R-fx Networks

 Linux Software & Blog

Follow me on TwitterRSS Feeds

  • Home
  • Development
  • HowTo
  • My Blog
  • Projects
    • Advanced Policy Firewall
    • Brute Force Detection
    • Incremental rsync
    • Linux Environment Security
    • Linux Malware Detect
    • Linux Socket Monitor
    • Network Socket Inode Validation
    • Process Resource Monitor
    • System Integrity Monitor
    • System Priority
  • About Us
    • Donation Roll
    • Site Map

LMD 1.4.1: Delivering on your requests

Nov 20th

Posted in Development

2 comments

The release of LMD 1.4.1 is now live and with it comes a few new features. In this small update, I have tried to deliver on on a couple of common feature requests from users which were in-line with my development goals. That said, right to it…

The biggest change has come in the form of what has been dubbed public mode scanning. This is where non-root users can execute malware scans. For this to work, a new quarantine, session and temporary path directory tree needed to be created that users had write access under. This presented some challenges and in the More >

lmd, malware, projects

Linux Malware Detect: 2 Years Strong

Oct 6th

Posted in Development

10 comments

As cliche as it sounds, where has the time gone? Today we celebrate two years of Linux Malware Detect, open-source (web) malware detection.

The project has seen allot of change since the first release. What was initially started as an internal project to deal with a large increase in malware activity at my job, a mid-sized web hosting company, quickly grew into a larger, established, project that proved useful for the hosting community at large. I spent nearly three months collecting malware to form the base of the initial signature set, developing the program logic and engaging people in WHT & More >

lmd, malware

LMD 1.4: Little Something For Everyone!

Apr 20th

Posted in Development

2 comments

The much awaited for 1.4 release of Linux Malware Detect is here! In this release there is quite literally something for everyone, from massive performance gains to FreeBSD support and everything in between . For those who wish to dive straight into it, you can run the -d or –update-ver option to update your install to the latest build and check out the change log for full details.

I will try cover some of the highlights of this release for those with the appetite for it, here goes…

One of the more exciting changes is that Clam Anti-Virus is now supported as More >

bsd, linux, lmd, malware, projects, upgrade

ATA Over Ethernet: As an Alternative

Apr 4th

Posted in HowTo

5 comments

New technologies, new toys — Oh how I love getting my hands dirty with them. Today I am going to have a look at ATA Over Ethernet (AoE) as an alternative solution to NFS in the role of a NAS/SAN implementation. We will look at both the server side vblade setup and the client side AoE kernel module along with a practical deployment setup which includes a convenience script I developed to make vbladed slightly less of a nuisance to maintain.

First things first though, what exactly is ATA Over Ethernet? Straight off the wikipedia page, here are the important parts More >

aoe, backup, linux, network, raid

LMD 1.3.9r1: Hexdepth Bug

Apr 3rd

Posted in Development

No comments

I have put up a revision to the 1.3.9 release of LMD that fixes a hexdepth bug in which malware greater than 65Kbytes would cause an error in the internal hexstring.pl script and be considered clean on the stage2 hex scanning of malware. This would mean that unless malware had a MD5 signature for it to be caught on stage1 scan, it would not be picked up by a corresponding HEX rule in stage2 scan if its file size was greater than 65Kbyte, due to the bug.

In addition, I have made the decision in this revision to enable release update More >

bugs, lmd, malware, projects

On The Road: Network Disaster & Dual Public-Private Network

Mar 24th

Posted in My Blog

No comments

As an administrator within a mid-sized organization, you can find yourself wearing many occupational hats, which becomes only second nature after awhile. One of these many hats I wear, is that of lead network administrator, which is something I am particularly fond of… I love networking and everything about it (except maybe wiring racks and crimping ).

Today many data center networks are designed in a dual public-private network setup, which simply put is you have a private network parallel to your public network — effectively you run two cat6 copper runs to all racks and servers. The traditional concept behind More >

network
12345»...Last »
    • Recent comments
    • Popular posts
    • Archives
    • Tags
    AIDE aoe apache apf arin atf backup bfd bogon bsd bugs centos data data recovery disclosure facebook ids incremental ips linux lmd malware network nginx prm projects r1soft raid rsync snort ssh upgrade vulnerability
    • November 2011 (1)
    • October 2011 (1)
    • April 2011 (3)
    • March 2011 (4)
    • February 2011 (1)
    • November 2010 (4)
    • September 2010 (1)
    • August 2010 (3)
    • July 2010 (4)
    • June 2010 (3)
    • May 2010 (12)
    • October 2009 (3)
    • June 2009 (1)
    • April 2009 (1)
    • March 2009 (2)
    • Upgrade CentOS 4.8 to 5.x (32bit) (47)
    • Linux Malware Detectection (11)
    • Linux Malware Detect: 2 Years Strong (10)
    • Happy Birthday APF: 8 Years Strong (7)
    • Nginx: Caching Proxy (7)
    • LMD: One Year Later (7)
    • Data Integrity: AIDE for Host Based Intrusion Detection (5)
    • ATA Over Ethernet: As an Alternative (5)
    • BFD 1.4: Important Security Fix (4)
    • Better Late Than Never: Linux Malware Detect 1.3 (3)
    • Mikkie: As for the problem with Modsec 2.7, it seems this can be workaround by appending an unused Action...
    • Mikkie: Maldet has been awesome so far, and we have been using it together with Modsecurity. However,...
    • Ryan M.: maldet -c /path/to/file
    • Awais Zaib: How do i send malicious script signature to you that is not detected by maldet ?
    • Ryan M.: In the file /usr/local/maldetect/internals.conf, change the line that...
    • Glenn: I've run into a small problem like I can see many others have. When running: maldet -m...
    • james o: Thanks for an awesome malware detection solution!
    • Brandon: Hi Ryan, When running maldet in ionotify mode, it writes an empty file named "0" in the directory...
  • Donation Roll



    2/22/2013 Senol ERDOGAN $5
    2/13/2013 Steve Thompson $10
    2/12/2013 Conor Moran $50
    2/11/2013 Hennings Bitsch $30
    2/8/2013 Viewdale Holdings $50
    More...
  • RSS LMD Malware Updates

    • gzbase64.inject.unclassed.697.MD5
      Wed, 22 May 2013 18:43:19 UTC
    • php.cmdshell.mic22.4256.MD5
      Wed, 22 May 2013 18:43:19 UTC
    • gzbase64.inject.unclassed.967.MD5
      Wed, 22 May 2013 18:43:19 UTC
    • php.ircbot.pbot.7876.MD5
      Wed, 22 May 2013 18:43:18 UTC
    • php.ircbot.InsideTeam.6995.MD5
      Wed, 22 May 2013 18:43:16 UTC
    • php.exe.globals.5494.MD5
      Wed, 22 May 2013 18:43:14 UTC
    • php.dbscan.0813.5239.MD5
      Wed, 22 May 2013 18:43:13 UTC
    • php.injector.genol.6298.MD5
      Wed, 22 May 2013 18:43:13 UTC
    • php.cmdshell.mic22.4324.MD5
      Wed, 22 May 2013 18:43:13 UTC
    • php.cmdshell.mic22.4290.MD5
      Wed, 22 May 2013 18:43:11 UTC
Mystique theme by digitalnature | Powered by WordPress
RSS Feeds XHTML 1.1 Top