Blog
TMP Directory Hardening Increasingly Ineffective
Posted by Jeff H. on April 10, 2009
Yesterday, I commented on how hardening host.conf file provides very little security. Today, I want to focus on another item often found on "server hardening" checklists: TMP directory hardening. While TMP directory hardening still has its place, I feel it has lost its effectiveness in today's threat landscape.
How to Remove Your IP from Earthlink’s Blacklist
Posted by Jeff H. on April 10, 2009
This is a second post in a series dealing with removing your IP from various email blacklists. In the first post, I covered how to remove your IP from Yahoo's blacklist. I recommend reading the first post as there is some details on there about how to proceed that are applicable to any blacklist removal process.
Host.conf Hardening Does Little for Server Security
Posted by Jeff H. on April 09, 2009
If you've ever looked at Linux "server management":http://www.rackaid.com/services/management/ companies, you often find a laundry list of "security" items that they apply to your servers. Many of these items are nothing more than standard practices while others are simply popular items gleamed from forums. Many of these "tweaks" have no real testing behind them; they are often applied with no real information as to why they are done.
Forwarded Emails May Cause Backscatter Spam Complaints
Posted by Jeff H. on April 03, 2009
Email backscatter is when your server bounces and email to an unknown user. Since the reply-to fields can be spoofed, this allows spammers to bounce emails off of your server, thus getting their spam delivered. Instead of sending these non-delivery reports (NDRs), you can set your server to reject email to unknown user. While this may sound similar, rejects send a 500 series email error to the senders server. Rejects do not send emails. As a result, the backscatter problem is stopped.
Zoho: The Future of SMB IT Services?
Posted by Jeff H. on March 19, 2009
A few weeks ago, I stumbled onto Zoho. Zoho is a SaaS provider delivering many business targeted applications. Since we provide "linux server management":http://www.rackaid.com/services/management/ services, you would think we would just fire up our own software on any number of the servers we own. However, sometimes it is quicker just to outsource a function rather than deal with setting up software.
10 Immutable Laws of Security Administration Revisited
Posted by Jeff H. on March 16, 2009
Over eight years ago, Scot Culp of Microsoft, published two white papers that get tossed around in security circles over and over. The 10 Immutable Laws of Security Administration and the 10 Immutable Laws of Security are often referenced in introductory security classes. Though these rules are dated, they are still relevant today. Just want to comment on a few of them and how we see them impacting our clients today.
SUBSCRIBE
Find Out More
-
Forgotten Password? Never Again with LastPass
Posted by Mike C 01/25/2012
-
Server Maintenance Checklist
Posted by Jeff H. 01/17/2012
-
SMART Server Management
Posted by Jeff H. 01/06/2012