<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HostedFX Blog &#187; Security</title>
	<atom:link href="http://www.hostedfx.com/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hostedfx.com/blog</link>
	<description>Behind the scenes at HostedFX</description>
	<lastBuildDate>Fri, 05 Apr 2013 23:17:28 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>A New Payment Method and a Securer Client Area</title>
		<link>http://www.hostedfx.com/blog/a-new-payment-method-and-a-securer-client-area/</link>
		<comments>http://www.hostedfx.com/blog/a-new-payment-method-and-a-securer-client-area/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 18:56:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Website Updates]]></category>
		<category><![CDATA[google checkout]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://www.hostedfx.com/blog/?p=50</guid>
		<description><![CDATA[As we expand as a company, we have to think even more so about how we can make each and every visitor to our website have a better and safer experience &#8211; regardless of if they are a customer or &#8230; <a href="http://www.hostedfx.com/blog/a-new-payment-method-and-a-securer-client-area/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>As we expand as a company, we have to think even more so about how we can make each and every visitor to our website have a better and safer experience &#8211; regardless of if they are a customer or not. With this in mind, I have made two fairly significant updates to the HostedFX website.</p>
<p><strong>A new payment gateway &#8211; Google Checkout</strong><br />
<a target="_blank" href="http://checkout.google.com/" target="_blank">Google Checkout</a> is becoming quite popular lately. If you haven&#8217;t heard of it, it is quite similar to the ever-popular <a target="_blank" href="http://www.paypal.com" target="_blank">PayPal</a>. &#8220;With Google Checkout you can quickly and easily buy from stores across the web and track all your orders and shipping in one place.&#8221; So far, we have found the fee&#8217;s on transactions to be slightly lower than PayPal&#8217;s and the whole interface is extremely pleasing on the eye and pleasant to use.</p>
<p><img class="size-medium wp-image-51 alignright" title="Google Checkout" src="http://www.hostedfx.com/blog/wp-content/uploads/2008/08/picture-1.jpg" alt="Google Checkout" width="210" height="107" /></p>
<p>For this reason, HostedFX now accepts Google Checkout as a payment method for all new orders and invoices for existing customers. Simply select Google Checkout from the drop-down box when paying an invoice. The only downside that I&#8217;ve found of Google Checkout is that there is no option for subscriptions; so for those of you who prefer to use a subscription, Google Checkout probably isn&#8217;t for you just yet.</p>
<p><strong>The client area is now even more secure</strong><br />
We&#8217;ve decided to go ahead and add SSL encryption to all of our transactions and activity within the <a target="_blank" href="https://clients.hostedfx.com">client area</a> (notice the new URL). For those of you who are not aware of what this means; &#8220;<em>An SSL Certificate refers to the digital certificate used with the most popular security protocol on the Internet. When you make a purchase on the Web and notice the closed lock icon at the top or bottom of your browser or the HTTPS:// prefix in the URL, it means you have established a secure SSL connection.</em>&#8221;</p>
<p>Two simple updates, which have meant more flexibility along with a greater sense of security for all of our clients. As always, if you have any suggestions just <a target="_blank" href="https://clients.hostedfx.com/contact.php" target="_blank">let us know</a>.</p>
<p>Thank you,</p>
<p>Gareth Hodson</p>
<p>HostedFX Web Hosting CEO.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hostedfx.com/blog/a-new-payment-method-and-a-securer-client-area/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>The Clients Area Has Moved&#8230;(Kind Of)</title>
		<link>http://www.hostedfx.com/blog/the-clients-area-has-movedkind-of/</link>
		<comments>http://www.hostedfx.com/blog/the-clients-area-has-movedkind-of/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 16:43:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Website Updates]]></category>
		<category><![CDATA[google checkout]]></category>
		<category><![CDATA[payment]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://www.hostedfx.com/blog/?p=48</guid>
