<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Auro Infotech &#187; Auro News</title>
	<atom:link href="http://blogs.auroinfotech.com/category/auro-infotech-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.auroinfotech.com</link>
	<description>Cost Effective High Quality Results On Time</description>
	<lastBuildDate>Fri, 23 Dec 2011 23:33:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Issue with Windows Server &#8211; Dec-2011</title>
		<link>http://blogs.auroinfotech.com/2011/12/22/issue-with-windows-server-dec-2011/</link>
		<comments>http://blogs.auroinfotech.com/2011/12/22/issue-with-windows-server-dec-2011/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 00:25:53 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=842</guid>
		<description><![CDATA[This post will be used to provide regular updates on the issue we are facing with one of our shared Windows servers. 24-Dec-2011 4am IST: All pending issues except the Plesk Control Panel login have been fixed. To resolve this issue, the server has to be put in maintenance mode. To minimize the downtime, we [...]]]></description>
			<content:encoded><![CDATA[<p>This post will be used to provide regular updates on the issue we are facing with one of our shared Windows servers.</p>
<p>24-Dec-2011 4am IST: All pending issues except the Plesk Control Panel login have been fixed. To resolve this issue, the server has to be put in maintenance mode. To minimize the downtime, we have asked the Plesk Parallels team to proceed with it during the day time today (Saturday early morning in Asia &#8211; Saturday midnight in Europe &#8211; Friday late night in North America). This is to minimize the inconvenience for users on the server who have not been affected by this issue. During this time, there will be interruptions due to reboot of the server. Please stand by for further updates on this.</p>
<p>&nbsp;</p>
<p>23-Dec-2011 1pm IST: The backup of all sites on the server is now completed. We are escalating this ticket now to the Plesk Parallels team so that they can investigate and fix.</p>
<p>23-Dec-2011 5.30am IST: The Data Center team has asked us to decide if to go to Plesk Parallels team to investigate this issue or to restore the server.</p>
<p>We prefer going to Plesk Parallels team as they have almost always been able to fix the issue. Though there is a possibility that the Plesk team might also advise us to do a restore, trying them before restoring gives us a chance to get the server up and running without a restore. So we have decided to use that route. Before doing that, we are starting a backup process to backup the latest data on the server, so that in case of a major issue, we can restore to this latest version of the backup.</p>
<p>23-Dec-2011 3am IST: The DC team has decided to upgrade to the latest version of Plesk to see if this fixes the issue.</p>
<p>23-Dec-2011 1am IST: The DC team is still investigating the issue.</p>
<p>22-Dec-2011 11pm IST: Data Center team is still investigating the issue. They are trying to check if Plesk was moved to use MSSQL server as the database, as it appears it automatically switched to it (we do not change the default installation of Plesk on the server.)</p>
<p>Issue: On 22-Dec-2011 at 6pm IST, we realized that some the key services (such as Plesk Control Panel, Email services) were automatically switched off and we could not start the services even as an administrator on the server. While most of the clients on the server are unaffected, six clients have reported either loss of email access or issue with logging into the control panel. After attempting to fix it manually, we escalated it to the Data Center to investigate at around 9pm IST.</p>
<p>We will continue to update the status of this issue here on this post, until the issue is resolved.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2011/12/22/issue-with-windows-server-dec-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Auro Infotech Ex-employee Jaishankar passed away</title>
		<link>http://blogs.auroinfotech.com/2011/12/12/auro-infotech-ex-employee-jaishankar-passed-away/</link>
		<comments>http://blogs.auroinfotech.com/2011/12/12/auro-infotech-ex-employee-jaishankar-passed-away/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 11:38:22 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=840</guid>
		<description><![CDATA[One of our ex-employees, Jaishankar, has passed away early this morning after fighting with cancer for quite a while. It is one of the saddest days for us at Auro Infotech as he was not only our first employee, but one of the best we could have ever. He was extremely committed and hard working, [...]]]></description>
			<content:encoded><![CDATA[<p>One of our ex-employees, Jaishankar, has passed away early this morning after fighting with cancer for quite a while.</p>
<p>It is one of the saddest days for us at Auro Infotech as he was not only our first employee, but one of the best we could have ever. He was extremely committed and hard working, and on a personal level a very humble person.</p>
<p>Jai, it was a honour knowing you and sincerely pray your soul rests in peace.</p>
