sonance.tech.news

July 13, 2009

wordpress mu updated to 2.8.1

Filed under: blogs, security, techupdate — berniq @ 2:17 pm

again .. wordpress mu was upgraded to the latest version :)

February 18, 2009

up again, database recovered

Filed under: Outage, security, sysadmin crunching, techupdate — iang @ 11:49 pm

after a long night of beer blah hack splice graft perl miceql grunge splech pizza argh art blech … the database has been recovered.

There may be errors or lost data … please let the support or stuff or tech lists know.

Also the security updates were done on the raw machine … hold your breath!

January 23, 2009

website down

Filed under: Outage, security, sysadmin crunching, techupdate — berniq @ 12:04 pm

As of last weekend, all websites are down due to a hack.  Apologies.

The problem is a lot of the websites are old and unmaintained.  We cannot see which ones, and we cannot fix them.  As there are hundreds of websites, it is beyond our capacity to keep them going or secure them.

So they must be the responsibility of each site owner.  In order to deal with this general problem, the board met last wednesday and voted on a general policy of membership requirements.  See an email post thursday.

Therefore two things are required for each website:

  • a systems administrator needs to be identified and responsible for the security of the site
  • a member needs to sponsor in some sense or other the site

For Membership, see the email sent out by doris.

February 20, 2008

meeting 20080220

Filed under: meeting, security — iang @ 7:22 pm

Present: iang, virtual-matthias-G

Zentrix hacked again and again …

  • Zentrix VM got hacked last friday night.
  • Cleanup lasted minutes and it was hacked again by monday.
  • vector of attack was either mod_perl or mod_php, no clarity on this point
  • PHP was opened up again last September.
  • Only active sysadms now have access, and new security policy is in place.
  • subik moving dns to new VM with assistance from FF’s Wolfgang
  • subik will solve ldap domains change problem.