R-fx Networks

 Linux Software & Blog

RSS Feeds

  • Home
  • Development
  • HowTo
  • My Blog
  • Projects
    • Advanced Policy Firewall
    • Brute Force Detection
    • Incremental rsync
    • Linux Environment Security
    • Linux Malware Detect
    • Linux Socket Monitor
    • Network Socket Inode Validation
    • Process Resource Monitor
    • System Integrity Monitor
    • System Priority
  • About Us

LMD Signatures: RSS Feed & XML

May 12th

Posted in Development

No comments

While I was making some signature updates this afternoon, It occurred to me that it might be useful if the signatures were available through an RSS feed for update tracking or should anyone want to serialize the importing of my signature data into other applications.

The signatures can be access in two data formats, the first is an RSS feed that presents the 50 most recent signatures published. The second is an XML element tree that can be queried by signature ID or for all/recent signatures. There is nothing fancy about either of these data sources, information is presented clean and More >

lmd, malware

Better Late Than Never: Linux Malware Detect 1.3

May 12th

Posted in Development

1 comment

Today I have released Linux Malware Detect (LMD) 1.3, the first public stable release of my malware detection tool. The documentation is a little thin but the details are on the project page and the README file should fill you in on anything you need to know, otherwise you can post a comment on the bottom of the project page and I will assist where possible. Input on feature ideas, bugs and malware data is always welcome, see the –help options on LMD for the checkout feature to upload malware data to rfxn.com.

In October I detailed the concepts behind the More >

linux, lmd, malware, projects

BFD 1.4: Important Security Fix

May 8th

Posted in Development

2 comments

Today I have put up a new release of BFD, version 1.4, that addresses an unsanitized variable issue that is used on the command line. This is a serious issue and should be treated as such, if you currently have BFD installed I would encourage you to update it immediately, the install.sh script in the BFD package will retain all your options and tracking data so the update process is painless.

Current Release: http://www.rfxn.com/downloads/bfd-current.tar.gz

Change Log: [Fix] properly sanitized vars passed to the command line [Fix] ignore.hosts is now updated with system addresses on each bfd run [Note] thanks to jpetersen@webhostsecurity.com for invaluable input and More >

bfd, bugs, linux, ssh

Nginx: Caching Proxy

May 6th

Posted in HowTo

3 comments

Recently I started to tackle a load problem on one of my personal sites, the issue was that of a poorly written but exceedingly MySQL heavy application and the load it would induce on the SQL server when 400-500 people were hammering the site at once. Further compounding this was Apache’s horrible ability to gracefully handle excessive requests on object heavy pages (i.e: images). This left me with a site that was almost unusable during peak hours — or worse — would crash the MySQL server and take Apache with it by frenzied F5ing from users.

I went through all the More >

apache, linux, nginx

Out with the old, In with the new!

May 6th

Posted in My Blog

1 comment

The old theme was doing my head in, so I ditched it. Keep an eye out in the coming days/weeks for new releases of APF & BFD in addition to a few more howto entries and the release of maldetect with a ATF stats landing page.

apf, atf, bfd, malware
« First...«23456»
    • Recent comments
    • Popular posts
    • Archives
    • Tags
    apache apf arin atf backup bfd bogon bsd bugs centos data recovery disclosure facebook incremental ips linux lmd malware nginx prm projects r1soft rsync snort ssh upgrade vulnerability
    • August 2010 (3)
    • July 2010 (4)
    • June 2010 (3)
    • May 2010 (12)
    • October 2009 (3)
    • June 2009 (1)
    • April 2009 (1)
    • March 2009 (2)
    • Upgrade CentOS 4.8 to 5.3 (10)
    • Linux Malware Detectection (8)
    • Nginx: Caching Proxy (3)
    • (ATF) Aggregate Threat Feed (2)
    • BFD 1.4: Important Security Fix (2)
    • The Test Of Time: 7 Years & Counting… (2)
    • The other side: who uses rfxn.com projects? (2)
    • Signature Updates: Month In Review (2)
    • Snorting the Web Farm (1)
    • Out with the old, In with the new! (1)
    • Texas brown county district clerk - County clerk - Brown county: [...] Linux Malware Detectection | R-fx Networks 19 Oct 2009. I have the last few weeks been...
    • Chris: Also, what rule file name would you use to handle usernames that have a character in them? i.e. ...
    • Chris: Peter M. Abraham: Ryan, given CMD: /usr/bin/perl mail.cgi What file name would I have...
    • Security Recommendations for every Administrator « My VPS Box: [...] at http://www.rfxn.com/projects/advanced-policy-firewall/ bfd – brute force detection...
    • Security Recommendations for every Administrator « My VPS Box: [...] tools which will be listed here is: apf – advance policy firewall at...
    • david: Can you put the proper way of updating from older versions of apf to your current version in your...
    • Jason: Hi, Great project, thanks! Quick question. In the conf the USER setting. Is this meant for a...
    • Jason: I'm also getting the same error as mp maldet(28915): {mon} no inotify process found, check...
  • Downloads

     Looking for one of our tools to download?  Check out the Projects page.

    Quick Links: APF | BFD | SIM | IRSYNC | LMD | LES

     Downloads (to date): 673209
     Downloads (month): 1931

  • RSS LMD Malware Updates

    • base64.inject.unclassed.17.MD5
      Wed, 08 Sep 2010 07:36:17 UTC
    • php.cmdshell.r3v3ng4ns.1121.MD5
      Wed, 08 Sep 2010 07:36:03 UTC
    • php.cmdshell.fx29.818.MD5
      Wed, 08 Sep 2010 07:36:01 UTC
    • php.ircbot.lolwut.1805.MD5
      Wed, 08 Sep 2010 07:35:59 UTC
    • php.ircbot.pbot.2070.MD5
      Wed, 08 Sep 2010 07:35:57 UTC
    • php.ircbot.lolwut.1822.MD5
      Wed, 08 Sep 2010 07:35:54 UTC
    • php.cmdshell.fx29.831.MD5
      Wed, 08 Sep 2010 07:35:51 UTC
    • php.ircbot.lolwut.1841.MD5
      Wed, 08 Sep 2010 07:35:39 UTC
    • php.cmdshell.mic22.1074.MD5
      Tue, 07 Sep 2010 12:02:31 UTC
    • perl.ircbot.rafflesia.585.MD5
      Tue, 07 Sep 2010 12:02:30 UTC
  • RSS BugTraq Updates

    • Vuln: Adobe Acrobat and Reader (CVE-2010-2208) Remote Code Execution Vulnerability
    • Vuln: Adobe Acrobat and Reader Flash Content Parsing Remote Buffer Overflow Vulnerability
    • Vuln: Adobe Acrobat and Reader CVE-2010-2211 Remote Memory Corruption Vulnerability
    • Vuln: Adobe Acrobat and Reader CVE-2010-2210 Remote Memory Corruption Vulnerability
    • Bugtraq: [USN-983-1] Sudo vulnerability
    • Bugtraq: Security problems in Zenphoto version 1.3
    • Bugtraq: [TEHTRI-Security Training + 0days] "Hunting Web Attackers" at HITBSecConf
    • Bugtraq: [ GLSA 201009-03 ] sudo: Privilege Escalation
    • More rss feeds from SecurityFocus
Mystique theme by digitalnature | Powered by WordPress
RSS Feeds XHTML 1.1 Top