R-fx Networks

 Linux Software & Blog

Follow me on TwitterRSS Feeds

  • Home
  • Development
  • HowTo
  • My Blog
  • Projects
    • Advanced Policy Firewall
    • Brute Force Detection
    • Incremental rsync
    • Linux Environment Security
    • Linux Malware Detect
    • Linux Socket Monitor
    • Network Socket Inode Validation
    • Process Resource Monitor
    • System Integrity Monitor
    • System Priority
  • About Us
    • Donation Roll
    • Site Map

LMD Signatures: RSS Feed & XML

May 12th

Posted in Development

No comments

While I was making some signature updates this afternoon, It occurred to me that it might be useful if the signatures were available through an RSS feed for update tracking or should anyone want to serialize the importing of my signature data into other applications.

The signatures can be access in two data formats, the first is an RSS feed that presents the 50 most recent signatures published. The second is an XML element tree that can be queried by signature ID or for all/recent signatures. There is nothing fancy about either of these data sources, information is presented clean and More >

lmd, malware

Better Late Than Never: Linux Malware Detect 1.3

May 12th

Posted in Development

3 comments

Today I have released Linux Malware Detect (LMD) 1.3, the first public stable release of my malware detection tool. The documentation is a little thin but the details are on the project page and the README file should fill you in on anything you need to know, otherwise you can post a comment on the bottom of the project page and I will assist where possible. Input on feature ideas, bugs and malware data is always welcome, see the –help options on LMD for the checkout feature to upload malware data to rfxn.com.

In October I detailed the concepts behind the More >

linux, lmd, malware, projects

BFD 1.4: Important Security Fix

May 8th

Posted in Development

4 comments

Today I have put up a new release of BFD, version 1.4, that addresses an unsanitized variable issue that is used on the command line. This is a serious issue and should be treated as such, if you currently have BFD installed I would encourage you to update it immediately, the install.sh script in the BFD package will retain all your options and tracking data so the update process is painless.

Current Release: http://www.rfxn.com/downloads/bfd-current.tar.gz

Change Log: [Fix] properly sanitized vars passed to the command line [Fix] ignore.hosts is now updated with system addresses on each bfd run [Note] thanks to jpetersen@webhostsecurity.com for invaluable input and More >

bfd, bugs, linux, ssh

Nginx: Caching Proxy

May 6th

Posted in HowTo

7 comments

Recently I started to tackle a load problem on one of my personal sites, the issue was that of a poorly written but exceedingly MySQL heavy application and the load it would induce on the SQL server when 400-500 people were hammering the site at once. Further compounding this was Apache’s horrible ability to gracefully handle excessive requests on object heavy pages (i.e: images). This left me with a site that was almost unusable during peak hours — or worse — would crash the MySQL server and take Apache with it by frenzied F5ing from users.

I went through all the More >

apache, linux, nginx

Out with the old, In with the new!

May 6th

Posted in My Blog

1 comment

The old theme was doing my head in, so I ditched it. Keep an eye out in the coming days/weeks for new releases of APF & BFD in addition to a few more howto entries and the release of maldetect with a ATF stats landing page.

apf, atf, bfd, malware

IRSYNC & Limiting Passwordless SSH Keys

May 4th

Posted in HowTo

No comments

Anyone who has ever used SSH key-pairs to access more than a couple of servers (or hundreds in my case), will tell you they are an invaluable convenience. It is a natural progression and very common usage that SSH key-pairs are coupled with other common tasks or tools, where having a pass phrase attached to the key would be counter-intuitive to the task automation. So, what do we do despite our better judgment? We create key-pairs with absolutely no pass phrase. The implications are abundantly obvious, if the private key ever gets lost or stolen, any accounts that have the More >

backup, incremental, linux, rsync, ssh
« First...«45678»
    • Recent comments
    • Popular posts
    • Archives
    • Tags
    AIDE aoe apache apf arin atf backup bfd bogon bsd bugs centos data data recovery disclosure facebook ids incremental ips linux lmd malware network nginx prm projects r1soft raid rsync snort ssh upgrade vulnerability
    • November 2011 (1)
    • October 2011 (1)
    • April 2011 (3)
    • March 2011 (4)
    • February 2011 (1)
    • November 2010 (4)
    • September 2010 (1)
    • August 2010 (3)
    • July 2010 (4)
    • June 2010 (3)
    • May 2010 (12)
    • October 2009 (3)
    • June 2009 (1)
    • April 2009 (1)
    • March 2009 (2)
    • Upgrade CentOS 4.8 to 5.x (32bit) (39)
    • Linux Malware Detectection (11)
    • Nginx: Caching Proxy (7)
    • LMD: One Year Later (7)
    • Happy Birthday APF: 8 Years Strong (7)
    • Linux Malware Detect: 2 Years Strong (7)
    • Data Integrity: AIDE for Host Based Intrusion Detection (5)
    • ATA Over Ethernet: As an Alternative (5)
    • BFD 1.4: Important Security Fix (4)
    • Better Late Than Never: Linux Malware Detect 1.3 (3)
    • Ryan M.: LMD provides a number of facilities for ignoring false positives including an ignore_paths file...
    • John: Need Help Please - Web hosting account suspended due to false positives from seo.classes.php I...
    • Peter M Abraham: How would a rule look like that checks if a given IP address is still bound to a given interface?...
    • Peter M Abraham: On some servers where their DNS is shaky at start up, APF basically locks up the machine because...
    • Ryan M.: I apologize, rfxn.com was recently moved to a new server and is currently undergoing a backend...
    • Eyal: Thanks for this excellent product! I found a threat that wasn't detected by maldet. I tried to...
    • Christian: Hi Ryan, thanks for working hard on the script :) I'm on Debian Squeeze (64bit) and am...
    • yngens: Hi Ryan and All! Trying PRM for the first time, but already excited by the possibilities it is...
  • Donation Roll



    1/1/2012 SBZ Systems $10
    12/13/2011 Peter Abraham $150
    11/16/2011 2MHost $100
    11/10/2011 Ned Dana $100
    11/04/2011 Green Olive Tree $75
    More...
  • Downloads

     Looking for one of our tools to download?  Check out the Projects page.

     Quick Links: APF | BFD | SIM | IRSYNC | LMD

     Downloads (to date): 943862
     Downloads (month): 1565
  • RSS LMD Malware Updates

    • gzbase64.inject.unclassed.336.MD5
      Mon, 30 Jan 2012 07:02:46 UTC
    • php.ircbot.lolwut.5002.MD5
      Mon, 30 Jan 2012 07:02:44 UTC
    • php.id.albania.4099.MD5
      Mon, 30 Jan 2012 07:02:42 UTC
    • php.ircbot.lolwut.5136.MD5
      Mon, 30 Jan 2012 07:02:39 UTC
    • php.ircbot.lolwut.5180.MD5
      Mon, 30 Jan 2012 07:02:38 UTC
    • php.cmdshell.c100.2270.MD5
      Mon, 30 Jan 2012 07:02:38 UTC
    • php.clamav.shell-8.2102.MD5
      Mon, 30 Jan 2012 07:02:33 UTC
    • php.ircbot.pbot.5889.MD5
      Mon, 30 Jan 2012 07:02:29 UTC
    • php.ircbot.lolwut.4976.MD5
      Mon, 30 Jan 2012 07:02:29 UTC
    • php.ircbot.lolwut.4942.MD5
      Mon, 30 Jan 2012 07:02:28 UTC
Mystique theme by digitalnature | Powered by WordPress
RSS Feeds XHTML 1.1 Top