<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InstaCarma Blog &#187; vulnerability</title>
	<atom:link href="http://www.instacarma.com/blog/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.instacarma.com/blog</link>
	<description>Information Resource for Web Hosting Technical Support and Server Management</description>
	<lastBuildDate>Tue, 24 May 2011 10:01:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
		<item>
		<title>Rkhunter and Chrootkit installation</title>
		<link>http://www.instacarma.com/blog/technical/rkhunter-and-chrootkit-installation/</link>
		<comments>http://www.instacarma.com/blog/technical/rkhunter-and-chrootkit-installation/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 15:34:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Articles and tutorials]]></category>
		<category><![CDATA[Technical]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://instacarma.com/blog/?p=544</guid>
		<description><![CDATA[Filed under: security, vulnerability Rkhunter Installation Rkhunter is a tool used to check trojans, rootkits, and other security problems. Here are the installation steps:- root@server1 [~]#wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz root@server1 [~]#tar -zxvf rkhunter-1.2.7.tar.gz root@server1 [~]#cd rkhunter-1.2.7 root@server1 [~]#./installer.sh You can scan the server by using the following command:- root@server1 [~]#/usr/local/bin/rkhunter -c You can update the rkhunter database [...]]]></description>
			<content:encoded><![CDATA[<p>Filed under: <a href='http://www.instacarma.com/blog/tag/security/'>security</a>, <a href='http://www.instacarma.com/blog/tag/vulnerability/'>vulnerability</a></p>
<p><strong>Rkhunter Installation</strong></p>
<p>Rkhunter is a  tool  used to check trojans, rootkits, and other security problems.<br />
Here are  the installation steps:-</p>
<blockquote><p>root@server1 [~]#wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz<br />
root@server1 [~]#tar -zxvf rkhunter-1.2.7.tar.gz<br />
root@server1 [~]#cd rkhunter-1.2.7<br />
root@server1 [~]#./installer.sh</p></blockquote>
<p>You can scan the server by using the following command:-</p>
<blockquote><p>root@server1 [~]#/usr/local/bin/rkhunter -c</p></blockquote>
<p>You can update the rkhunter database by issuing the following command:-</p>
<blockquote><p>root@server1 [~]#rkhunter –update</p></blockquote>
<p><strong>Chrootkit Installation</strong></p>
<p>Chrootkit is a tool used for scanning the trojans in the server.</p>
<p>Here are the installation steps:-</p>
<p>1) Download the source package</p>
<blockquote><p>root@server1 [~]#wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz</p></blockquote>
<p>2)Check the  MD5 SUM of the download for security.</p>
<blockquote><p>
root@server1 [~]#ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.md5<br />
root@server1 [~]#md5sum chkrootkit.tar.gz</p></blockquote>
<p>3) Extract the source file and install it.</p>
<blockquote><p>root@server1 [~]#tar xvzf chkrootkit.tar.gz<br />
root@server1 [~]#cd chkrootkit*<br />
root@server1 [~]#make sense</p></blockquote>
<p>4) Scan the server.</p>
<blockquote><p>root@server1 [~]#./chkrootkit</p></blockquote>
<div class="alignright"><div class="g-plusone" data-href="http://www.instacarma.com/blog/technical/rkhunter-and-chrootkit-installation/" size="standard" count="true"></div></div>]]></content:encoded>
			<wfw:commentRss>http://www.instacarma.com/blog/technical/rkhunter-and-chrootkit-installation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>K T Ligesh , Owner of Lxlabs (creator of LxAdmin/HyperVM/Kloxo) , is no more.</title>
		<link>http://www.instacarma.com/blog/company-updates/k-t-ligesh-owner-of-lxlabs-makers-of-lxadminhypervmkloxo-passes-away/</link>
		<comments>http://www.instacarma.com/blog/company-updates/k-t-ligesh-owner-of-lxlabs-makers-of-lxadminhypervmkloxo-passes-away/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 15:01:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Company Updates]]></category>
		<category><![CDATA[hyperVM]]></category>
		<category><![CDATA[kloxo]]></category>
		<category><![CDATA[LxAdmin]]></category>
		<category><![CDATA[openVZ]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Xen]]></category>

		<guid isPermaLink="false">http://instacarma.com/blog/?p=456</guid>
		<description><![CDATA[Filed under: hyperVM, kloxo, LxAdmin, openVZ, vulnerability, Xen Owner of LxLabs, K T Ligesh (32) , passed away at his residence in Bangalore last night. Initial reports state that he committed suicide. As per the news-reports, it appears that Ligesh , who was a guitarist as well, was going through a difficult time personally. LxLabs [...]]]></description>
