS attack on a computer with several times the bandwidth of the perpretator.

I’ve posted a solution to my obscure cPanel guide, have a look if your interested:
Fixing Open DNS servers

DeliciousFacebookTwitterLinkedInShare/Bookmark
Tags: bind, DNS, GNU/Linux, hacking, hosting, Security, WHM

Related posts:

  • Major flaw on the DNS Internet architecture discovered
  • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
  • modsec.sh updated

Posted in GNU/Linux, hosting, WHM | No Comments »

  • Tags

    advertising AI apple behavioural-targeting business Computing cPanel deep packet inspection Downloads DSP Games GNU/Linux google hacking hacking Hardware headphones hosting Ideas Instant Messaging iphone marketing online-advertising online media Personal Philosophy phorm poker Programming satire scripts Security sociology startups technology Travel ubuntu v-moda Visionarism web-2.0 web-marketing Web Design WHM wunderloop yahoo
  • Pages

    • About
    • Web Server Administration
      • Auto update modsecurity rules – modsec.sh
      • DirectAdmin to cPanel : a partial BASH solution
      • The Definite Guide of Obscure Tweaks to Install and Maintain cPanel / WHM (version 10)
        • Configuring E-mail (Exim) related areas
        • Fixing open DNS servers
        • Monitoring your server
        • Scripts and misc information
        • Security by Obscurity
        • Tweaking apache web server
  • Twitter Updates

    • Ads

    • RSS ExchangeWire.com

      • Looking Beyond The Gadget Porn, What Were The Key Takeaways From This Year’s CES For Ad Tech? 27 January, 2012
      • AppNexus CEO, Brian O’Kelley, And Brian Lesser, CEO, Xaxis, Confirmed To Speak At Ad Trader Conference, Hamburg, On April 19 27 January, 2012
      • The PostView: Are Facebook And Amazon About To Disrupt The Multi-Billion Euro/Dollar Traditional Display Model? 26 January, 2012
    • RSS Lies, Damned Lies…

      • Building the Perfect Display Ad Performance Dashboard, Part II – metrics 20 December, 2011
      • Should Wikipedia accept advertising? 21 November, 2011
      • Building the Perfect Display Ad Performance Dashboard, Part I – creating a measurement framework 9 November, 2011
    • RSS iMedia Connection: Consumer Strategies

      • A consumer-driven mindset in a big media package
      • Learn to leverage the social-search connection
      • Your social media disaster kit
    • RSS Segmentacion por comportamiento

      • Chrome Users: Try the WordPress.com Extension 27 January, 2012
      • Your Stats Have a New Home 26 January, 2012
      • Reblogging is Back! 22 January, 2012
    • RSS Sandlines

      • The Social Phone doesn’t come with an IVR menu 7 November, 2011
      • Are you ready for Big Data? 2 November, 2011
      • Sandlines @ Mediapro 29 October, 2011
    • RSS Adotas

      • Sponsormob Leads the Way Into RTB for Mobile 27 January, 2012
      • Clearstream Rolls Out Verification for Online Video Ads 27 January, 2012
      • Study: How Do Marketers Define Social Media ROI? 27 January, 2012
    • RSS NMA

      • Twitter embroiled in censorship row 27 January, 2012
      • Security fears lead O2 to exceed tweet limit 27 January, 2012
      • Facebook urges clearer understanding of social commerce 26 January, 2012
    • RSS Brand Republic

      • Eurostar to appoint AMV BBDO to pan-European advertising 27 January, 2012
      • Telegraph prepares for London 2012 adspend lift with Allen appointment 27 January, 2012
      • Ireland's Out of Home sector drops 5% to total €194.6m in 2011 27 January, 2012
    • RSS MarketingVox

      • Closing Bell: FBI plans social map app | Facebook IPO | Twitter censorship 27 January, 2012
      • MovenBank Moves Industry Closer to Social Media Credit Scoring 27 January, 2012
      • Google+ May Be Wasting Its Time on the Teen Market 27 January, 2012
    • RSS Behavioural Targeting news

      • The worst Internet privacy scandals of all time - Techworld.com 29 January, 2012
      • Movers & Shakers for Jan. 29, 2012 - MetroWest Daily News 29 January, 2012
      • Changing people's behavior: From reducing bullying to training scientists - EurekAlert (press release) 27 January, 2012
      • Videology Partners with I-Behavior and Kantar Shopcom to Extend CPG Purchase ... - MarketWatch (press release) 26 January, 2012
      • Advertisers to police themselves when targeting online users - Toronto Star 25 January, 2012
    • Ads

    • Blogroll

      • 90kts
      • Acxiom Poker Nights
      • Amy’s blog
      • Bytter’s blog
      • Impare Arquitectura
      • Impare Design
      • morena flor no samba da saudade
      • Not Quite There Yet
      • Swedish Pirate Party
    • Cartoons

      • Geek & Poke
      • Order of the Stick
      • User Friendly
    • Gaming

      • Neverwinter Nights
    • online media

      • Knowledge for the Digital Economy
      • Mike on Ads
    • Personal

      • Banksy
      • Designarte
      • Made to measure shirts – Atelier de Camisa
      • My Amazon Wishlist
      • SkyServers.Org
    • Science

      • New Scientist
      • Rex Research
      • ScienceBox
      • Wired
    • Security

      • GPG4Win
      • GPGol
      • GPGShell
      • Mod Security
      • Offline Windows NT(2k,XP) Password Recovery
    • Web Design

      • PageStrength
      • SiteScore
      • UrlTrends
    • Akismet

      99,726 spam comments blocked by
      Akismet
    • Meta

      • Log in
      • Entries RSS
      • Comments RSS
      • WordPress.org

    © 2003 - 2011 Paulo Cunha | SkyHorse.Org is proudly powered by WordPress | Theme based on Bob