TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Proactive Log Review Might Be A Good Idea

69 点作者 pcj超过 12 年前

8 条评论

darkarmani超过 12 年前
Increase his salary by 2x and demand 5x work output from him. Let him scale it up and manage his foreign workers.
malbs超过 12 年前
Pro-active log review is a good idea. No argument. I'd been incredibly lazy about log reviews on my two vps's. I started looking through the logs weekly and was incredibly freaked out by what I saw. There are almost constant attacks on the machines (obviously script kiddies), and it was just my initial setup of the linux environment that probably saved me (ssh key based auth, basic iptables, fail2ban etc). It's kind of like when I installed a security camera at the back door of my house (we'd been robbed a couple of times) - it was a pandoras box, prior to the camera going in I was under the illusion that no one ever ventured on to the property. Once the camera went in, I discovered it wasn't a rare event. Same with log reviews, once you start looking, you find attacks are common, and it's actually incredibly unnerving.<p>Web server logs are another example, once you have a publicly accessible website, you'll see thousands of requests just trolling for phpmyadmin installs, versions of php forum software, known exploitable cgi scripts. I certainly felt better about it when I was ignorant of what was going on with my servers!<p>However, the example the author provided seems a little far fetched though? Could someone seriously pull this off?<p>Seems like a house of cards that would fall down the first moment he was required to talk with a colleague about some bit of code he'd committed to source control, he'd have to be a pretty good liar.
评论 #5063967 未加载
BryantD超过 12 年前
Google cache: <a href="http://webcache.googleusercontent.com/search?q=cache:EGh4ld_KwXUJ:securityblog.verizonbusiness.com/2013/01/14/case-study-pro-active-log-review-might-be-a-good-idea/+http://securityblog.verizonbusiness.com/2013/01/14/case-study-pro-active-log-review-might-be-a-good-idea/&#38;cd=1&#38;hl=en&#38;ct=clnk&#38;gl=us" rel="nofollow">http://webcache.googleusercontent.com/search?q=cache:EGh4ld_...</a>
评论 #5064550 未加载
chmars超过 12 年前
I bet 'Bob' read the 'The 4-Hour Workweek'. His only problem was that he still had to spend time in the office … for Chinese contractors, this story is of course a great free ad.
sachingulaya超过 12 年前
If it wasn't a critical infrastructure company they should've moved him to HR and had him outsource all their coding ;D
schrodinger超过 12 年前
If he's getting everything done to the extent that he's getting great performance reviews, what's the problem?
评论 #5065291 未加载
kylemaxwell超过 12 年前
Site should be working again. Now I know what slashdotting feels like. Sorry, everybody!
评论 #5065403 未加载
mars超过 12 年前
well done, pal. although he must be bored to death riding his chair into the future.