<p>We offer our sincere condolences to his family and are taking steps to give them whatever support we can at this time</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2011/12/12/auro-infotech-ex-employee-jaishankar-passed-away/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upgrading to SQL Server 2008</title>
		<link>http://blogs.auroinfotech.com/2011/07/13/upgrading-to-sql-server-2008/</link>
		<comments>http://blogs.auroinfotech.com/2011/07/13/upgrading-to-sql-server-2008/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 22:43:25 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>
		<category><![CDATA[Auro Team]]></category>
		<category><![CDATA[Web Hosting]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=835</guid>
		<description><![CDATA[We are happy to announce that we are finally upgrading our Microsoft SQL Server from 2005 to 2008 this month. As you all know, we have been providing Microsoft SQL Server with our Windows Servers for many years now. As a part of the continuous upgrade strategy, we are upgrading our SQL Server database from [...]]]></description>
			<content:encoded><![CDATA[<p>We are happy to announce that we are finally upgrading our Microsoft SQL Server from 2005 to 2008 this month.</p>
<p>As you all know, we have been providing Microsoft SQL Server with our Windows Servers for many years now. As a part of the continuous upgrade strategy, we are upgrading our SQL Server database from 2005 to 2008 this month. </p>
<p>Since MS SQL Server 2008 is backward compatible with MS SQL Server 2005 version, we expect this migration to be seamless. As always, we will make sure you are well aware of the upgrade process that impacts your sites, if you use SQL Server database. We will contact you before the upgrade and also let you know about the progress as we proceed. We expect this migration to be completed before the end of the month.</p>
<p>Please feel free to email us or call us if you have any questions on the same.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2011/07/13/upgrading-to-sql-server-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 3.2 is here but is full of bugs</title>
		<link>http://blogs.auroinfotech.com/2011/07/04/wordpress-3-2-is-here-but-is-full-of-bugs/</link>
		<comments>http://blogs.auroinfotech.com/2011/07/04/wordpress-3-2-is-here-but-is-full-of-bugs/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 01:51:18 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[Open Source]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=830</guid>
		<description><![CDATA[WordPress team launched version 3.2 today to coincide with 4th July &#8211; American Independence Day. As the WordPress team has always delivered fully tested products in the past, we decided to take the plunge and upgrade to 3.2. As we started using it, we realized the Manage Links feature was fully broken and we could [...]]]></description>
			<content:encoded><![CDATA[<p>WordPress team launched version 3.2 today to coincide with 4th July &#8211; American Independence Day. As the WordPress team has always delivered fully tested products in the past, we decided to take the plunge and upgrade to 3.2.</p>
<p>As we started using it, we realized the Manage Links feature was fully broken and we could no longer add or edit or delete any links. We gave the benefit of doubt to the WordPress team, as such minor issues do happen.</p>
<p>Then as we started adding new blogs, and then when we tried adding new images, it gave a serious error that file types were not recognized or something like that. </p>
<p>Now I know for a fact that this version has not been thoroughly tested and has bugs which is not worth using right away. So if a patch is released within a day or so, we will apply it or roll back to the previous version on our blog networks.</p>
<p>If you are planning to upgrade to v3.2, I strongly recommend waiting for a few days before doing so.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2011/07/04/wordpress-3-2-is-here-but-is-full-of-bugs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New RBI Guidelines for using Paypal</title>
		<link>http://blogs.auroinfotech.com/2011/01/28/new-rbi-guidelines-for-using-paypal/</link>
		<comments>http://blogs.auroinfotech.com/2011/01/28/new-rbi-guidelines-for-using-paypal/#comments</comments>
		<pubDate>Fri, 28 Jan 2011 19:36:06 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=812</guid>
		<description><![CDATA[Just received an email from Paypal about changes coming to the account starting 1-Mar-2011 It is quite clear that the RBI wants all payments made to Indian Business Accounts via Paypal should be brought into banks in India, before they can be spent for export related expenses. This is quite an interesting move as it [...]]]></description>
			<content:encoded><![CDATA[<p>Just received an email from Paypal about changes coming to the account starting 1-Mar-2011</p>
<p>It is quite clear that the RBI wants all payments made to Indian Business Accounts via Paypal should be brought into banks in India, before they can be spent for export related expenses.</p>
<p>This is quite an interesting move as it will surely tighten the tracking of the flow of money &#8211; which has been quite difficult all these days.</p>
<p>After the confusion last year, we stopped using Paypal, but I guess it be worth giving it another chance to see if things have improved.</p>
<blockquote><p>
As part of our commitment to provide a high level of customer<br />
service, we would like to give you a 30-day advance notice on<br />
changes to our user agreement for India. </p>
<p>With effect from 1 March 2011, you are required to comply with<br />
the requirements set out in the notification of the Reserve Bank<br />
of India governing the processing and settlement of export-related<br />
receipts facilitated by online payment gateways (&#8220;RBI Guidelines&#8221;). </p>
<p>In order to comply with the RBI Guidelines, our user agreement in<br />
India will be amended for the following services as follows:</p>
<p>1. Any balance in and all future payments into your PayPal account<br />
may not be used to buy goods or services and must be transferred<br />
to your bank account in India within 7 days from the receipt of<br />
confirmation from the buyer in respect of the goods or services; and </p>
<p>2. Export-related payments for goods and services into your PayPal<br />
account may not exceed US$500 per transaction.</p>
<p>We seek your understanding as we continue to employ our best efforts<br />
to comply with the RBI Guidelines in a timely manner. </p>
<p>We regret any inconvenience caused to you and hope the advance notice<br />
will enable you to plan your future use of our services accordingly.<br />
For further information, click here </p>
<p>https://email0.paypal.com/servlet/cc6?iitHiQTBCTQWVHKupgxHmjhpgMhlLJoQJhuV2VTV20G62fGv28w9GVRRRBRATRSVa61ab9VCdaWWRTCT7YRAYUW0VGf6be862GEw05VvwvV86fy6bEvb9VCSASVwzgzgG0b9VUDWDTVXLX</p>
<p>If you have any questions, please contact PayPal customer support by<br />
logging into your PayPal account and clicking on &#8220;contact us&#8221; at the<br />
bottom of the page. We sincerely thank you for your patience and<br />
continued support.</p>
<p>Sincerely,</p>
<p>The PayPal Team</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2011/01/28/new-rbi-guidelines-for-using-paypal/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Important &#8211; 777 Permissions To Be Removed From All Servers</title>
		<link>http://blogs.auroinfotech.com/2010/10/22/important-777-permissions-to-be-removed-from-all-servers/</link>
		<comments>http://blogs.auroinfotech.com/2010/10/22/important-777-permissions-to-be-removed-from-all-servers/#comments</comments>
		<pubDate>Fri, 22 Oct 2010 11:06:16 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>
		<category><![CDATA[Auro Team]]></category>
		<category><![CDATA[Auro Technology Research Program]]></category>
		<category><![CDATA[eCommerce]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Aravind]]></category>
		<category><![CDATA[Client Notifications]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[SuPHP]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=780</guid>
		<description><![CDATA[Due to the large scale phishing attacks happening on many of our sites due to the lack of security on many of the domains, we are taking certain steps to protect our servers and the sites from such attacks. As a part of this, we are disabling 777 access to any website. To accomplish this, [...]]]></description>
			<content:encoded><![CDATA[<p>Due to the large scale phishing attacks happening on many of our sites due to the lack of security on many of the domains, we are taking certain steps to protect our servers and the sites from such attacks.</p>
<p>As a part of this, we are disabling 777 access to any website. To accomplish this, we are migrating our servers to SuPHP to secure our PHP and apache configurations. This move will make sure files cannot be written by everyone and will prevent the issue caused by the 777 permissions that were previously allowed on all files.</p>
<p>We are implementing this change in our shared servers on 30-Oct-2010.<br />
suPHP is a tool for executing PHP scripts with the permissions of their owners. With this we have following advantages in shared hosting environment</p>
<p>No folders or files can have 777 permission and it cannot be owned by user &#8220;nobody&#8221;. This is one of the greatest advantage where we can secure the files and folders in the site as none can do anything other than the site owners.</p>
<p>This change will go in at midnight on 29-Oct-2010 and as of 30-Oct-2010 we will not allow any 777 access on any of our servers.</p>
<p>Site Owner should make following in their site<br />
1. Make sure no 777 permission files or folders/directories present in the site. The recommendation is to change it to 755 for folders and 644 for files.<br />
2. .htaccess file should not contain any php_value. Please move those values under php.ini file instead.</p>
<p>Please feel free to contact us if you need any help with this.</p>
<p>Resellers please pass this is to the respective site owners.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2010/10/22/important-777-permissions-to-be-removed-from-all-servers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Site Complaints Notification Process at Auro Infotech</title>
