0 day exploits

Zero day exploits, best explained here, will be coming out daily for the month of January, it seems, due to a security research firm in Russia. No matter what you think about their methods, this does highlight a fact that is sometimes forgotten, every running service presents the potential for an exploit. But without those services a computer is just an overpriced electric heater. So how do we protect ourselves against the unknown and unpatched? By being very careful about what our servers are running, only allowing access to the minimum number of resources required to get the job done, and having a plan for when your monitoring reports the service is down.

     Since linux distributions are varied in their installs I won’t go through each but most of the “friendly” distributions start, by default, a variety of services that may not be required but could potentially have exploits. While most of these don’t have a network component, combined with other exploits they could help open the server to attack. For example, Red Hat starts processes to monitor the software raid and logical volume manager even if you aren’t using them. It also starts processes for handling bluetooth devices, HP printers, and command line mouse support, even if you don’t have them. None of these should cause you any concern but if you don’t need them they don’t need to run at all.

     Most Apache HTTP server installs suffer from the same desire for usability, many modules are made available to the server by default. For example, you probably aren’t using LDAP authentication or WebDAV as part of your server but the modules for them are preloaded on most default installs. Identifying the modules that are required for your web site or application to run and then disabling the ones that are not will reduce your apache httpd footprint and therefore reduce your exposure.

     MySQL server doesn’t have the modular nature of our prior two examples but there are some steps that you can take to reduce your exposure. First off, after doing the install and setting the root password, remove the test user and database. These have no known exploits but aren’t needed. Second, ensure that your users are bound to a host instead of a wild card address, this makes sure that connections are only authorized from known hosts. Finally, if you are running mysql on the same host as your webserver and this is the only server that needs to access it, configure it to only listen on localhost ( There is no place like 127.0.0.1 ), this ensures that remote hosts cannot connect to your database even if your firewall fails.

     While I did focus on some of the more simple things that can be done to a LAMP server, this should give you an idea of what kind of changes can be made that won’t effect your service but will reduce your exposure footprint. Remember that before you make any changes you should do a backup and make copies of the files you are editing. We will see what this month brings as far as unpublished exploits and should also take this time to remember that not all exploits are published or patched, or even discovered yet.

Reblog this post [with Zemanta]
  1. Hey there I think your website might be having browser compatibility issues When I look at your blog site in Chrome it looks fine but when opening in

  2. After examine just a few of the blog posts in your website now and I actually like your means of blogging I bookmarked it to my bookmark web site listing and can be checking again soon Pls check out my web page as well and let me know what you think

  3. I am typically to blogging and i really admire your content. The article has actually peaks my interest. I’m going to bookmark your website and hold checking for brand spanking new information.

  4. My partner as one example Your site as regards to Bob’s Ideas 24 hours Several all about the ‘Que Make your way Perfect what expected!.

  5. Hi there Im at work surfing around your blog from my new iphone 4 Just wanted to say I love reading through your blog and look forward to all your posts Keep up the superb work

  6. Happy Birthday to our dear maknae Seohyun (20 2in Korean age) Stay healthy strong and bless babygirl and remember global sones are always with you anywhere you go God bless Saranghaeyo

  7. I do agree with all of the ideas you have presented in your post Theyre very convincing and will certainly work Still the posts are very short for novices Could you please extend them a little from next time Thanks for the post

  8. Agreed it`s just Brady haters If the Pat`s had never won a Superbowl you wouldn`t have as many Brady haters plain and simple Take it from me after the 2004-2005 Superbowl I hated Brady too But then I realized he was and is one of the greats of all time and I was just mad that he beat my team lol The guy emulated Joe Montana – is there anything more that needs to be said

  9. Good web site I truly love how it is simple on my eyes and the data are well written Im wondering how I might be notified when a new post has been made

  10. Always keep your words soft and sweet just in case you have to eat them

  11. Hi Oh my goodness an amazing article dude Thank you However I am experiencing issue with ur rss Dont know why Unable to subscribe to it Is there

  12. It is appropriate time to make some plans for the future and it’s time to be happy. I’ve read this post and if I could I wish to suggest you few interesting things or tips. Perhaps you could write next articles referring to this article. I desire to read more things about it!

  13. Click on tools at the top of your screne Then click on internet options A pop-up window will open Then you should be able to click on clear history

  14. A person necessarily lend a hand to make significantly posts Id state This is the first time I frequented your web page and up to now I amazed with the research you made to make this actual publish amazing Magnificent task

  15. I keep playing what is this great update lecture about receiving boundless online grant applications i really are already exploring the top site to get

  16. What i don’t realize is actually how you’re not actually much more well-liked than you may be now.You are very intelligent.You realize therefore significantly relating to this subject, made me personally consider it from numerous varied angles.Its like men and women aren’t fascinated unless it’s one thing to do with Lady gaga! Your own stuffs outstanding.Always maintain it up!

  17. I don’t even know how I ended up here, but I thought this post was good.I don’t know who you are but certainly you are going to a famous blogger if you aren’t already ;) Cheers!

  18. Actually one of many challenges which people starting a brand new on-line firm face is that of obtaining guests to their internet site.

  19. I’m into hip hop this might just help me make some new tracks thanks

  20. Thank you so much for giving everyone an exceptionally breathtaking chance to read articles and blog posts from this web site. It’s always very fantastic and also packed with amusement for me and my office colleagues to search your web site more than 3 times in one week to learn the newest things you have. And lastly, we are actually satisfied with all the excellent techniques you give. Selected 2 tips in this posting are definitely the most efficient we’ve ever had.

  21. My spouse and i have been now comfortable Jordan could carry out his studies with the precious recommendations he grabbed from your very own weblog. It’s not at all simplistic just to happen to be giving for free guides that many others have been making money from. We see we now have the blog owner to thank for that. The type of explanations you’ve made, the easy website menu, the friendships you will give support to create – it is everything wonderful, and it’s really helping our son and our family do think the idea is excellent, which is certainly truly essential. Thank you for everything!

  22. I have no statistics on how happy other hip replacement patients are but I can tell you that I have had both hips replaced in separate surgeries and I couldnt be more pleased with the outcome If I hadnt had the surgeies I would be in a wheelchair today I consider it sort of a miracle surgery in how it relieves pain and restores function in people who would otherwise end up in wheelchairs I couldnt walk without a cane or stand for more than a few minutes during the months before surgery Now I can shop till I drop and walk miles Like I said — a miracle As for recovery time I was able to drive at the 5-week mark (after each surgery) I used a walking aid (walker or crutches then a single crutch then a cane) for about 2-3 months (I recovered faster from the second surgery) I finished outpatient PT at about the 8-week mark I just had my 7-year check-up

1 ... 23 24 25
  1. No trackbacks yet.