Simon: The decision saved your life. Zoe: Won't happen again, sir. Mal: Good. And thanks. I'm grateful. Zoe: It was my pleasure, sir.

'Out Of Gas'


Buffistas Building a Better Board ++

Do you have problems, concerns, or recommendations about the technical side of the Phoenix? Air them here. Compliments also welcome.


-t - Sep 13, 2012 1:51:29 pm PDT #3259 of 4673
I am a woman of various inclinations and only some of the time are they to burn everything down in frustration

Have a lovely evening, Tom.


Jessica - Sep 13, 2012 2:33:34 pm PDT #3260 of 4673
And then Ortus came and said "It's Ortin' time" and they all Orted off into the sunset

YAAAAAAAAAAAAY!!!! Huzzah, three cheers for the Scola!


Jesse - Sep 13, 2012 2:48:22 pm PDT #3261 of 4673
Sometimes I trip on how happy we could be.

Hip hip HOORAY!

Hip hip HOORAY!

Hip hip HOORAY!!!


Liese S. - Sep 13, 2012 3:31:06 pm PDT #3262 of 4673
"Faded like the lilac, he thought."

Okay, okay, we better move the Scola-worship back to Natter or somewhere before ita ! gets back and thinks all these posts are things she needs to resolve. (Me too, not coming down on anyone here.)


Rob - Sep 18, 2012 6:45:26 am PDT #3263 of 4673

post-mortem later

So what happened?


Tom Scola - Sep 18, 2012 2:42:45 pm PDT #3264 of 4673
Remember that the frontier of the Rebellion is everywhere. And even the smallest act of insurrection pushes our lines forward.

Hackers got in again, via Plesk.

They modified the /etc/php.conf and /etc/httpd/conf/httpd.conf file so that PHP would insert malicious code into people’s browsers whenever a PHP page was visited. Fortunately, the hijacked PHP would not execute and instead would fail immediately. Unfortunately, this caused the entire site to go down—probably a better outcome than the alternative.

Scanning the system afterwards, I found the only other changes to the system at the time of the attack were to some Plesk internals. At the very least, Plesk needs to be wiped out and reinstalled from scratch.

At this point, I would recommend moving to a whole new server, with an up to date version of Plesk, and an up to date OS (we’re running CentOS 4.9). If iStrata can’t provide us this, then we should switch hosting.


§ ita § - Sep 18, 2012 3:31:33 pm PDT #3265 of 4673
Well not canonically, no, but this is transformative fiction.

If we're starting from scratch, any reason to stay? It is more exhausting moving across the state instead of down the hall, but we will have to pick up everything and find its place in the new digs, and I suspect we will have to pay them for any help they give us.

Mostly I blanch at the change of address part of the metaphor.


Rob - Sep 18, 2012 3:41:57 pm PDT #3266 of 4673

I agree with Tom.

Although the iStrata guys were really good when I rented my server seven or eight years ago, they haven't kept up with the times. There's no reason to get an actual physical server these days when a virtual server could easily handle the board's load.

We might even be able to run the entire thing out of the Amazon EC2 free tier for a year.

[link]

If not, the Linode guys are highly regarded.


§ ita § - Sep 18, 2012 4:27:23 pm PDT #3267 of 4673
Well not canonically, no, but this is transformative fiction.

You agree with me too, right? Validate meeeeeeeee.......

Just kidding.

I'd rather not go with Amazon for reasons I have no right to impose on the board, so only if it's perfectly reasonable and equally viable.

Popping something up in the cloud sounds like a good and safe option. We shouldn't be in the OS administration business. Just keeping the php running and not php itself. Not even the mySQL, if we can avoid it. But certainly not Linux.


Lee - Sep 18, 2012 9:59:15 pm PDT #3268 of 4673
The feeling you get when your brain finally lets your heart get in its pants.

I feel like one of Gary Larson's dogs.