Recently in Security Category

Three websites on three different shared servers were compromised by a hacker through weak FTP passwords.  The hacker uploaded a trojan to these hosting packages and so these three servers were placed on anti-spam blacklists.

All three website owners have been contacted now and their FTP passwords reset.  The offending files have been removed and the servers should be fully out of the blacklists soon.  In the meantime for any users of the following servers they might be seeing some emails they send bouncing back to them undeliverable:

Galahad - 81.17.248.4
Gorlois - 81.17.252.85
Rivalin - 81.17.252.145

As a note to all users, please ensure all of your passwords are relatively secure.  Some secure password tips would be:

# Don't use a dictionary word
# Don't use part of the username
# Keep the password at least 7 characters long
# Have a combination of at least three of:
- lowecase characters (a, b, c)
- uppercase characters (A, B, C)
- numbers (1, 2, 3)
- non-alphanumeric characters (!, %, *, {, £, )


Update (12.00pm):  The three servers were removed from the blacklist about 90-120 minutes ago and most, if not all, mailservers around the world should have updated their blacklists to no longer include these three IP addresses.  The IP addresses are fully removed from the blacklist itself.
If you are using the popular CMS Joomla please make sure that you are running the latest version.

Older versions of Joomla are affected by a serious security issue which can lead to your site(s) being compromised and possibly defaced.

If you installed Joomla using the auto-installer (installatron) available to users on our DirectAdmin powered servers you should be able to upgrade via the control panel.

Even the Joomla developers were affected by this security issue


Reblog this post [with Zemanta]
The following security bulletin was issued today by Debian Linux.

http://lists.debian.org/debian-security-announce/2008/msg00152.html

This affects Debian systems and derivatives such as Ubuntu from Edgy onwards. Please install/update openssl packages on your servers where appropriate and re-generate all SSL key/cert pairs along with an openssh keys that you use for authentication purposes.

Blacknight will be apply fixes to managed customers servers and re-generating ssh keys, ssl cert cert/key pairs during the next 24 hours.

Note: This is Debian specific, CentOS, RHEL etc are not affected.