Likes Likes:  0
Resultaten 1 tot 4 van de 4
Geen
  1. #1
    ConfigServer eXploit Scanner (cxs)
    administrator
    21.459 Berichten
    Ingeschreven
    17/12/01

    Locatie
    Amsterdam

    Post Thanks / Like
    Mentioned
    71 Post(s)
    Tagged
    0 Thread(s)
    590 Berichten zijn liked


    Naam: Domenico Consoli
    Bedrijf: Webhostingtalk.nl
    Functie: Oprichter
    URL: webhostingtalk.nl
    Registrar SIDN: Ja
    KvK nummer: 51327317
    TrustCloud: domenico
    View domenicoconsoli's profile on LinkedIn

    Thread Starter

    ConfigServer eXploit Scanner (cxs)

    Vooral cPanel gebruikers kennen allemaal wel de respectabele producten csf en lfd maar nu is er dan ook de ConfigServer eXploit Scanner kortweg csx genaamd.

    http://www.configserver.com/cp/cxs.html
    ConfigServer eXploit Scanner (cxs) is a new tool from us that performs active scanning of files as they are uploaded to the server.

    Active scanning is performed on all text files uploaded through:

    •PHP upload scripts (via a mod_security or suhosin hook)
    •Perl upload scripts (via a mod_security hook)
    •CGI upload scripts (via a mod_security hook)
    •Any other script type that utilizes the HTML form ENCTYPE multipart/form-data (via a mod_security hook)

    •Pure-ftpd

    The active scanning of uploaded files can help prevent exploitation of an account by malware by deleting or moving suspicious files to quarantine before they become active. This includes recent exploits such as the Dark Mailer spamming script and the Gumblar Virus.

    cxs also allows you to perform on-demand scanning of files, directories and user accounts for suspected exploits, viruses and suspicious resources (files, directories, symlinks, sockets). It has been tuned for performance and scalability.

    Exploit detection includes:

    •Over 4500 known exploit scripts fingerprint matching
    •Known viruses via ClamAV
    •Regular expression pattern matching to help identify unknown exploits
    •Filename matching
    •Suspicious file names
    •Suspicious file types
    •Binary exeuctables
    •... and more!
    Included with the cxs Command Line Interface (CLI) is a web-based User Interface (UI) to help:

    •Run scans
    •Schedule and Edit scans via CRON
    •Compose CLI scan commands
    •View, Delete and Restore files from Quarantine
    •View documentation
    •Set and Edit default values for scans
    •Edit commonly used cxs files
    Note: cxs is not a rootkit scanner, though it can help detect rootkits uploaded to user accounts.
    Wat denken jullie hiervan? Heeft het potentie en kan het zinvol zijn? Zijn er al mensen die het op hun server hebben draaien?

  2. #2
    ConfigServer eXploit Scanner (cxs)
    moderator
    8.233 Berichten
    Ingeschreven
    29/03/03

    Post Thanks / Like
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)
    266 Berichten zijn liked


    Naam: Ron
    Ondernemingsnummer: nvt

    Jammer dat het CSF nodig heeft, zodat de *BSD varianten er geen gebruik van kunnen maken. IPtables op een BSD server is nog altijd knap lastig

  3. #3
    ConfigServer eXploit Scanner (cxs)
    moderator
    8.233 Berichten
    Ingeschreven
    29/03/03

    Post Thanks / Like
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)
    266 Berichten zijn liked


    Naam: Ron
    Ondernemingsnummer: nvt

    Bovenstaande is niet geheel correct: IPtables/csf is geen harde eis:
    csf is only needed if you want to block IP addresses of connections uploading suspected exploits via pure-ftpd.
    En:
    I'm going to look into adding FreeBSD support to cxs. I've built a test
    environment and it will install on a cPanel server and CLI scanning does
    work, but the integration with pure-ftpd doesn't as yet. Hopefully I'll
    have it fully working in the next few days, time permitting.

  4. #4
    ConfigServer eXploit Scanner (cxs)
    geregistreerd gebruiker
    6.041 Berichten
    Ingeschreven
    23/10/04

    Locatie
    Amersfoort

    Post Thanks / Like
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    171 Berichten zijn liked


    Functie: Freelance IT Professional
    URL: localhost
    View randytenhave's profile on LinkedIn

    Ik gebruik het Turtle pakket op Plesk servers met managed spulletjes. Dacht dat er meer mensen zijn, o.a. Berrie die dit hebben. Het scheelt je al een hoop zaken bijwerken, met name signatures voor ClamAV en mod_security. Ben benieuwd of dit wat is. Zal hem eens proberen op een testdoosje. Even een Cpanel testlicentie regelen.
    Hoop wel dat er snel een DA port komt. Met CSF heb ik goede ervaringen, al is de default template met settings verre van goed tenzij je voor iedere scheet een warming wil hebben per e-mail .
    MultiMaak - Voor persoonlijke cadeau's en relatiegeschenken!

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics