Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Website and Server Administration Forum


You are currently viewing our Website and Server Administration Forum as a guest. Please register to participate.
Login



Reply
Old 12-02-2008, 08:00 PM VPS Question
Skilled Talker

Posts: 64
Name: Ralph Freshour
Trades: 0
I have a VPS account with several customers. One of them is trying to get PCI certified and his ASV (Approved Scanning Vendor: TrustWave) says OpenSSL is out of date and needs to be updated to the latest version. They also report that MySQL has an open port to the internet.

My questions are:

1. I thought a VPS account would allow you to install any software on your account only and not affect other accounts? My hosting provider is telling me that they cannot upgrade OpenSSL on just this one account only, that they would have to upgrade the whole server. Is this true or are they just BSing me?

2. What about MySQL? Can that be upgrade on one account only or does it have to affect the whole server?

3. Regarding TrustWaves report of having an open port in MySQL to the internet, how in the heck do they expect you to have a database if you don't have it open to your customers?

I starting think that maybe I don' really have a VPS account...it sounds like a Shared account to me but I'm not sure.
__________________
RalphF
Business Text Messaging Services

Please login or register to view this content. Registration is FREE
rfresh is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 12-02-2008, 08:32 PM Re: VPS Question
chrishirst's Avatar
Missing! presumed drunk.

Posts: 41,519
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
1/ depends on how the server hardware is segmented. But I'd be a little concerned about a server operator who won't upgrade the SSL setup in any case.

2/ Again it depends on the details.

but for both 1 & 2 IF the server is running fully isolated segments, each VPS could have different configurations of software with affecting the other segments

3/ You don't really need open ports for MySql, sites that are running on the server use localhost as the server name.
Only if you allow remote access to MySql should port 3306 be opened to the outside world, and even then access from remote system should be limited to named hosts or specific IPs.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
A foolish consistency is the hobgoblin of little minds
Thought for today:- I SEO the only industry where all the cowboys are Indians?
chrishirst is offline
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 12-02-2008, 08:51 PM Re: VPS Question
Skilled Talker

Posts: 64
Name: Ralph Freshour
Trades: 0
They said openSSL has been backwards upgraded for all known vulernabilities and they want to keep that stable version. I'm waiting to hear from my customer if he can get TrustWave to give him a wavier based on this.

I understand re the open MySQL port.

Thanks...
__________________
RalphF
Business Text Messaging Services

Please login or register to view this content. Registration is FREE
rfresh is offline
Reply With Quote
View Public Profile
 
Old 12-02-2008, 09:46 PM Re: VPS Question
Skilled Talker

Posts: 64
Name: Ralph Freshour
Trades: 0
I asked to close off the outside mysql port and they did that but now I've lost my 3rd party SQL tool access. They said they cannot close this port off for one vps account only. This doesn't sound like a VPS account to me, it sounds like a Shared hosting account.
__________________
RalphF
Business Text Messaging Services

Please login or register to view this content. Registration is FREE
rfresh is offline
Reply With Quote
View Public Profile
 
Old 12-02-2008, 10:05 PM Re: VPS Question
andrei155's Avatar
CEO of BLD Hosting

Posts: 1,514
Name: Andrei
Location: Canada
Trades: 6
Sounds like an inexperienced web host.
__________________
No Overselling Guarantee
Now Includes a Free Domain
BLD Hosting -
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
andrei155 is offline
Reply With Quote
View Public Profile Visit andrei155's homepage!
 
Old 12-03-2008, 04:11 AM Re: VPS Question
chrishirst's Avatar
Missing! presumed drunk.

Posts: 41,519
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
"backwards upgraded" Hmm? I wonder how that works.

and I'm with Andrei on this one.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
A foolish consistency is the hobgoblin of little minds
Thought for today:- I SEO the only industry where all the cowboys are Indians?
chrishirst is offline
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 12-14-2008, 02:50 AM Re: VPS Question
Average Talker

Posts: 15
Name: Scott
Trades: 0
This sounds funny to me as well.

It does depend on how the virtualization is being handled on the node as to how some software can be installed, but for the most part, installations are separate from the node on vps.
powerMonster is offline
Reply With Quote
View Public Profile
 
Old 12-14-2008, 09:30 AM Re: VPS Question
damien_ls's Avatar
Layershift

Posts: 474
Name: Damien
Trades: 0
Quote:
Originally Posted by chrishirst View Post
"backwards upgraded" Hmm? I wonder how that works.
I assume that they're refering to something like Red Hat's policy of backporting critical fixes to earlier versions, so most likely (as with most PCI DSS scanning in my experience) the scan is just looking for a version number rather than a vulnerability - in which case this will flag up as an error even though the version they're running may be perfectly safe.

As for the MySQL bit, it's complete nonsense to say that they can't firewall that for you without affecting other customers. If you're running this on a VPS (assuming that the MySQL server is also within that, rather than a shared MySQL server that you connect to for instance) it shouldn't be a problem.

Also I should mention that you could firewall MySQL for every IP except the one you connect from (assuming that you have a static IP) so it'll pass scanning, and still enable you to use remote management tools. Not entirely sure where this stands on compliance though.

Some of what they're saying could be to do with the details of the virtualisation software they're using... or they could just be a useless host (as others have suggested). What virtualisation software are they using? (e.g. Xen, Virtuozzo, VMware, OpenVZ etc.).
__________________

Please login or register to view this content. Registration is FREE
:: DDS & Dedicated, UK & USA-based
Please login or register to view this content. Registration is FREE
, Reseller & Shared Hosting
Experienced Parallels Platinum Partners (Plesk since 2001, Virtuozzo since 2003)
damien_ls is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to VPS Question
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.81708 seconds with 12 queries