OK folks...I'm fairly satisfied with the state of things after the site migration/server upgrade. Now, comes another fun change...
I mentioned in another thread, that migrating to different software for the C-Brats was something I'm looking into. There are many reasons for this, but one of the primary issues I'm trying to address is security. phpBB, the software we use here, has a questionable track record in this area.
Unfortunately, switching to something better won't happen any time soon. In the mean time, I need to configure some server-side protection, that is more universal in nature. Essentially, it scans and blocks hacking attempts by "signature". Think of it as virus scanning on the C-Brat server; it actively looks at incoming requests, and blocks things that look suspicious.
The problem is, there's a balance to be found in setting how aggressive the scanning rules are. If I set them too lax, attackers can still get in. If I set them too strict, I may inadvertently disable some normal site function.
So...let this note be a heads up. I'll do my best to configure things so as not to disrupt any normal activity here, but I'm depending on all of you to reply here if you see something out of the ordinary - I can't possibly test every single function of the site.
I'll be dropping the security module in place tonight (Saturday), and will follow up here once done.
Thanks,
Bill
I mentioned in another thread, that migrating to different software for the C-Brats was something I'm looking into. There are many reasons for this, but one of the primary issues I'm trying to address is security. phpBB, the software we use here, has a questionable track record in this area.
Unfortunately, switching to something better won't happen any time soon. In the mean time, I need to configure some server-side protection, that is more universal in nature. Essentially, it scans and blocks hacking attempts by "signature". Think of it as virus scanning on the C-Brat server; it actively looks at incoming requests, and blocks things that look suspicious.
The problem is, there's a balance to be found in setting how aggressive the scanning rules are. If I set them too lax, attackers can still get in. If I set them too strict, I may inadvertently disable some normal site function.
So...let this note be a heads up. I'll do my best to configure things so as not to disrupt any normal activity here, but I'm depending on all of you to reply here if you see something out of the ordinary - I can't possibly test every single function of the site.
I'll be dropping the security module in place tonight (Saturday), and will follow up here once done.
Thanks,
Bill