Security

PGP Key

Posted by on October 31, 2012 at 1:15 pm

I just finished setting up my PGP Key: —–BEGIN PGP PUBLIC KEY BLOCK—– Version: PGP Universal 2.9.1 (Build 347) mQENBFCRVvgBCADFtL6vrnWMzM3ISvYFvvqX9DvzAJEot18BCvE/tNwacOghDYvP DrwGGolTnmtuE8Rnjtw2IoaxUjhzqfcyLm+U0tyPem4ONOkqvWuQwEmRrmWDh7O5 GEopWjU5cQYZlZ/T3TbtLKdNIcmQEGfiCEc3AI1GRSvz6TaQpSq5vuyvB0wU9Wmr Khj/Bgc6B9D8EoFnQcCHclB8Ci0HUsFGrd+CxIvhIOTmsOVVlV0Gmz89Tzt25Z3i iLt0fmxolVaSb/RFppOMqnM0Yr5FlMt4dzVQJ33DC2JwneFCiJhnLalzs3h3zBWv M2Iw3zZ/+IGx9ifRikAo4AIAfDWlLZ6Mu6VTABEBAAG0L1JpY2hhcmQgQ29ybndl bGwgKFJDUCkgPHJpY2hhcmRAdGVjaHRva25vdy5uZXQ+iQE4BBMBAgAiBQJQkVb4 AhsvBgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRCl8oLkpLXJ9vtWCACtxytH ZCM4Qp9k0Qn1fhYreQSAeE06LfXcQur+9qGTP6OMgTBrJ9Dx13mmyuWnA3fKOk2W Qr5+CX8lzjoQEzyNJ+4ye2dHno9FSIzQhcyf3xK3xnQJNpsgB/PUUZqtQswYggG0 dZZZmfyv0AyZuTf8mdcki86cVm7ShKSK7VzsLHZszKL1cTPgqvEvlRkN1p/q2sl8 L2twXzw3vQelSGM4HY+6VYrli97fT9kYaQDIV/JZcj6DzfKIYni9eJbTFLV7YGl8 uuQybyTZMzHIpUw4JGxpW+mPOl5TSAwEMa4D6m1re+92yVEkRovg4kX9YQPKvm8l yq/o2l3HwTtO/DtTiQEiBBABAgAMBQJQkVeRBQMAEnUAAAoJEJcQuJvKV618NJcH /3ov8crB2fjL4WBdTzxVHnNykScSNqM/l4zTmPt5A0C7xwQRajVguBNxF+9elYjv T/IOwAyZwuM7Qz1wMipDLNmOkHBJD+PiE3FH0DwE7+lEtn5z4UZQQP7ExK/d7N/C Lada0Uk4kqKR0tIdpTQb4nmBZuN8NX4UQ/XLVJiOzKW8ExOCf2DLNeG18+3RJP4p zLls94RGxDVjmQFMhL0TFzSOtlQhYNW8SfFrjOTJ6Yp4MDhNIPoRmwvj03OnJ3BF jqBO6gWGd+hitQMhhGGK/ypPoqIYJSajw9qwt/lJ1ylY+gZe0vvDYp4eYEnFGAoK XYcqhP5wv18FqIkFG41BUiy5AQ0EUJFW+AEIAMb91/McCVIxqXNr6ZYwE2SzdgcP ZWzTrxnI5rAFRGMRHLx/Cw0QDefGaue8on8kEgAekfjFj4Yh1Xl6Hd7pWKV2csno X49GNY715XtIVvncV1WVNalzZbyFeSXz+bn8ReGGnVHcfoimkxY6kOB2tFv6nb9W SNWPONe3JPZ3a8o+Vs4BMHiNFe0SB1a1N2iEQM7vQAbmOTLGQbELMszW4IJlY9wI OtFxMofc2TDMgQWj5B0Y9Lh2864HHhBJrlsJH1G9eqRQmsucPTPTQ9Z8oEHd9oDB mQAggFtA5jSiVg1BCGwJRZOkzGxLks4uPkAA9HPLcKXWzbWjUg8irFwJi5cAEQEA AYkCPgQYAQIACQUCUJFW+AIbLgEpCRCl8oLkpLXJ9sBdIAQZAQIABgUCUJFW+AAK CRDrZoXKBCUk5HDMB/sGutX7wGPF9GanPbaV7ol3hCFDqnPo94cAjlMaAOmcbUD7 NrCHUzgWRf3ipN9ITydlJanhRYX3B6lJGz/NYyslePpsZIno/EWrB7KlOEfA9JvB Zzr0bwEmrQRpThaSYS9xUUZPRNEJJrnEpv2CSacEax+YkN0dXCi6vDM89MOcS7e2 Uecj0Iq2eIf3BfjF9t17CHkGOfUlenC0umCCBw3BTbtv7WMmbps0STtuj+msbmRb FCF5YlKpdxrt/9QUuOGH/C+szhX3XQ9BRnfPMXv+oeBszHJPg21pF8SDWhzN1wFm b8ovzF5oQMsjMr+v1DCStCFh38R1UFawRoDHCBLqkpgIAKRtYitpoVqhCWf8yQ3S jUUVP4XDRhLiO0RdyNg6VGcFCv8eh2yyPQiiRjPhbj3SALni9kgiFK8oV0pw/Siw WCT6ri715s26xl7Lu+2pK16om8vvQBU4l6KqogU7xSvAkB0I/I7dndHqu9jI2yWb Qtv8mtfZuGdFvQdPSUX/dIwpIdPw0OhAwqkSf83RnlRQuU2yRiTLk9AS1WvQPu1D UZ49xZGkLphol9ufqvPFh+9gNGkE7cF+6IKqaeZTbQTE0RFASTHXECvncoCEKgF0 […]