		<description><![CDATA[Very quick update for you guys, The clients/order/support area for HostedFX has always been located at hostedfx.com/clients/ &#8211; but now I have decided to move it onto the domain of clients.hostedfx.com. This is predominantly for two main reasons; 1. Having &#8230; <a href="http://www.hostedfx.com/blog/the-clients-area-has-movedkind-of/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Very quick update for you guys,</p>
<p>The clients/order/support area for HostedFX has always been located at hostedfx.com/clients/ &#8211; but now I have decided to move it onto the domain of <a target="_blank" title="HostedFX Client Area" href="http://clients.hostedfx.com" target="_blank">clients.hostedfx.com</a>.</p>
<p>This is predominantly for two main reasons;</p>
<p>1. Having the area on a subdomain means we will be adding an SSL certificate to the clients area to make logging in/ordering even more secure.</p>
<p>2. We will soon (hopefully this week!) be offering <a target="_blank" title="Google Checkout" href="http://checkout.google.com" target="_blank">Google Checkout</a> as a payment method, so you will be able to choose between Google Checkout and PayPal in order to pay invoices. Additionally, Google Checkout happens to require an SSL certificate in order to use it&#8230;(see point 1).</p>
<p>Two simply reasons to further improve the whole HostedFX experience. Please let me know your thoughts on this, especially with regards to the new payment method of Google Checkout.</p>
<p>Thanks all,<br />
Gareth</p>
<p>P.S you may still access the client area via hostedfx.com/clients, but in order to use it more securely from next week I strongly recommend using the subdomain of <a target="_blank" title="HostedFX Client Area" href="http://clients.hostedfx.com" target="_blank">clients.hostedfx.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hostedfx.com/blog/the-clients-area-has-movedkind-of/feed/</wfw:commentRss>
		<slash:comments>128</slash:comments>
		</item>
		<item>
		<title>General Security/Performance Upgrades</title>
		<link>http://www.hostedfx.com/blog/general-securityperformance-upgrades/</link>
		<comments>http://www.hostedfx.com/blog/general-securityperformance-upgrades/#comments</comments>
		<pubDate>Tue, 24 Jul 2007 22:32:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Upgrades]]></category>

		<guid isPermaLink="false">http://www.hostedfx.com/blog/?p=30</guid>
		<description><![CDATA[Over the past 24 hours we have added some extra safety precautions to our server in order to secure the protection and integrity of all our clients and their websites. In addition, we have made a few tweaks to ensure &#8230; <a href="http://www.hostedfx.com/blog/general-securityperformance-upgrades/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Over the past 24 hours we have added some extra safety precautions to our server in order to secure the protection and integrity of all our clients and their websites. In addition, we have made a few tweaks to ensure the performance of our server is as high as possible. The measures taken are as follows.</p>
<p>- CHKRootKit &#8211; a simple program that detects and hacker software and notifies us if any has been detected via email.<br />
- RootKit Hunter &#8211; scanning tool to ensure our system does not have any backdoors or exploits.<br />
- Securing and Upgrading of SSH Server &#8211; increases security during ssh connections failures and automatically blocks the attackers ip in the firewall.<br />
- System Integrity Monitor &#8211; 24&#215;7 Internal Monitor that checks all services and restarts them if they are down.<br />
- SPRI &#8211; changes the priority of different processes in accordance to level of importance, hence increasing server performance.<br />
- Secure and Optimize Apache (HTTP)- tweaks apache to perform better, and prevent unnecessary information from being easily seen. Also installed mod_security to restrict web attacks.<br />
- MySQL optimization &#8211; increases performance of MySQL.<br />
- host.conf hardenening &#8211; prevent dns lookup poisoning &amp; spoofing protection.<br />
- nsswitch.conf modification &#8211; secure and optimize DNS lookups.<br />
- sysctl.conf hardening &#8211; helps prevent TCP/IP stack from syn-flood attacks and other network abuses.<br />
- Shell Fork Bomb/Memory Hog Protection &#8211; prevents a user logged into a shell from consuming all the resources on the server.<br />
- TMP Directory hardening ( /tmp, /var/tmp, /dev/shm) &#8211; helps prevents execution of malicious scripts.</p>
<p>As always, HostedFX is always striving to provide the best service possible for<strong> you</strong>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hostedfx.com/blog/general-securityperformance-upgrades/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>[Warning] TopSites</title>
		<link>http://www.hostedfx.com/blog/warning-topsites/</link>
