Book Mark

Ike.ninja

Linux Fun
  • Home
  • How to
  • Reference Links
  • Categories
    • Releases
    • Plesk
    • Community
    • CMS
    • security
    • MYSQL
    • cPanel
  • Tools
    • IP Checker
    • Byte Converter
RSS

Red Hat: 2014:1365-01: kernel: Important Advisory

Oct13
by Ike on October 13, 2014 at 10:05 am
Posted In: Other

(Oct 7) Updated kernel packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 6.4 Extended Update Support. Red Hat Product Security has rated this update as having Important security [More…]

└ Tags: Important Advisory, Red Hat, security, update
 Comment 

Red Hat: 2014:1371-01: nss: Important Advisory

Oct13
by Ike on October 13, 2014 at 10:05 am
Posted In: Other

(Oct 10) Updated nss packages that fix one security issue are now available for Red Hat Enterprise Linux 4 Extended Life Cycle Support, Red Hat Enterprise Linux 5.6 Long Life, Red Hat Enterprise Linux 5.9 Extended Update Support, Red Hat Enterprise Linux 6.2 Advanced Update Support, and Red Hat [More…]

└ Tags: Important Advisory, Red Hat, security
 Comment 

Joomla Community Magazine | October 2014

Oct10
by Ike on October 10, 2014 at 11:00 pm
Posted In: CMS, Community, General News, Joomla, Releases

JCM October 2014

The October issue of the Joomla Community Magazine is here! Our stories this month:

Editors Introduction

Joomla! World Conference 2014, Get Your Tickets Now!

Feature Stories

Interview with Brian Teeman
A New and Improved Joomla! Resources Directory
A Dream, Which we Dream Together, is Reality

Events

Upcoming Joomla Events October/November 2014

Project News

Leadership Highlights October 2014
A Thank You to OSM & the Joomla Community from CloudAccess.net
A Thank You to CloudAccess.net

Administrators

Investing in HTTPS is Crucial to Your Joomla Site’s Integrity

International Stories

Catalan

Open Source Matters tria nova presidenta, Sarah Watz…
Actualitzar Joomla! de la versió 2.5 a la 3.x

Français

Retour sur le JoomlaDay™ Bénin 2014
La création d’un article avec Joomla! n’a jamais été aussi facile !
Joomla! World Conference 2014, achetez vos billets maintenant !
Joomla! pour mon entreprise (partie 1)
Revenons aux fondamentaux : la puissance du collaboratif
Annonce de la création du Update Working Group
Joomla! annonce un nouveau site de démo et une option…

German

Der neue Joomla! Release Zyklus

Spanish

Premios y reconocimientos del CMS Joomla!
ACL en Joomla!
Desenredando Warp 7 y UIKIT
Un Nuevo Directorio de Recursos
Joomla! en La Rioja

In our next issue

We want to publish your Joomla! story in the next JCM issue! So take a look at our Author Resources content to get a better idea of what we are looking for, and then register to become a JCM author and submit your Joomla! story!

└ Tags: Editors Introduction, Events, General News, International Stories, Project News
 Comment 

October 2014 Web Server Survey

Oct10
by Ike on October 10, 2014 at 10:25 am
Posted In: Web Server Survey

In the October 2014 survey we received responses from 1,028,932,208 sites,
which is nearly six million more than last month.

Apache regains the lead

Microsoft lost the lead to Apache this month, as the two giants continue to battle closely for the largest
share of all websites. Apache gained nearly 30 million sites, while Microsoft lost 22 million, causing Apache to be thrust back into
the lead by more than 36 million sites. In total, 385 million sites are now powered by Apache, giving it a
37.45% share of the market.

A significant contributor to this change was the expiry of domains previously used for link farming on Microsoft IIS servers. The domains used by these link farms were acquired and the sites are now hosted on Apache servers at Confluence-Networks, which display Network Solutions parking notices.

A new major release in the Apache 2.2 legacy branch was announced on 3 September. Apache 2.2.29
also incorporates many changes — including several security fixes — from version
2.2.28, which was not officially released.
New versions of nginx stable and
mainline were also released during September,
which included fixes for an SSL session reuse vulnerability, plus several other bugfixes.

Top million sites

The million busiest websites now represent less than 0.1% of all websites in the survey, but provide an insight into the preferences amongst the sites which are responsible for the great majority of today’s web traffic.

Just over half (50.2%) of the top million sites use Apache, which is very similar to its
share amongst all active sites; however, nginx’s market share is skewed noticeably higher amongst the top million
sites, where it powers 20.3% of sites, compared with only 14.3% of all active sites.

