Saturday, December 27, 2008

This blog has been shifted to amolbharti.com

Thanks for visiting codergeek82's blog. This blog is being shifted to amolbharti.com

Labels: , , , , , , ,

Thursday, September 28, 2006

Couldn’t make it to IIT Delhi "Rendezvous" with FLIRT

Sorry (FLIRT) I couldn’t make it to IIT Delhi "Rendezvous" as my Manager did not approve my leave but I arranged my replacement so that you guys don’t fall short of a dancer.   Aseem and Mani you guys Rock man as always.. I knew this time you will make our dream into reality and you guys did it. I literally don’t have words to express my joy. So once again congratulations to all of us for this fantastic win at IIT Delhi "Rendezvous".

Undoubtedly, This is the most cheerful, enjoyable, and happening time in India and I want to be a part of this Nirvana. I am eagerly waiting for Diwali, which is one of the most significant and most celebrated Hindu Festivals in India. Diwali Festival in India is regarded as the 'Festival of Lights'. The illumination on Diwali signifies end of darkness which stands for ignorance and beginning of knowledge symbolized by lights that shall enlighten all. So am back on track... You guys keep hollering me, don't forget to ping me time to time, so that I keep realizing my friends around.

Wednesday, July 19, 2006

What to do before your website gets Hacked

It feels like the world's on your shoulders when you are responsible for setting up and managing a large community portal or a website. Being the administrator of the website you have access to user's data including credentials and full control of their accounts but it is up to you, how honest and responsible you are. Not only you have to terminate the bad side of yourself but also you have to fight with the wild wild world outside waiting to screw you and your website. Always remember, You are responsible if your website ever get's hacked, Never go to the community with lame excuses. So better do something before your website get's hacked.

I am the administrator of ietBugs.com and the owner of almost a dozen other websites, My objective is to always keep the data secure and maintain a high standard of anti hacking policies making the best use of the technology. I care for the private data like user account credentials associated with the registered users, that is why I learned how to be a Hacker to Hackers. Before you think about how to safeguard your website or applications from hackers you need to think like a wildest hacker. So here are a few things am gonna teach you, that I learn with experience in over a few years.

First off, store an entire set of working files locally. This should be a set of files that has never been off your computer so that you know that they have not been tampered with. Edit them locally, when you need to, and then upload them to your webspace, either through the file manager in your cpanel or with ftp, sftp, ssh, or something similar. You don't have to upload the entire set each time, just the modified files.

Some people edit their files live on the server. If you do this you will not have a current local copy. If you download the file(s) from your server, you do not know for certain that they have not been modified by a hacker. ALWAYS edit your local files and upload them to the server, not the other way around.

It wouldn't be a bad idea to get XAMPP (from Apache Friends) and develop locally as well but that's beyond the scope of this post.

Before installing a new mod, make a copy of the entire local directory and datestamp it (rename the directory copy to indicate the date). That way if anything goes wrong, you can revert to the old copy. It is a good idea to keep a couple of these snapshots (backups taken at different times) around just to be safe.

Now, if your site ever gets hacked it is easy to fix. Go to your webspace and delete all the files associated with your site. Use some common sense though. There may be other folders such as for cgi, logs, statistics, etc that you might want to keep. (They should not be in a web accessible location anyway but that's another issue). Once you have deleted your website from the server, upload the entire fileset from your local computer. Now, your website should be back to where it was before you got hacked. That should be a fairly quick and painless recovery process.Do not upload your files over the existing files. You must delete everything first. Otherwise you will not remove any new files or folders that were added by the hacker.
That is step one: Preparing to recover from an attack.

Step two is protecting against an attack in the first place.

Most important.. Set the permissions correctly! The documentation states that you should set the permissions on a few folders to 777. That is fine if you want to be hacked. If you follow those instructions, you WILL be hacked, it's just a matter of time.

Set the permissions on ALL folders to 755. If your host has PHP installed as CGI through phpSuExec (the proper method), then your site will run fine this way. If they have PHP installed as a module, you will get a warning from oscommerce saying that it is unable to write to the images folder. Setting permissions back to 777 will make the message go away but it will leave you open to an attack. Contact your host and ask them if they could change the way in which they install PHP. If they will not, you should immediately get a new host. This isn't an arbitrary statement. By installing PHP the wrong way, they have created a security vulnerability that you will not be unable to resolve. A partial work-around is to upload images via file manager in cpanel or through ftp. A less secure method is to set the permissions on the images folder to 777 just long enough to add your new products and then set it back to 755. This work-around does not, however, deal with the permissions issues on a couple of other folders. Loading PHP in the correct manner is the only fix.

Set the permissions on all files to 644, with two exceptions. There are two configure.php files. One is located in /catalog/includes/ the other is in /catalog/admin/includes/. The permissions on these two files should be 400, 444, or 644 dependent on your server configuration. Use the lowest setting that will still allow your store to function and that your host's setup allows you to set.