Common proxy headers to look out for.

Posted by on October 3, 2012 at 11:42 am

Here is a list of all the common proxy headers I can find… They are useful if you need to log the IP behind a porxy.   CLIENT_IP FORWARDED FORWARDED_FOR FORWARDED_FOR_IP HTTP_CLIENT_IP HTTP_FORWARDED HTTP_FORWARDED_FOR HTTP_FORWARDED_FOR_IP HTTP_PC_REMOTE_ADDR HTTP_PROXY_CONNECTION HTTP_VIA HTTP_X_FORWARDED HTTP_X_FORWARDED_FOR HTTP_X_FORWARDED_FOR_IP HTTP_X_IMFORWARDS HTTP_XROXY_CONNECTION VIA X_FORWARDED X_FORWARDED_FOR Of course if you know of any, That missed please let […]

Top 10 sysadmin apps

Posted by on October 3, 2012 at 11:34 am

Right so you been running a web server for a long time now… How do you know that every thing is running right? and how do you monitor every thing?  Well here is a list of 10 Sysadmin apps every system admin should know of:   htop – This is htop, an interactive process viewer for Linux. iotop […]

How to remove X-PHP-Originating-Script

Posted by on October 3, 2012 at 11:09 am

X-PHP-Originating-Script Will show the line and script of the file witch sent the email within php.  You may want to disable this for security reasons. To do so… Just edit /etc/php5/cgi/php.ini and change the following to: mail.add_x_header = Off   While your in there change: expose_php = Off

How to setup Domain Keys (DKIM) using Debian and Postfix

Posted by on October 3, 2012 at 9:11 am

DomainKeys is an e-mail authentication system designed to verify the DNS domain of an e-mail sender thereby allowing a person, or organization to claim some responsibility for the message and helps verify that your mail is legitimate. This will help your emails not get flagged as spam or fraud, especially if you are doing bulk […]

JavaScript – SSL Strip Detector with Client Alert

Posted by on February 13, 2012 at 8:33 am

Code name: JavaScript SSL Strip Detector and Alerter. Code version: v1.0 Copyright: Copyright (C) 2012  Richard Cornwell Website: http://thegeekoftheworld.com/js-ssl-strip-detector/ Email: richard@techtoknow.net Code license: GNU General Public License v3 You can find this Script at: http://thegeekoftheworld.com/scripts/sslstripjs.txt   This code way made to protect the client for a local SSL Strip attack. Do take note this is only for the client side… not server […]