			<content:encoded><![CDATA[<p>Filed under: <a href='http://www.instacarma.com/blog/tag/hypervm/'>hyperVM</a>, <a href='http://www.instacarma.com/blog/tag/kloxo/'>kloxo</a>, <a href='http://www.instacarma.com/blog/tag/lxadmin/'>LxAdmin</a>, <a href='http://www.instacarma.com/blog/tag/openvz/'>openVZ</a>, <a href='http://www.instacarma.com/blog/tag/vulnerability/'>vulnerability</a>, <a href='http://www.instacarma.com/blog/tag/xen/'>Xen</a></p>
<div class="wp-caption alignleft" style="width: 167px"><img title="K T Ligesh" src="http://instacarma.com/blog/wp-content/uploads/2009/ligesh" alt="Image Source: Kannada Prabha" width="157" height="336" /><p class="wp-caption-text">Image Source: Kannada Prabha</p></div>
<p>Owner of <strong>LxLabs</strong>, K T Ligesh (32) , passed away at his residence in Bangalore last night. Initial reports state that he committed suicide. As per the <a href="http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms" target="_blank">news-reports</a>, it appears that Ligesh , who was a guitarist as well, was going through a difficult time personally.</p>
<p>LxLabs is the creator of <strong>HyperVM</strong> &#8211; optimized virtualization technology which runs on both Xen and OpenVZ, “Host In a Box” solution <strong>- LxAdmin/Kloxo</strong> for Web hosting companies, server owners, resellers etc. Recently, there have been some serious  <a href="http://www.milw0rm.com/exploits/8880" target="_blank">vulnerability reports </a>concerning their software.</p>
<p><span style="font-size: small;">Ligesh was an exceptional software engineer, and the mastermind behind all the well known software products his company produced. His stellar engineering talent is evident in the way he created innovative software products that were quick to rise in popularity and adoption within the industry, capturing the imagination of thousands of industry watchers. <strong>InstaCarma</strong> and its Directors shared a cordial relationship with Ligesh. His brilliance and intelligence always shone through in all our interactions with him.</span></p>
<p>Details regarding who will take over the operations of the company or the development/maintenance of the software is not available at the moment. Also, it is not known what the server owners who use LxLabs&#8217; software should do in the wake of this news. While further updates are awaited, Ligesh is in our thoughts and prayers . May his soul rest in peace!</p>
<div class="alignright"><div class="g-plusone" data-href="http://www.instacarma.com/blog/company-updates/k-t-ligesh-owner-of-lxlabs-makers-of-lxadminhypervmkloxo-passes-away/" size="standard" count="true"></div></div>]]></content:encoded>
			<wfw:commentRss>http://www.instacarma.com/blog/company-updates/k-t-ligesh-owner-of-lxlabs-makers-of-lxadminhypervmkloxo-passes-away/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Nessus : Vulnerability scanner</title>
		<link>http://www.instacarma.com/blog/technical/nessus-vulnerability-scanner/</link>
		<comments>http://www.instacarma.com/blog/technical/nessus-vulnerability-scanner/#comments</comments>
		<pubDate>Fri, 08 May 2009 14:57:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Articles and tutorials]]></category>
		<category><![CDATA[Technical]]></category>
		<category><![CDATA[Nessus]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://instacarma.com/blog/?p=132</guid>
		<description><![CDATA[Filed under: Nessus, PCI, scan, scanner, security, vulnerability Nessus is one of the best vulnerability scanning tool available today. It is available free of cost for personal use. It can detect potential vulnerabilities in an individual system or a network. In the Unix/Linux environment,  Nessus consists of two parts :- nessusd &#8211; It is the [...]]]></description>
			<content:encoded><![CDATA[<p>Filed under: <a href='http://www.instacarma.com/blog/tag/nessus/'>Nessus</a>, <a href='http://www.instacarma.com/blog/tag/pci/'>PCI</a>, <a href='http://www.instacarma.com/blog/tag/scan/'>scan</a>, <a href='http://www.instacarma.com/blog/tag/scanner/'>scanner</a>, <a href='http://www.instacarma.com/blog/tag/security/'>security</a>, <a href='http://www.instacarma.com/blog/tag/vulnerability/'>vulnerability</a></p>
<p><strong></strong></p>
<p><strong>Nessus</strong> is one of the best vulnerability scanning tool available today. It is available free of cost for personal use. It can detect potential vulnerabilities in an individual system or a network.</p>
<p>In the Unix/Linux environment,  Nessus consists of two parts :-<br />
<em><br />
nessusd &#8211; It is the daemon which does the scanning.<br />
Nessus  &#8211; the client which controls the scanning and provides the report to the user.</em></p>
<p>Source and guidelines for the installation is available on the official Nessus website – <a href="http://www.nessus.org" target="_blank">www.nessus.org</a></p>
<p>Once you are done with the installation you need to make sure that the nessusd daemon is up and running. After that an <em>user </em>needs to be added. This can be done using the command &#8216;nessus-adduser&#8217; (of course, without the quotes).<br />
The figure below explains it quite well:</p>
<div id="attachment_140" class="wp-caption aligncenter" style="width: 386px"><img class="size-full wp-image-140" title="Adding an user" src="http://instacarma.com/blog/wp-content/uploads/2009/05/useradd_bak.png" alt="Adding an user" width="376" height="398" /><p class="wp-caption-text">Adding an user</p></div>
<p>This user will be able to login to the client and run the scan.</p>
<p>Then you can start the client by entering the command &#8216;nessus&#8217; through the console.<br />
You will be presented with an interface like in figure 2 .</p>
<p>This screen shot was taken while we were running a scan for one of our clients.</p>
<div id="attachment_143" class="wp-caption aligncenter" style="width: 285px"><img class="size-medium wp-image-143" title="fig2" src="http://instacarma.com/blog/wp-content/uploads/2009/05/fig2-275x300.jpg" alt="Figure 2" width="275" height="300" /><p class="wp-caption-text">Figure 2</p></div>
<p>You just need to fill in the fields and click &#8216;Log in&#8217;</p>
<p>Please note that you might have to update the plugins and for that you need to get your scanner registered online. The process takes just a couple of minutes and the instructions are available at <a href="http://www.nessus.org/plugins/index.php?view=register-info" target="_blank">http://www.nessus.org/plugins/index.php?view=register-info</a></p>
<p>Then you need to click on the tab &#8216;Plugins&#8217;</p>
<div id="attachment_147" class="wp-caption aligncenter" style="width: 297px"><img class="size-medium wp-image-147" title="plugins" src="http://instacarma.com/blog/wp-content/uploads/2009/05/plugins-287x300.jpg" alt="Figure 3" width="287" height="300" /><p class="wp-caption-text">Figure 3</p></div>
<p>Enable all the plugins as shown above in figure 3. If you do not enable the required plugins then the scan will not return the desired results.</p>
<p>Certain plugins might cause freezing of the network from which you are running the scan . So, make sure  you have the system administrators ready in case you run into any trouble.</p>
<p>Now, you need to mention the &#8216;target&#8217; machine on which the scan is going to be run.  Please refer to figure 4 below :</p>
<div id="attachment_145" class="wp-caption aligncenter" style="width: 297px"><img class="size-medium wp-image-145" title="target" src="http://instacarma.com/blog/wp-content/uploads/2009/05/target-287x300.png" alt="Figure 4" width="287" height="300" /><p class="wp-caption-text">Figure 4</p></div>
<p>Now, you can go ahead and &#8216;Start the scan&#8217; . You can see the progress of the scan on your screen as shown in figure 5.</p>
<div id="attachment_148" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-148" title="progress" src="http://instacarma.com/blog/wp-content/uploads/2009/05/progress-300x233.png" alt="Figure 5 " width="300" height="233" /><p class="wp-caption-text">Figure 5 </p></div>
<p>Once the scan is completed, you will be presented  with a report as the one given below in figure 6.</p>
<div id="attachment_149" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-149" title="report" src="http://instacarma.com/blog/wp-content/uploads/2009/05/report-300x236.png" alt="Figure 6" width="300" height="236" /><p class="wp-caption-text">Figure 6</p></div>
<p>This report can be exported to html or pdf format also.</p>
<p>For reference, I am pasting parts of the pdf that we got after scanning the client server.</p>
<p><img class="aligncenter size-full wp-image-151" title="summary1" src="http://instacarma.com/blog/wp-content/uploads/2009/05/summary1.png" alt="summary1" width="742" height="110" /></p>
<p>The above part depicts the summary of the scan on the whole.</p>
<p>The one below shows the part which explains one of the vulnerability and the suggested solution.</p>
<p><img class="aligncenter size-full wp-image-152" title="vlner" src="http://instacarma.com/blog/wp-content/uploads/2009/05/vlner.png" alt="vlner" width="583" height="307" /></p>
<p>Likewise, you will get a detailed report about the potential problems and the suggested fixes.<br />
If all the vulnerabilities are fixed then the server is most likely to achieve PCI compliance.</p>
<p>I hope this article would be helpful for some people out here. If you have any further queries then do get back to us. We would be happy to help you.</p>
<div class="alignright"><div class="g-plusone" data-href="http://www.instacarma.com/blog/technical/nessus-vulnerability-scanner/" size="standard" count="true"></div></div>]]></content:encoded>
			<wfw:commentRss>http://www.instacarma.com/blog/technical/nessus-vulnerability-scanner/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