Computer growth

The most stable metric is the market share of web-facing computers — hundreds of thousands of websites can easily be served from a single computer (and subsequently disappear all in one go) but it is obviously far less trivial and less desirable to deploy or decommission a significant number of computers. Netcraft’s survey is also able to identify distinct computers which use multiple web-facing IP addresses, which adds further stability.

Apache leads in this market with a 47.5% share, and Microsoft also performs well with 30.7%, but both have been gradually falling over the past few years as a result of nginx’s strong growth. nginx gained more than 17,000 additional web-facing computers this month, helping to bring its market share up to 10.3%.

New top level domains

The relatively new .xyz domain, which showed tremendous growth over the past couple of months, has started to flatten out slightly after gaining only 33,000 sites this month (+8%). Nonetheless, this is still quite a healthy gain, albeit notably less than last month’s growth of 177,000 hostnames which then boosted its total by 78%.

Other promising TLDs include .london, .hamburg and .公司,
each of which had fewer than 50 sites in last month’s survey, but now have 17,000, 11,000 and 10,000
sites respectively.

The internationalised .公司 (.xn--55qx5d) TLD is delegated to the Computer Network Information Center of Chinese
Academy of Sciences. It means “company”, making it the Chinese equivalent of .com.

Total number of websites

Web server market share

Developer September 2014 Percent October 2014 Percent Change
Apache 355,925,985 34.79% 385,354,994 37.45% 2.66
Microsoft 371,406,909 36.31% 345,485,419 33.58% -2.73
nginx 144,717,670 14.15% 148,330,190 14.42% 0.27
Google 19,499,154 1.91% 19,431,026 1.89% -0.02

Web server market share for active sites

Developer September 2014 Percent October 2014 Percent Change
Apache 90,229,153 50.74% 90,599,505 50.85% 0.11
nginx 25,865,132 14.54% 25,588,943 14.36% -0.18
Microsoft 21,122,925 11.88% 21,700,874 12.18% 0.30
Google 13,737,537 7.73% 13,692,124 7.68% -0.04

For more information see Active Sites

Web server market share for top million busiest sites

Developer September 2014 Percent October 2014 Percent Change
Apache 504,816 50.48% 501,922 50.19% -0.29
nginx 200,526 20.05% 203,439 20.34% 0.29
Microsoft 125,513 12.55% 125,235 12.52% -0.03
Google 26,740 2.67% 26,302 2.63% -0.04
Web server market share for computers

Developer September 2014 Percent October 2014 Percent Change
Apache 2,339,250 47.65% 2,360,061 47.47% -0.18
Microsoft 1,516,088 30.88% 1,525,278 30.68% -0.20
nginx 496,417 10.11% 513,961 10.34% 0.23
└ Tags: Apache, Confluence Networks, Network Solutions, TLD, Web Server Survey
 Comment 

Phishing with data: URIs

Oct09
by Ike on October 9, 2014 at 1:00 pm
Posted In: security

A recent spate of phishing attacks has taken to using the data URI scheme for evil.
Supported in most browsers, these special URIs allow the content of a phishing page
to be contained entirely within the URI itself, effectively eliminating the need
to host the page on a remote web server and adding an additional layer of indirection.

One of these attacks is demonstrated below, where a phishing campaign was used
to herd victims to a compromised site in the US, which then redirected them to a Base64-encoded
data URI. This particular example impersonates Google Docs in an attempt to steal email addresses and
passwords from Yahoo, Gmail, Hotmail, and AOL customers.

Google Docs phishing site using data: URI

All of the attacks use Base64-encoded data URIs, rather than human-readable plain text, making it
harder for people, simple firewalls and other content filters to detect the malicious content.

Most phishing sites are
hosted on
compromised websites,
but can also be seen using purpose-bought domain names and bulletproof hosting packages that
have been paid for fraudulently. However, fraudsters can take advantage of open redirect
vulnerabilities to “host” these malicious data URIs without the need for conventional web hosting.

This situation is ideal for scenarios
such as malware delivery and social engineering attacks where no subsequent client-server interaction
is required, but phishing sites still need some way of transmitting their victim’s credentials to the fraudster.
Most phishing attacks that use data URIs resort to the traditional method of transmitting stolen credentials, i.e. POSTing them to a script on a remote web server. However, with no obvious phishing content being hosted on the remote web server, such scripts could be more difficult for third parties to take down; and as long as they remain functional, each one can continue to be used by any number of data URI attacks.