		<comments>http://www.hostedfx.com/blog/warning-topsites/#comments</comments>
		<pubDate>Tue, 12 Jun 2007 22:29:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.hostedfx.com/blog/?p=28</guid>
		<description><![CDATA[In the past week there have been issues on several servers which point back to TopSites installations. TopSites is a popular site ranking script which you may be familiar with. The problem we see is that many different IPs (most &#8230; <a href="http://www.hostedfx.com/blog/warning-topsites/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>In the past week there have been issues on several servers which point back to TopSites installations. TopSites is a popular site ranking script which you may be familiar with.</p>
<p>The problem we see is that many different IPs (most are hijacked PCs located in Turkey, used as bot networks) are hammering these TopSites directories, acting as mini DoS attacks against those servers. The last security advisory for TopSites was last year, but apparently it remains unpatched. This does not give us much faith in the developers &#8211; it could have been fixed a long time ago, then we would not be dealing with this problem now.</p>
<p>The bottomline is that we are forced to disable the affected directories as we find them. <strong>We do recommend replacing this script with a similar one. We are likely disabling TopSites in all Fantastico panels.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hostedfx.com/blog/warning-topsites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recent DOS Attacks</title>
		<link>http://www.hostedfx.com/blog/recent-dos-attacks/</link>
		<comments>http://www.hostedfx.com/blog/recent-dos-attacks/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 22:14:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Issues]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.hostedfx.com/blog/?p=21</guid>
		<description><![CDATA[Unfortunately we have been having some downtime issues over the last 24 hours due to several DOS attacks. Be assured that we are working on stopping and preventing this from happening in the future. We have been constantly monitoring the &#8230; <a href="http://www.hostedfx.com/blog/recent-dos-attacks/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Unfortunately we have been having some downtime issues over the last 24 hours due to several DOS attacks. Be assured that we are working on stopping and preventing this from happening in the future.</p>
<p>We have been constantly monitoring the apache status of the server and could find that there is contact attack and heavy apache access from many IPs. The main problem is that the access IPs keep on changing. Due to this, we are now configuring our Brute Force Detection software in order to prevent any further attacks. Furthermore we have enabled Mod_Dosevasive in order to prevent this.</p>
<p>We thank you for your patience during this time, be assured that we at HostedFX are determined to deliver the best service to our customers at all times. We will always do everything within our power to ensure maximum performance and reliability.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hostedfx.com/blog/recent-dos-attacks/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>[Security] Google CodeSearch &amp; Zip Files</title>
		<link>http://www.hostedfx.com/blog/security-google-codesearch-zip-files/</link>
		<comments>http://www.hostedfx.com/blog/security-google-codesearch-zip-files/#comments</comments>
		<pubDate>Sat, 27 Jan 2007 21:16:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.hostedfx.com/blog/?p=15</guid>
		<description><![CDATA[Hello all, Google&#8217;s new &#8216;Code Search&#8216; system has been finding a number of zip files uploaded on various customers&#8217; sites and publishing the script contents, including sensitive data. Please, do not leave your zip/tar.gz files or site backups in a &#8230; <a href="http://www.hostedfx.com/blog/security-google-codesearch-zip-files/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Hello all,</p>
<p>Google&#8217;s new &#8216;<a target="_blank" href="http://www.google.com/codesearch" target="_blank">Code Search</a>&#8216; system has been finding a number of zip files uploaded on various customers&#8217; sites and publishing the script contents, including sensitive data.</p>
<p><strong>Please, do not leave your zip/tar.gz files or site backups in a web-accessible location!</p>
<p>Place them in password protected directories only.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hostedfx.com/blog/security-google-codesearch-zip-files/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
