I want to host my newly purchased domain on my W2K Server box - few questions...

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Bleep

Diamond Member
Oct 9, 1999
3,972
0
0
Lots of advice here. but There is a lot simpler way. Download PHPtriad. You will have the latest Apache server, PHP, MySql. Mysql adiministration, all configured and ready to go. Apache config is easy all you have to do is edit 3 lines of text and dump your website stuff into htdocs. It takes about 20 minutes from start to finish. And if you want to put up a bulletin board PhpBB will dump into the server along with your website and you will have that up and running in just a little bit.

Bleep
Link to triad
 

Tanner

Diamond Member
Dec 15, 2001
7,391
0
0
Bleep

Hey thanks for the linky d00d! :D

I know that I'd like to have a msg. board for the whole fam. to use, but I'm afraid that the learning curve will be so steep for them (as hosting it will be for me) that they won't have the desire to learn it inorder to utelize it! :D

sure will be kewl for my friends and I though! :D

Thanks AGAIN! :D
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
So, it seems as though, the only way to make something secure, for certain, is to run some sort of incredibly scarce system and Linux.

Even then you can't be 100% sure, not all break-ins require a buffer-overflow be exploited. The only way to be as sure as possible is to be informed, stay up to date on all the software you run and know it inside and out.

man...this thing has blown up so much in my face now. that I'm almost afraid to put anything on the internet! BAH

You should be scared, I'm pretty sure it was said a default, unpatched install of Win2K+IIS or RedHat 7 (provided you choose the default server install and let it install all the daemons it wants) will get cracked in under 10 minutes.
 

Tanner

Diamond Member
Dec 15, 2001
7,391
0
0


<< I'm pretty sure it was said a default, unpatched install of Win2K+IIS or RedHat 7 (provided you choose the default server install and let it install all the daemons it wants) will get cracked in under 10 minutes >>



this is completely ridiculous!! :disgust:
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
nimda is automated, once a web server is infected it searches for other IIS servers to infect.
 

ttn1

Senior member
Oct 24, 2000
680
0
0
I haven't seen it mentioned here yet, so I'll mention. Logs are your best friend in the whole world. Learn to search your logs often and thoroughly. There are some nice logs searching softwares available as well.

I have yet to find a compromised machine that doesn't have a tell-tale listing in the logs. There is almost always something strange.

Also, this has already been said, but keep up to date on whatever software you use. Frequenting a few security sites is always a good idea.

And last, but not least, if you know a machine has been compromised, don't try to "fix" it. Backup important data and then format and reinstall. If you document your install procedures this shouldn't take too much time. Then virus check your data to within an inch of it's life before restoring it.
 

flippinfleck

Golden Member
Oct 24, 2000
1,090
1
0
Sure you may not want to try to fix it, but if you just wipe everything how the heck are you going to know how they got in in the first place? Wherever the flaw was, it's going to be in the new install that you set up according to the doc's you made when you first installed.

Wouldn't it be more beneficial to remove all your personal data and allow only incoming connections to the cracked box? You'd be able to find out where they came in, how they came in, and most important; how to close it up. Hell, might even be able to find out who it is.

Oh, but this would require a decent firewall, a little experience, and some patience. My bad.



<< And last, but not least, if you know a machine has been compromised, don't try to "fix" it. Backup important data and then format and reinstall. If you document your install procedures this shouldn't take too much time. Then virus check your data to within an inch of it's life before restoring it. >>

 

Tanner

Diamond Member
Dec 15, 2001
7,391
0
0
watts3000 PM'd me and was curious as to what I was going to do now...so I figured that I'd g'head and state that ;)

I'm going to host my family's pic's on my cyberwings account until they go out of business :D Then, WHO knows what! :D

My decisions were largely influenced by the responses to my thread questioning the potential illegality of running it on a .EDU IP range

I really appreciate all the responses from N11, n0cmonkey, ScottMac, Drakkhen, chiwawa626, ??damaged?? over there in that thread...and n0cmonkey I liked that last explanation of DNS lookup. I'm going to ck. it out more in a few... But, anyhow, after seeing that some ppl thought that I would prolly get busted (ScottMac0 ;) I dont think that I wanna get busted very much..so I rekon I'll just host it elsewhere and wait to get outta here. Unless U guys got another idea or two! ;) hehehehhe

Thanks again, and God Bless!
Tanner