Another interesting example which impersonated an eBay login page is shown below.
If a victim is unfortunate enough
to fall for this particular phishing attack, his credentials will be transmitted to a PHP script hosted on a compromised web server in Germany.

eBay phishing site using a data: URI

This demonstrates an interesting deficiency in Google Chrome: If the
data URI is longer than 100,000 characters, then none of the Base64-encoded data within the URI
will be displayed in the address bar. Rather than truncating the URI, Chrome’s address bar will only display the string “data:”.

This behaviour could make it more difficult for wary victims to
report such attacks. Although the victim is viewing an eBay
phishing page, if he tries to copy the URI from the address bar in Chrome,
the clipboard will still only contain the string “data:”.

The Netcraft Extension provides protection against the redirects used in the phishing attacks above, and Netcraft’s open redirect detection service
can be used to identify website vulnerabilities which would allow fraudsters to easily redirect victims to
similar phishing content.

└ Tags: AOL, Google Docs, security, URI, US
 Comment 
  • Page 2,361 of 2,975
  • « First
  • «
  • 2,359
  • 2,360
  • 2,361
  • 2,362
  • 2,363
  • »
  • Last »

What’s New?

  • Fedora 41: Apptainer CVE-2025-65105 Security Fix Advisory
  • Fedora 43: Apptainer 1.4.5 Important Fix CVE-2025-65105
  • Ubuntu 18.04: USN-7907-5 Linux Kernel Important Security Flaws
  • Debian: Chromium Important DSA-6080-1 Code Exec DoS Issues
  • Fedora 42: SingularityCE Important Upgrade 4.3.5 – FEDORA-2025-54d78b9fed
  • Fedora 43: perl-Alien-Brotli Critical Security DoS Fix 2025-d93200cf16
  • Fedora 42: Wireshark 4.6.1 Critical Issue Advisory – FEDORA-2025-f810869906
  • Fedora 42: yarnpkg Command Injection Fix CVE-2025-64756 Advisory
  • Ubuntu 25.10: Linux Kernel Critical Flaws Security Patch USN-7906-3
  • Ubuntu 22.04: USN-7889-6 Linux Kernel Important Security Patch
  • Ubuntu 22.04 LTS: Linux Kernel Critical Security Issues USN-7928-3
  • Ubuntu 22.04: 7928-2 Linux Kernel FIPS Security Updates
  • Ubuntu 22.04 LTS: USN-7928-1 Linux Kernel Critical Security Issues
  • Debian: Important DoS Vulnerabilities in FFmpeg DSA-6080-1 Advisory
  • Ubuntu 20.04 LTS: USN-7922-1 Linux Kernel Important Security Issues
  • Ubuntu 24.04 LTS: Kernel Important Security Fixes USN-7921-1 CVE-2025-39946
  • Debian: firefox-esr Critical Privilege Escalation DSA-6078-1 CVE-2025-14321
  • 2026 Global Partner Program Announcement
  • Debian: pdns-recursor Critical Denial of Service Vulnerability DSA-6077-1
  • Debian: libpng1.6 Critical Info Leak & DoS Vulnerabilities DSA-6076-1
  • Fedora 43: python3-docs Update 2025-e235793f10 – Maintenance Release
  • Fedora 43: python3.14 Critical Update Addresses Quadratic Complexity Bug
  • Debian: WordPress Important XSS and Info Disclosure DSA-6075-1
  • Ubuntu 22.04 LTS: fontTools Important Path Traversal Risk CVE-2025-66034
  • Debian: webkit2gtk Critical Info Exfiltration DSA-6074-1 CVE-2025-13947

Search

Translator

Tags

Business and industry code Community cPanel CVE Debian Debian Linux Distribution - Security Advisories Development Events Fedora Fedora Linux Distribution - Security Advisories General Hosting Important Advisory Linux Moderate Advisory Month in WordPress news Parallels Plesk Parallels Plesk Panel Performance PHP Plesk news and announcements Plesk Panel Podcast ProdDevSec Product and technology Products Project Release News Red Hat Red Hat Linux Distribution - Security Advisories Releases security Security Centre sensitive site Ubuntu Ubuntu Linux Distribution - Security Advisories update updates Various vulnerability Web Server Survey Wordpress wp-briefing

Posts

Helpful Links

  • Liquidweb.com
  • MYSQL Dev Documentation
  • Plugins
  • Source forge SED command
  • Themes
  • WordPress Documentation
  • You Tube
December 2025
M T W T F S S
« Nov    
1234567
891011121314
15161718192021
22232425262728
293031  
  • Google
  • Yahoo
  • Liquid Web
  • Storm
  • YouTube

©1999-2025 Ike.ninja | Powered by WordPress with Easel | Subscribe: RSS | Back to Top ↑

53 queries. 8.5 mb Memory usage. 0.390 seconds.