R-fx Networks

 Linux Software & Blog

RSS Feeds

  • Home
  • Development
  • HowTo
  • My Blog
  • Projects
    • Advanced Policy Firewall
    • Brute Force Detection
    • Incremental rsync
    • Linux Environment Security
    • Linux Malware Detect
    • Linux Socket Monitor
    • Network Socket Inode Validation
    • Process Resource Monitor
    • System Integrity Monitor
    • System Priority
  • About Us

Snorting the Web Farm

Jun 10th

Posted in Development

1 comment

Here are some rules for you snort freaks to chew on that I have found useful in web heavy environments.

alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET ATTACK RESPONSE x2300 phpshell detected"; content:"Locus7Shell"; nocase; classtype:web-application-activity; reference:url,www.rfxn.com; sid:300010; rev:1;)
alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET ATTACK RESPONSE RFI Scanner detected"; content:"RFI Scanner"; classtype:web-application-activity; reference:url,www.rfxn.com; sid:300020; rev:2;)
alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET ATTACK RESPONSE lila.jpg phpshell detected"; content:"CMD PHP"; classtype:web-application-activity; reference:url,www.rfxn.com; sid:300030; rev:2;)
alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET ATTACK RESPONSE ALBANIA id.php detected"; content:"UNITED ALBANIANS aka ALBOSS PARADISE"; classtype:web-application-activity; reference:url,www.rfxn.com; sid:300040; rev:2;)

alert tcp More >
ips, snort

BOGON Filtering, Update It

Apr 17th

Posted in Development

One of the features used by APF to prevent address spoofing is that it filters reserved IP address space, also known as BOGON filtering. This is an otherwise very reliable method to keep out random unallocated spoofed addresses from injecting traffic towards your server, assuming of course the list is updated regularly.

We decided a few months ago that we would disable by default all remote features in APF, including the auto updating of the reserved networks file (BOGON filter list), however this was done with one ill-fated consequence… That if you do not turn on the update feature yourself you More >

apf, arin, bogon

“oops” Wrong Server!

Mar 31st

Posted in My Blog

No comments

So this past weekend, I did the unthinkable, I accidentally recycled the wrong dedicated server at work. Usually, this is not much of an issue  (not that I make a habit of it) with the continuous data protection we have implemented at the data center (cdp r1soft) except that the backup server this particular client system was using had suffered a catastrophic raid failure the very night before. We have had raid arrays go bust on us before, typically very rare but it does happen… Obviously this resulted in the clients site and databases getting absolutely toasted and having only More >

backup, data recovery, linux, r1soft

New Site, At Last!

Mar 1st

Posted in My Blog

It has been on my plate for a long time now to redo the R-fx Networks site, although this process began some years ago with a few incarnations of new sites developing behind the scenes, none ever made it into production. In the end I drew the conclusion that sometimes simpler is better, so here we have it – the new R-fx Networks site – devoted to the projects and my personal work as a whole.

Where I want to go with this new site is explained a bit in the about us section, so head on over there if you have More >

projects
« First...«23456
    • Recent comments
    • Popular posts
    • Archives
    • Tags
    apache apf arin atf backup bfd bogon bsd bugs centos data recovery disclosure facebook incremental ips linux lmd malware nginx prm projects r1soft rsync snort ssh upgrade vulnerability
    • August 2010 (3)
    • July 2010 (4)
    • June 2010 (3)
    • May 2010 (12)
    • October 2009 (3)
    • June 2009 (1)
    • April 2009 (1)
    • March 2009 (2)
    • Upgrade CentOS 4.8 to 5.3 (10)
    • Linux Malware Detectection (8)
    • Nginx: Caching Proxy (3)
    • (ATF) Aggregate Threat Feed (2)
    • BFD 1.4: Important Security Fix (2)
    • The Test Of Time: 7 Years & Counting… (2)
    • The other side: who uses rfxn.com projects? (2)
    • Signature Updates: Month In Review (2)
    • Snorting the Web Farm (1)
    • Out with the old, In with the new! (1)
    • Texas brown county district clerk - County clerk - Brown county: [...] Linux Malware Detectection | R-fx Networks 19 Oct 2009. I have the last few weeks been...
    • Chris: Also, what rule file name would you use to handle usernames that have a character in them? i.e. ...
    • Chris: Peter M. Abraham: Ryan, given CMD: /usr/bin/perl mail.cgi What file name would I have...
    • Security Recommendations for every Administrator « My VPS Box: [...] at http://www.rfxn.com/projects/advanced-policy-firewall/ bfd – brute force detection...
    • Security Recommendations for every Administrator « My VPS Box: [...] tools which will be listed here is: apf – advance policy firewall at...
    • david: Can you put the proper way of updating from older versions of apf to your current version in your...
    • Jason: Hi, Great project, thanks! Quick question. In the conf the USER setting. Is this meant for a...
    • Jason: I'm also getting the same error as mp maldet(28915): {mon} no inotify process found, check...
  • Downloads

     Looking for one of our tools to download?  Check out the Projects page.

    Quick Links: APF | BFD | SIM | IRSYNC | LMD | LES

     Downloads (to date): 673209
     Downloads (month): 1931

  • RSS LMD Malware Updates

    • base64.inject.unclassed.17.MD5
      Wed, 08 Sep 2010 07:36:17 UTC
    • php.cmdshell.r3v3ng4ns.1121.MD5
      Wed, 08 Sep 2010 07:36:03 UTC
    • php.cmdshell.fx29.818.MD5
      Wed, 08 Sep 2010 07:36:01 UTC
    • php.ircbot.lolwut.1805.MD5
      Wed, 08 Sep 2010 07:35:59 UTC
    • php.ircbot.pbot.2070.MD5
      Wed, 08 Sep 2010 07:35:57 UTC
    • php.ircbot.lolwut.1822.MD5
      Wed, 08 Sep 2010 07:35:54 UTC
    • php.cmdshell.fx29.831.MD5
      Wed, 08 Sep 2010 07:35:51 UTC
    • php.ircbot.lolwut.1841.MD5
      Wed, 08 Sep 2010 07:35:39 UTC
    • php.cmdshell.mic22.1074.MD5
      Tue, 07 Sep 2010 12:02:31 UTC
    • perl.ircbot.rafflesia.585.MD5
      Tue, 07 Sep 2010 12:02:30 UTC
  • RSS BugTraq Updates

    • Vuln: Adobe Acrobat and Reader (CVE-2010-2208) Remote Code Execution Vulnerability
    • Vuln: Adobe Acrobat and Reader Flash Content Parsing Remote Buffer Overflow Vulnerability
    • Vuln: Adobe Acrobat and Reader CVE-2010-2211 Remote Memory Corruption Vulnerability
    • Vuln: Adobe Acrobat and Reader CVE-2010-2210 Remote Memory Corruption Vulnerability
    • Bugtraq: [USN-983-1] Sudo vulnerability
    • Bugtraq: Security problems in Zenphoto version 1.3
    • Bugtraq: [TEHTRI-Security Training + 0days] "Hunting Web Attackers" at HITBSecConf
    • Bugtraq: [ GLSA 201009-03 ] sudo: Privilege Escalation
    • More rss feeds from SecurityFocus
Mystique theme by digitalnature | Powered by WordPress
RSS Feeds XHTML 1.1 Top