R-fx Networks

Upgrade CentOS 4.8 to 5.3

by Ryan M. on Oct.20, 2009, under HowTo, My Blog

Traditionally, the dist upgrade path that many were familiar with from the RH8/9->Fedora or similarly Fedora dist upgrades, have applied more or less to RHEL/CentOS but with the release of 4.5 and early releases of 5.0 the actual dist upgrade path was messy or nearly impossible. The early versions of 5.0 (up to 5.2) had [...]

6 Comments :, , more...

Linux Malware Detectection

by Ryan M. on Oct.19, 2009, under Development Blog, My Blog

I have the last few weeks been working on a new project for malware detection on Linux web servers, it is already at a pre-release version in use at work and it has shown phenomenal promise.
Right to it, some background… On a daily basis the network I manage receives a large number of attacks, [...]

6 Comments :, , , more...

The Way Forward

by Ryan M. on Oct.18, 2009, under Development Blog, My Blog

It is hard to believe the year is almost done and gone already, it has been busy for me with some life drama earlier in the year then a couple of larger projects keeping me on my toes since then.
During the last few weeks I have taken the time to draft a solid road map [...]

Comments Off :, , , more...

Snorting the Web Farm

by Ryan M. on Jun.10, 2009, under My Blog

Here are some rules for you snort freaks to chew on that I have found useful in web heavy environments.
alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:”ET ATTACK RESPONSE x2300 phpshell detected”; content:”Locus7Shell”; nocase; classtype:web-application-activity; reference:url,www.rfxn.com; sid:300010; rev:1;)
alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:”ET ATTACK RESPONSE RFI Scanner detected”; content:”RFI Scanner”; classtype:web-application-activity; reference:url,www.rfxn.com; sid:300020; [...]

Comments Off :, , , , more...

BOGON Filtering, Update It

by Ryan M. on Apr.17, 2009, under Development Blog

One of the features used by APF to prevent address spoofing is that it filters reserved IP address space, also known as BOGON filtering. This is an otherwise very reliable method to keep out random unallocated spoofed addresses from injecting traffic towards your server, assuming of course the list is updated regularly.
We decided a few [...]

Comments Off :, , more...

Looking for something?

Use the form below to search the site:

Site Links

A few links to navigate our site quicker...

Archives

All entries, chronologically...