amuck-landowner

Search results

  1. tchen

    How to do encrypted backups with duply/duplicity

    Duply is a thin command line wrapper around duplicity, handling configuration, keys and pre-post scripts.  You can still pass in duplicity options directly, but this just makes things so much nicer. This guide assumes You are running Debian You want to backup selective parts of your system to...
  2. tchen

    DDOS Protection

    Hehe, I'll adopt this thread.  I've been interested in DDoS protection for a while and welcome the thread updates.
  3. tchen

    Who uses Stripe for payments? Beware, they seem to not validate cards.

    @Damian jclark's Braintree module like his other one for stripe will inject the CC form on page.  The only difference between this and the Stripe one is that it uses the S2S method. There's another transparent mode one (direct to Braintree's servers) although I can't say it gives me a warm fuzzy.
  4. tchen

    WHMCS exploit involving Stripe payments?

    You might be stumbling across this gem https://support.stripe.com/questions/cvc-or-avs-failed-but-payment-succeeded Also, Stripe.com does not do phone numbers.  All it handles per card are name, address-lines, cvc, zip code.  Even then, not all card banks verify all fields, and the API only...
  5. tchen

    Nginx redirect http to https

    So just for reference to anyone else searching... your own-post has several issues (pointed out by everyone else on this board): 1)  Uses "if" in a nginx config where it really doesn't even need it.  Your $scheme will always be 'http' give its location in the :80 server config. 2)  Your use of...
  6. tchen

    Nginx redirect http to https

    I'm perplexed as to why the best answer is your own blog post. And don't say the posts above yours didn't work as the extra 'scheme' check you out in the post does nothing. Is this a new form of rep back linking?
  7. tchen

    ChicagoVPS global password reset? Hacked again?

    The sql injection contains the userid requested. Which increments toward total rows. That said, each row could be an active user, a lapsed client, or even a fraud-locked one. I wouldn't put it past them to have accumulated so much debris in their system to have such a high 'client' count.
  8. tchen

    New WHMCS Exploit

    That mass mailing function deserved to be broken :)
  9. tchen

    BuyVM - Leaving Buffalo Early

    So, does this mean the buffalo machines will get some love sooner than later?  SSDs perhaps?  :P
  10. tchen

    What do YOU use to monitor your servers?

    Zabbix, but first line of defense is monit.  I have it set to auto-restart any misbehaving services. Bandwidth usage is handled by vnstat.
  11. tchen

    "true cloud" providers

    If the datacenter resilancy is off the table, then any OnApp provider should be able to float your boat. I wouldn't call it a recommendation though as they tend to charge far too much for snake oil.
  12. tchen

    "true cloud" providers

    There's vmware which supports stretched clusters (~100km apart at most).  Although anyone providing this as a end-client solution probably has them closer together to ensure the storage backend can do synchronous replication without losing too much performance.  Frankly, to the OP - don't rely...
  13. tchen

    New WHMCS Exploit

    Or... Naxsi (which I'll give TJR the benefit of doubt on) Edit :!Nvm, I see kujoe already mentioned it.
  14. tchen

    ColoCrossing and vpsBoard

    I'd leave it be from the admin side. Threads like those should exist, not for their content, but more for shedding light on individual posters/providers. I've come to use them as a way to separate more mature individuals from the rest. As a community member, if you don't like them, just post...
  15. tchen

    East Coast DDOS Filtering

    Can we buy the Buffalo VPS's right now and just stick the DDOS as an addon later?  Or is it a packaged deal.
  16. tchen

    Thought Experiment: A Completely Anonymous Web Site

    Does it still count as anonymous if you get a bona fide person to do it for you?  A blind maildrop sort of system.  Once you get root and a vpn setup, open cafe wifi's are your oyster.
  17. tchen

    SSL Speed Up?

    Turn off DHE ciphers if you're using nginx from http://techsamurais.com/?p=1384 That should alleviate some of the strain at least.
  18. tchen

    Your take on DNS Providers and Their Own Configurations

    At least with regards to rage4dns using another provider, it should be expected. Otherwise how would you have status updates or ticket contacting if the service is down. Basic business continuity stuff.
Top
amuck-landowner