3 ms·
It is definitely not the only measure. There are many more aspects of security. But a hacker only needs to find one gap. So the security is not the average of a
by dolfje 11y ago
It is definitely not the only measure. There are many more aspects of security. But a hacker only needs to find one gap. So the security is not the average of all aspects, but the minimum. So finding hosters that fail one aspect (outdated software) are already problematic.
That is the reason why security is hard ;)
- mediacatch 11y agoMediacatch here. We really do appreciate it. I'm surprised we made it to the list of 100 hosters since we're very(extremely) small compared to the others. As to the issues: - Our apache was 2.2.29, it is recommended for 2.2.31 due to the 1 CVE. The re-compile is running now. Edit: It's now done. - We use a piece of software called cloudlinux, and it features the ability to switch PHP versions. We just moved this server a few months ago and it had PHP 5.2 as the default. Admittingly, this was an oversight and I've just switched it to PHP 5.3.29. This PHP version does have security backports for CentOS/RHEL 6. This is the latest version that we can use due to our billing system. We use WHMCS, so we need to go to V6 instead of our current V5. This is a large undertaking since we need to re-theme a complex theme. - Openssl/OpenSSH is now up to date according to the CentOS repo, which has backported patches for exploits mentioned. I'm actually not sure why this wasn't auto-updated since we had that enabled like our other servers. We don't have the experimental J-PAKE enabled, so the 2 warning vulnerabilities that your system cited are not relevant. I've also run this your tool again on our site to confirm the openssl/openssh were fixed. You didn't provide a contact on your blog post, would you be able to please downgrade/remove us? Thank you.
- dolfje 11y agoGlad to see you fixed the issues, I absolutely love it that you acted to fast. You have been removed from the list.