@ubuntu asks us to bill you 1e-2e per month for each VPS/PCI/PCC/SD. If not,
prohibition to use the mark “Ubuntu” on our website.— Octave Klaba / Oles (@olesovhcom) 19 de junho de 2016
Category Archives: Hosting
Stack Overflow: The Architecture – 2016 Edition
So what’s changed in the last 2 years? Besides replacing some servers and network gear, not much. Here’s a top-level list of hardware that runs the sites today (noting what’s different since 2013):
-
4 Microsoft SQL Servers (new hardware for 2 of them)
-
11 IIS Web Servers (new hardware)
-
2 Redis Servers (new hardware)
-
3 Tag Engine servers (new hardware for 2 of the 3)
-
3 Elasticsearch servers (same)
-
4 HAProxy Load Balancers (added 2 to support CloudFlare)
-
2 Networks (each a Nexus 5596 Core + 2232TM Fabric Extenders, upgraded to 10Gbps everywhere)
-
2 Fortinet 800C Firewalls (replaced Cisco 5525-X ASAs)
-
2 Cisco ASR-1001 Routers (replaced Cisco 3945 Routers)
-
2 Cisco ASR-1001-x Routers (new!)
Full article http://nickcraver.com/blog/2016/02/17/stack-overflow-the-architecture-2016-edition/
Scaleway VPS
Just got a Scaleway VPS.


Over 650 terabytes of MongoDB data exposed on Internet
The popular expert and Shodan creator John Matherly found over 650 terabytes of MongoDB data exposed on the Internet by vulnerable databases.
https://blog.shodan.io/its-the-data-stupid/
https://blog.shodan.io/its-still-the-data-stupid/
http://securityaffairs.co/wordpress/42897/hacking/mongodb-vulnerable-databases.html
ERROR 502 – connect() to unix:/var/run/php5-fpm.sock failed (11: Resource temporarily unavailable) while connecting to upstream
2015/11/24 12:01:49 [error] 48055#0: *14094117 connect() to unix:/var/run/php5-fpm.sock failed (11: Resource temporarily unavailable) while connecting to upstream, client:
Once again, i’m struggling with nginx + php-fpm
sudo nano /etc/php5/fpm/pool.d/www.conf
search for
listen = /var/run/php5-fpm.sock
and replace it for
listen = 127.0.0.1:7777
On the *.conf files of sites-enabled (/etc/nginx/sites-enabled/)
replace (or comment)
fastcgi_pass unix:/var/run/php5-fpm.sock;
with
fastcgi_pass 127.0.0.1:7777;
More readings
Esoterica – acesso externo ao MySQL em alojamentos partilhados
Em ‘tuguês…
básicamente é o seguinte:
Boa tarde,
Informamos que o acesso externo ao MySQL em alojamentos partilhados Esoterica encontra-se bloqueado por questões de segurança.
A gestão da base de dados deverá ser efectuado através do phpMyAdmin disponível no painel de controlo da sua conta de alojamento.
Se necessitar de esclarecimentos adicionais não hesite em contactar-nos.
Cumprimentos,
A bunch of security tools for Ubuntu
- 2 Factor Authentication (Authy)
- UFW (Firewall)
- FSTAB (Secure Shared Memory) [Step 2]
- Disallow Root Access [Step 3]
- Protect SU [Step 4]
- SYSCTL Settings (Harden Network) [Step 5]
- IP Spoofing [Step 7]
- DenyHosts (Prevent Brute Force Attacks)
- Fail2Ban (Protect SSH)
- PSAD (Network Intrusion Detection)
- Tripwire (Server Intrusion Detection)
- RKHunter (Rootkit Guard)
- Apparmor (SELinux) [Step 17]
Ubuntu CIS Benchmark
This document provides prescriptive guidance for establishing a secure configuration posture for Ubuntu 12.04 LTS Server. To obtain the latest version of this guide, please visit http://benchmarks.cisecurity.org. If you have questions, comments, or have identified ways to improve this guide, please write us at [email protected].
https://benchmarks.cisecurity.org/tools2/ubuntu/CIS_Ubuntu_12.04_LTS_Server_Benchmark_v1.0.0.pdf
Apache CIS Benchmark
This document, CIS Apache 2.4 Benchmark, provides prescriptive guidance for establishing a secure configuration posture for Apache Web Server versions 2.4 running on Linux. This guide was tested against Apache Web Server 2.4.3 – 2.4.6 as built from source httpd-2.4.x.tar.gz from http://httpd.apache.org/ on Linux. To obtain the latest version of this guide, please visit http://benchmarks.cisecurity.org. If you have questions, comments, or have identified ways to improve this guide, please write us at [email protected].
https://benchmarks.cisecurity.org/tools2/apache/CIS_Apache_HTTP_Server_2.4_Benchmark_v1.1.0.pdf
Got it from http://askubuntu.com/questions/447144/basic-security-tools-and-packages-that-should-be-installed-on-a-public-facing-we
NGINX Plus Release 6 with Enhanced Load Balancing, High Availability, and Monitoring Features
Well!
I can’t afford a NGINX Plus yet! 🙂
I might need to have one in one year of things work out like I want!
NGINX Plus looks hot!
- A new “Least Time” load-balancing algorithm
- Full-featured TCP load balancing
- High availability and failover between NGINX Plus instances
- A new statistics dashboard and improved monitoring
- Support for SSL authentication of email traffic (IMAP, POP3, and SMTP)

New “Least Time” Load-Balancing Algorithm
Full-Featured TCP Load Balancing
High Availability
Cloudflare Force or redirect to HTTPS in Nginx
I need to redirect anyone that enters on a specific domain/subdomain to use https protocol…
This is how
server {
...
if ($http_x_forwarded_proto = "http") {
return 301 https://$server_name$request_uri;
}
...
}
Grabbed from http://serverfault.com/questions/250476/how-to-force-or-redirect-to-ssl-in-nginx
Online.net hosting – printscreens





