The first step in securing servers is to ensure that they are physically as secure as possible and and then monitored for unauthorized access Many times when setting up servers in a small office or co-location facility many people have their systems in a locking cabinet within a moderately secured physical building. However a determined [...]
Sysadmin's archives
Server cabinet door alarm
OSSEC Daily Reports
As with any user of OSSEC, analyzing and working with the data is the key to successfully managing your environment. From a prior post you can see we are monitoring events as they occur which is good for catching serious issues as they occur; however, it is not usually the best way to document what [...]
Vyatta border gateway passthrough filtering
Vyatta routers bring high-quality enterprise routing in an open-source package. Like many projects it was originally designed for small office/home configurations but has grown to enterprise solutions. The current documentation on filtering between zones does not tie everything together well enough to understand zone filtering. This post will walk through a complex filter configuration for a vyatta running as a border gateway and not a small office/home gateway.
Zabbix & OSSEC: Open-Source compliance and security monitoring
Good security, not just compliance requirements, encourages IT & Security staff to spend time reviewing security events. There are many tools available for many security components of your network; this article will focus on host security and host log monitoring using OSSEC and Zabbix.
Anti Virus and PCI Compliance
Last year PCI DSS 1.2 was released changing the intent of the controls required for anti-virus software. In version 1.1 anti-virus software was only required for systems commonly affected by viruses and excluded UNIX based operating systems and mainframes. Version 1.2 now requires all operating system types commonly affected by malicious software be protected and [...]
Tips & Tricks: Optimize performance of Kerio MailServer
Kerio MailServer includes log viewing directly within the administration console. This is a quick and easy way to troubleshoot problems, identify attempts to breach security, or monitor daily activity. Although these files contain only textual information, over time they can become quite large, and without any maintenance, they can degrade the performance of the server [...]
Categories
-
- Announcements (7)
- CentOs (1)
- Change Management (1)
- Debian (4)
- Email (4)
- HIPPA (3)
- InterWorx (3)
- Kerio Mail Server (8)
- Linux (9)
- PCI (19)
- PHP (2)
- Security (15)
- Sysadmin (12)
- Ubuntu (2)
- VPS Servers (2)
- Xen (1)
Recent Posts
Search
February 2012 M T W T F S S « Jan 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
Archives
Tags
- activesync amazon ec2 apache assesment caller-id CentOs change cli command line Control Panel credit card credit card payment credit cards stolen data breach Debian dsbl dss Email HIPPA Hosting hosting control panel InterWorx Interworx-CP kerio lamp Linux log files mail server openssl PCI permissions qsa search Security sender policy shared hosting Small Business spam spf spoofing Sysadmin Ubuntu vps VPS Servers Xen
Blogroll
Links
- ZZ Servers Managing Partner to speak at #Shmoocon #Firetalks
- Server cabinet door alarm
- Managing Partner speaking to College of Charleston Computer Science / ACM
- OSSEC Daily Reports
- Vyatta border gateway passthrough filtering
- ZZ Servers Expands to Equinix Ashburn
- Kerio connect 7.1 offers native support for BlackBerry
- The surprising truth about what motivates us
- PCI Data Security Standards Rock Video
- Kerio Connect links Apple iPad to Business Communications
- sj7trunks in Zabbix & OSSEC: Open-Source complia…
- Shawn Oswald in PCI Data Security Standards Rock Vi…
- PCI Free in PCI Data Security Standards Rock Vi…
- Secure USB Flas… in Zabbix & OSSEC: Open-Source complia…
- Has anyone trie… in Zabbix & OSSEC: Open-Source complia…
- monicauk in Anti Virus and PCI Compliance
- joanfronske in Kerio MailServer and Mac OS X Snow …
- Andy in Amazon confirms EC2/S3 does not mee…
- Twitted by Juli… in Amazon confirms EC2/S3 does not mee…
- Zen Dzign - Ama… in Level 2 Merchants Required to Have …
- Batteries.com Credit Card Data Stolen (3)
- Zabbix & OSSEC: Open-Source compliance and security monitoring (3)
- Amazon confirms EC2/S3 does not meet PCI guidelines (2)
- PCI Data Security Standards Rock Video (2)
- Level 2 Merchants Required to Have On-Site Assessment by QSA (1)
- Kerio MailServer and Mac OS X Snow Leopard (1)
- Anti Virus and PCI Compliance (1)