If you have trouble setting permissions on files or folders through ftp, try the file manager in cpanel instead. Some hosts don't allow ftp to change permissions.
The admin folder requires a password (in the latest version of osc). This method of password protection is not secure. A hacker could run a password cracker program against it and try thousands of passwords a second until they get in. Use the feature in cpanel to password protect your admin directory. When a hacker runs a password cracker program against this, the system will be notified after a set number of attempts and the hacker's IP will be automatically banned from the system (on a properly configured server. It wouldn't hurt to check this with your host).

Renaming your admin folder to something obscure (a 12+ character long string of random letters and numbers would be best) makes it even more difficult for hackers since they won't even know where your admin folder is now. You will have to modify your configure.php files to point to the newly renamed admin directory. Be sure that you do not list the new name in any other files (like robots.txt) as this will give the name away.

Lastly, install the following security mods:
Security Pro
Sitemonitor
IP Trap
.htaccess Protection
Anti-XSS

With all of those changes made, it is very unlikely that you will be hacked. There are always other methods of attack and some can only be prevented by making changes to the server configuration (which is out of your control). Keep in mind that shared-host accounts have more security issues than dedicated accounts and that "cheap" accounts are just that; don't expect that a cheap account is managed by competent or conscientious people.

Lastly, make sure that your admin settings for file-based sessions and cache (if you use either), do not use the /tmp folder if you are on a shared-host account. On most systems, the /tmp folder is a symlink to a shared system folder that all the other accounts on that shared-host also use. Not only can this potentially cause problems but it can be a security leak, sharing customer data through this shared folderHope that helps.

Good luck!
codergeek82 Hacker to Hackers !

Thursday, July 13, 2006

College days were the best days of my Life !

Undoubtedly, College days were the best days of my Life ! Yeah, I miss the time and those moments I spent with hell a lot of friends. I miss my class, my , my Break dance and Dandia group (Mani, Aseem, Saurav, Sobi, Abhi, Shifali, Gaurav, Rahul, bhawna, Karishma, Aditi) I miss some friends who were close but lost some where in the darkness and never turned back. (Aastha, Natasha, Mehak, Richa, Tavleen, Ishu, Bhupinder, Gurminder, Ashwani, Amanjeet, Sandeep) I miss my Coach/Sports Teacher "Mr. Pathania" who was more like a friend to me. Only because of his support I qualified for North Zone inter University Badminton Championship last year and begged College Color Award in year 2006. Our team secured second and third positions for Bhaddal in inter college badminton tournaments for three consecutive years.

I miss the Canteen, Fruit shop, net labs where i spent un-counted hours of my life. I miss those nights i spent in hostel preparing for break dance events with Aseem, Mani, Saurabh, Sobi and Abhi. I miss Lover's Teela no. 1/2 , I miss some really nice beauties, who helped me out in assignment copying. I miss each and every tile of I.E.T Bhaddal. Those were the best days of my life

"I don’t know how these past few years flew,
But one thing is true,
And I say this with a lot of pain.
Things are never gonna be the same again.
I’m gonna miss rushing to class at 9,
And trying to eat in class without being seen.
I’m gonna miss talking to you friends everyday,
And the jokes and the pranks that we did play.
I’m gonna miss hanging out with you guys,
especially the treats, So many of us sitting around in the seats,
Talking away to glory, And each telling many a story.
I’m gonna miss the fun when we were trekking,
With so many dark tunnels and even the bridges creaking,

I’m also gonna miss the lecturers,
Who more than often bored us
But we still had so much fun in the class,
We never could realize how the time did pass. I’m gonna miss sitting on the Lover's Teela No. 2
Making fun of each other and lol

I’m gonna miss that carefree life
It cuts like a knife, but no, it doesn’t feel so right.
I may not be a good poet but I had this much to say,
Let us not forget each other after today.
I wish this college life never ends,
Life is so great with all of you, my friends."


Codergeek82

Hellossss theressss !

The flatterer gets flattened when the eyes and ears his words are meant for come back to him chaotic and disposed of. Sometimes you think writing a fancy sounding sentence about someone will be the end to your problems when in fact, it may very well be the beginning. "I miss you's" and "you're beautiful's" are taken with grains of salt as if I wrote/said the words just so I'd have something to say, or with malice as if this was all an overly dramatic way to make you miss me back(tough luck). But what I actually meant was I want to be with you so badly that the insides of my bones hurt.

This tiny keyboard will only let me type heart.

Amu

Wednesday, July 12, 2006

Phew - World Cup is Over!

So, before I get into everything else about this last weekend, let me just say - phew, the World Cup is over. I'm not big into football, but what happened to Zidane? How could he have been so stupid as to end his career like that? I just couldn't believe it . But it's over for another four years...
check out this video haha do you think am nutts, no so watch original

Any way soon Cricket World Cup going to be the next big thing for all of us..