[137058] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: WebServer and Firewall Help

daemon@ATHENA.MIT.EDU (Curtis Maurand)
Tue Feb 8 19:15:11 2011

Date: Tue, 08 Feb 2011 19:14:32 -0500
From: Curtis Maurand <cmaurand@xyonet.com>
To: nanog@nanog.org
In-Reply-To: <D7D7F18F-21F3-4C67-A9C5-6AAB93959FDC@gmail.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

On 2/8/2011 3:00 PM, Joshua Klubi wrote:
>
>>> I want to know what measure i can do on the server to get it protected which
>>> mysql protection
>>> I should implement. since i can see that it might be a php or mysql
>>> injection that is been used.
>>>
>>> Currently I run these security measures on it.
>>> Ubuntu UFW
>>> Fail2ban
>>> PHP model security
>>> Apache security
>>>
>>> Joshua
>> the problem may not be your operating system but the web application running.  what web application/s are on that box?
>>

I agree, you've got other problems.  I would look at defending against 
sql injection attacks and I would look to making sure that all the 
passwords get changed.





home help back first fref pref prev next nref lref last post