R-fx Networks

 Linux Software & Blog

RSS Feeds

  • Home
  • Development
  • HowTo
  • My Blog
  • Projects
    • Advanced Policy Firewall
    • Brute Force Detection
    • Incremental rsync
    • Linux Environment Security
    • Linux Malware Detect
    • Linux Socket Monitor
    • Network Socket Inode Validation
    • Process Resource Monitor
    • System Integrity Monitor
    • System Priority
  • About Us

IRSYNC & Limiting Passwordless SSH Keys

May 4th

Posted in HowTo

No comments

Anyone who has ever used SSH key-pairs to access more than a couple of servers (or hundreds in my case), will tell you they are an invaluable convenience. It is a natural progression and very common usage that SSH key-pairs are coupled with other common tasks or tools, where having a pass phrase attached to the key would be counter-intuitive to the task automation. So, what do we do despite our better judgment? We create key-pairs with absolutely no pass phrase. The implications are abundantly obvious, if the private key ever gets lost or stolen, any accounts that have the More >

backup, incremental, linux, rsync, ssh

(ATF) Aggregate Threat Feed

May 2nd

Posted in Development

2 comments

ATF sexyness

For my first post back into things in awhile (a long while), I thought I would introduce everyone to the sexyness that i’ve called the Aggregate Threat Feed or ATF for short. This feed is derived from threat data at work, namely our network edge IPS (a custom snort implementation, another post on that later) and aggregated firewall data from 250+ servers, mostly being brute force/invasive scan attack addresses.

There really is nothing terribly fancy about this, the data is presented in a drop list format that is updated every 15 minutes with an optional variable to adjust the amount More >

apf, atf, ips

Upgrade CentOS 4.8 to 5.3

Oct 20th

Posted in HowTo

10 comments

Traditionally, the dist upgrade path that many were familiar with from the RH8/9->Fedora or similarly Fedora dist upgrades, have applied more or less to RHEL/CentOS but with the release of 4.5 and early releases of 5.0 the actual dist upgrade path was messy or nearly impossible. The early versions of 5.0 (up to 5.2) had excessive dependency issues with versions later than 4.4 for straight dist upgrades that would often result in a box blowing up on you or forcing a messy downgrade attempt of 4.5+ to 4.4 to try get things to dist upgrade. With more recent release updates More >

centos, linux, upgrade

Linux Malware Detectection

Oct 19th

Posted in Development

8 comments

[ UPDATE: Linux Malware Detect has been released ] I have the last few weeks been working on a new project for malware detection on Linux web servers, it is already at a pre-release version in use at work and it has shown phenomenal promise.

Right to it, some background… On a daily basis the network I manage receives a large number of attacks, most of these are web based abuses against common web application vulnerabilities which inject/upload to servers an array of malware such as phishing content, defacement tools, exploits for privilege escalation and irc c&c bots. All these actions are typically More >

ips, linux, malware, snort

The Way Forward

Oct 18th

Posted in My Blog

No comments

It is hard to believe the year is almost done and gone already, it has been busy for me with some life drama earlier in the year then a couple of larger projects keeping me on my toes since then.

During the last few weeks I have taken the time to draft a solid road map for the projects and where I would like them to be by this time next year. The road map evolved in very organic fashion with me jotting down a few points here and there every day, now it is pretty long but very constructive. It More >

bugs, projects
« First...«23456»
    • Recent comments
    • Popular posts
    • Archives
    • Tags
    apache apf arin atf backup bfd bogon bsd bugs centos data recovery disclosure facebook incremental ips linux lmd malware nginx prm projects r1soft rsync snort ssh upgrade vulnerability
    • August 2010 (3)
    • July 2010 (4)
    • June 2010 (3)
    • May 2010 (12)
    • October 2009 (3)
    • June 2009 (1)
    • April 2009 (1)
    • March 2009 (2)
    • Upgrade CentOS 4.8 to 5.3 (10)
    • Linux Malware Detectection (8)
    • Nginx: Caching Proxy (3)
    • (ATF) Aggregate Threat Feed (2)
    • BFD 1.4: Important Security Fix (2)
    • The Test Of Time: 7 Years & Counting… (2)
    • The other side: who uses rfxn.com projects? (2)
    • Signature Updates: Month In Review (2)
    • Snorting the Web Farm (1)
    • Out with the old, In with the new! (1)
    • Texas brown county district clerk - County clerk - Brown county: [...] Linux Malware Detectection | R-fx Networks 19 Oct 2009. I have the last few weeks been...
    • Chris: Also, what rule file name would you use to handle usernames that have a character in them? i.e. ...
    • Chris: Peter M. Abraham: Ryan, given CMD: /usr/bin/perl mail.cgi What file name would I have...
    • Security Recommendations for every Administrator « My VPS Box: [...] at http://www.rfxn.com/projects/advanced-policy-firewall/ bfd – brute force detection...
    • Security Recommendations for every Administrator « My VPS Box: [...] tools which will be listed here is: apf – advance policy firewall at...
    • david: Can you put the proper way of updating from older versions of apf to your current version in your...
    • Jason: Hi, Great project, thanks! Quick question. In the conf the USER setting. Is this meant for a...
    • Jason: I'm also getting the same error as mp maldet(28915): {mon} no inotify process found, check...
  • Downloads

     Looking for one of our tools to download?  Check out the Projects page.

    Quick Links: APF | BFD | SIM | IRSYNC | LMD | LES

     Downloads (to date): 673203
     Downloads (month): 1925

  • RSS LMD Malware Updates

    • base64.inject.unclassed.17.MD5
      Wed, 08 Sep 2010 07:36:17 UTC
    • php.cmdshell.r3v3ng4ns.1121.MD5
      Wed, 08 Sep 2010 07:36:03 UTC
    • php.cmdshell.fx29.818.MD5
      Wed, 08 Sep 2010 07:36:01 UTC
    • php.ircbot.lolwut.1805.MD5
      Wed, 08 Sep 2010 07:35:59 UTC
    • php.ircbot.pbot.2070.MD5
      Wed, 08 Sep 2010 07:35:57 UTC
    • php.ircbot.lolwut.1822.MD5
      Wed, 08 Sep 2010 07:35:54 UTC
    • php.cmdshell.fx29.831.MD5
      Wed, 08 Sep 2010 07:35:51 UTC
    • php.ircbot.lolwut.1841.MD5
      Wed, 08 Sep 2010 07:35:39 UTC
    • php.cmdshell.mic22.1074.MD5
      Tue, 07 Sep 2010 12:02:31 UTC
    • perl.ircbot.rafflesia.585.MD5
      Tue, 07 Sep 2010 12:02:30 UTC
  • RSS BugTraq Updates

    • Vuln: Adobe Acrobat and Reader (CVE-2010-2208) Remote Code Execution Vulnerability
    • Vuln: Adobe Acrobat and Reader Flash Content Parsing Remote Buffer Overflow Vulnerability
    • Vuln: Adobe Acrobat and Reader CVE-2010-2211 Remote Memory Corruption Vulnerability
    • Vuln: Adobe Acrobat and Reader CVE-2010-2210 Remote Memory Corruption Vulnerability
    • Bugtraq: [USN-983-1] Sudo vulnerability
    • Bugtraq: Security problems in Zenphoto version 1.3
    • Bugtraq: [TEHTRI-Security Training + 0days] "Hunting Web Attackers" at HITBSecConf
    • Bugtraq: [ GLSA 201009-03 ] sudo: Privilege Escalation
    • More rss feeds from SecurityFocus
Mystique theme by digitalnature | Powered by WordPress
RSS Feeds XHTML 1.1 Top