TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Proactive Log Review Might Be A Good Idea

69 pointsby pcjover 12 years ago

8 comments

darkarmaniover 12 years ago
Increase his salary by 2x and demand 5x work output from him. Let him scale it up and manage his foreign workers.
malbsover 12 years ago
Pro-active log review is a good idea. No argument. I'd been incredibly lazy about log reviews on my two vps's. I started looking through the logs weekly and was incredibly freaked out by what I saw. There are almost constant attacks on the machines (obviously script kiddies), and it was just my initial setup of the linux environment that probably saved me (ssh key based auth, basic iptables, fail2ban etc). It's kind of like when I installed a security camera at the back door of my house (we'd been robbed a couple of times) - it was a pandoras box, prior to the camera going in I was under the illusion that no one ever ventured on to the property. Once the camera went in, I discovered it wasn't a rare event. Same with log reviews, once you start looking, you find attacks are common, and it's actually incredibly unnerving.<p>Web server logs are another example, once you have a publicly accessible website, you'll see thousands of requests just trolling for phpmyadmin installs, versions of php forum software, known exploitable cgi scripts. I certainly felt better about it when I was ignorant of what was going on with my servers!<p>However, the example the author provided seems a little far fetched though? Could someone seriously pull this off?<p>Seems like a house of cards that would fall down the first moment he was required to talk with a colleague about some bit of code he'd committed to source control, he'd have to be a pretty good liar.
评论 #5063967 未加载
BryantDover 12 years ago
Google cache: <a href="http://webcache.googleusercontent.com/search?q=cache:EGh4ld_KwXUJ:securityblog.verizonbusiness.com/2013/01/14/case-study-pro-active-log-review-might-be-a-good-idea/+http://securityblog.verizonbusiness.com/2013/01/14/case-study-pro-active-log-review-might-be-a-good-idea/&#38;cd=1&#38;hl=en&#38;ct=clnk&#38;gl=us" rel="nofollow">http://webcache.googleusercontent.com/search?q=cache:EGh4ld_...</a>
评论 #5064550 未加载
chmarsover 12 years ago
I bet 'Bob' read the 'The 4-Hour Workweek'. His only problem was that he still had to spend time in the office … for Chinese contractors, this story is of course a great free ad.
sachingulayaover 12 years ago
If it wasn't a critical infrastructure company they should've moved him to HR and had him outsource all their coding ;D
schrodingerover 12 years ago
If he's getting everything done to the extent that he's getting great performance reviews, what's the problem?
评论 #5065291 未加载
kylemaxwellover 12 years ago
Site should be working again. Now I know what slashdotting feels like. Sorry, everybody!
评论 #5065403 未加载
marsover 12 years ago
well done, pal. although he must be bored to death riding his chair into the future.