<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="0.92">
<channel>
	<title>Justin Samuel</title>
	<link>http://www.justinsamuel.com</link>
	<description>Security, Linux, Development</description>
	<lastBuildDate>Tue, 15 Jan 2008 22:00:03 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Vulnerability: AWBS magic_quotes_gpc &#8220;Off&#8221; SQL Injection and XSS</title>
		<description>Advisory: AWBS magic_quotes_gpc "Off" SQL Injection and XSS Vulnerabilities
Release Date: 2007-06-10
Last Modified: 2007-07-26
Author: Justin Samuel [http://www.justinsamuel.com]

Application: AWBS &#60; 2.6.0
Severity: Highly Critical
Impact: Disclosure of sensitive information
Cross site scripting
Vendor Status: Vendor released version 2.6.0 to address issue. Testing still needed to verify that issue is corrected.

Vendor: Total Online Solutions, Inc.
App. Website: http://www.awbs.com/
References: ...</description>
		<link>http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/</link>
			</item>
	<item>
		<title>Vulnerability: AWBS Dedicated Server Info Visible to All Users</title>
		<description>Advisory: AWBS Dedicated Server Info Visible to All Users
Release Date: 2007-06-10
Last Modified: 2007-07-26
Author: Justin Samuel [http://www.justinsamuel.com]

Application: AWBS &#60; 2.6.0
Severity: Less Critical
Impact: Disclosure of sensitive information
Vendor Status: Vendor released version 2.6.0 to address issue. Testing still needed to verify that issue is corrected.

Vendor: Total Online Solutions, Inc.
App. Website: http://www.awbs.com/
References: http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/

--------------------------------------------------------------------------

Description:

Advanced Webhost ...</description>
		<link>http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/</link>
			</item>
	<item>
		<title>Vulnerability: ModernBill Insecure CURL Settings</title>
		<description>#################################################################

Vulnerability discovered by: Justin Samuel (www.justinsamuel.com)
Discovery Date: 2006-07-11
Severity: Less Critical
Impact: Exposure of sensitive information

Product: ModernBill
Affected Versions: 5.0.1
Vendor: ModernGigabyte, LLC (www.moderngigabyte.com)
Product Link: http://www.modernbill.com/

#################################################################
 </description>
		<link>http://www.justinsamuel.com/2006/07/11/vulnerability-modernbill-insecure-curl-settings/</link>
			</item>
	<item>
		<title>php 5.1.4 rpms for rhel4 added (with apc)</title>
		<description>php 5.1.4 rpms for rhel 4 have been added to the rpm downloads section. These are based off of the current fedora core 5 rpms with the following changes:

    * shared hosting security: removed posix functions [shared hosting security]
    * removed pcntl functions [shared ...</description>
		<link>http://www.justinsamuel.com/2006/05/25/php-514-rpms-for-rhel4-added-with-apc/</link>
			</item>
	<item>
		<title>scponly rpms with chroot enabled added for rhel4</title>
		<description>i've added scponly rpms with chroot enabled for rhel4.  get the files here or by apt/yum.  this is more useful in a shared hosting environment than the rpms found at DAG and elsewhere that don't have chroot enabled.

to use this, for example on a plesk box to allow ...</description>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/</link>
			</item>
	<item>
		<title>HOWTO: use forwards in bind to only answer queries for domains on your servers (and not be an open dns server)</title>
		<description>This howto is meant to be a quick fix for those moving from one server to two or those with two servers who want to disable recursion.  This only works if at least one of your nameservers answers authoritatively for each zone already.  I believe it should work ...</description>
		<link>http://www.justinsamuel.com/2006/03/16/use-forwards-in-bind-to-only-answer-queries-for-domains-on-your-servers/</link>
			</item>
	<item>
		<title>php APC rpms added for php 5.1.2 / APC 3.0.10 / rhel 4</title>
		<description>I've added php-apc rpms for php 5.1.2 on rhel4, using the current stable release of APC (3.0.10).   get the files here or by apt/yum.  Additional notes:  </description>
		<link>http://www.justinsamuel.com/2006/03/15/php-apc-rpms-added-for-php-512-apc-3010-rhel-4/</link>
			</item>
	<item>
		<title>HOWTO: Create a self-signed (wildcard) SSL certificate</title>
		<description>The following commands are all you need to create a self-signed (wildcard, if you want) SSL certificate: </description>
		<link>http://www.justinsamuel.com/2006/03/11/howto-create-a-self-signed-wildcard-ssl-certificate/</link>
			</item>
	<item>
		<title>HOWTO: Setup SSL certificates for mail services (pop3s, imaps, smtps) on Plesk / Courier-Imap / Qmail</title>
		<description>This howto will show you how to setup an SSL certificate on a Plesk server so that it will be used when people connect through secure pop, smtp and imap. </description>
		<link>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/</link>
			</item>
	<item>
		<title>HOWTO: Backup and restore a Plesk domain from the command line</title>
		<description>This HOWTO shows how to use the Plesk command line utilties to backup and restore a single domain.  This can be useful, among other reasons, as a way to move a site between servers (though now they have the Migration Manager for that) or as a way to make ...</description>
		<link>http://www.justinsamuel.com/2006/03/09/howto-backup-and-restore-a-plesk-domain-from-the-command-line/</link>
			</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.150 seconds -->