		<link>http://blogs.auroinfotech.com/2010/09/17/site-complaints-notification-process-at-auro-infotech/</link>
		<comments>http://blogs.auroinfotech.com/2010/09/17/site-complaints-notification-process-at-auro-infotech/#comments</comments>
		<pubDate>Fri, 17 Sep 2010 10:59:00 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>
		<category><![CDATA[Web Hosting]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=771</guid>
		<description><![CDATA[In the past year or so, we have received an increasing number of website related complaints of various kinds. Some of the common categories of complaints against sites on the servers managed by us are: 1. Copyright violation notifications against sites 2. Phishing attacks originating from sites 3. Spam mails originating from sites 4. Malicious [...]]]></description>
			<content:encoded><![CDATA[<p>In the past year or so, we have received an increasing number of website related complaints of various kinds. Some of the common categories of complaints against sites on the servers managed by us are:</p>
<p>1. Copyright violation notifications against sites<br />
2. Phishing attacks originating from sites<br />
3. Spam mails originating from sites<br />
4. Malicious content such as spyware, worms, etc originating from sites<br />
5. Other types of abuse notifications about the sites</p>
<p>The process to notify these complaints is defined below:</p>
<p>1. Please send an email to support@auroinfotech.com with the following information:<br />
a. Name of the site<br />
b. Exact Link where violation occured (This is mandatory for reporting copyright violations, phishing attacks or malicious content notification)<br />
c. Short Description of the issue and the action expected to be taken<br />
d. Name and email id of the team to whom response should be sent</p>
<p>2. We will forward the notification to our clients and we always insist our clients to provide a response within 24 hours on the action taken.</p>
<p>3. If the client provides a response within 24 hours, we will pass it to you. If we do not get a response within 24 hours from our clients, we will take necessary action as per your request and update you.</p>
<p>4. Upon receiving written legal notification postal letter under Indian laws, we will provide the name and address of the clients whose servers are managed by us.</p>
<p>Please note that we manage the servers and the sites on it. We are not responsible for the content that resides on these sites, but as a professional policy, we will follow up on such complaints against sites hosted on servers managed by us.</p>
<p>On a related note, we will write separate blog posts about each of the types of complaints listed above, and the steps that can be taken by our clients to protect their sites from such violations.</p>
<p>Please feel free to contact us if you have any questions about this.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2010/09/17/site-complaints-notification-process-at-auro-infotech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blackberry using SMTP and POP3</title>
		<link>http://blogs.auroinfotech.com/2010/09/08/blackberry-using-smtp-and-pop3/</link>
		<comments>http://blogs.auroinfotech.com/2010/09/08/blackberry-using-smtp-and-pop3/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 21:45:09 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[Outlook]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=769</guid>
		<description><![CDATA[Some of our clients with hosting accounts on our servers have often asked us for details on how to connect their email accounts with their blackberry device. Since we use Blackberry heavily at Auro Infotech, we are quite comfortable with the setup of Blackberry to be used with email accounts on Auro Infotech hosted domains. [...]]]></description>
			<content:encoded><![CDATA[<p>Some of our clients with hosting accounts on our servers have often asked us for details on how to connect their email accounts with their blackberry device.</p>
<p>Since we use Blackberry heavily at Auro Infotech, we are quite comfortable with the setup of Blackberry to be used with email accounts on Auro Infotech hosted domains. This post gives details of the steps involved in setting up the same.</p>
<p><span id="more-769"></span></p>
<p>Lets assume your domain name is called yourdomain.com and your user name is username. Please make a note of the following details regarding this:</p>
<blockquote><p>Domain Name: yourdomain.com</p>
<p>SMTP Server Name: mail.yourdomain.com</p>
<p>POP3 Server Name: mail.yourdomain.com</p>
<p>user name: username@yourdomain.com</p>
<p>email id: username@yourdomain.com</p></blockquote>
<p>To configure your email account with a blackberry device, choose the option to &#8216;Integrate with Personal Email Account&#8217;. (This has to be done for any setup which is not going to use a Exchange server and since our hosting accounts do not use a Exchange server, we have to use this option).</p>
<p>Once you choose it, go to Settings &#8211; Email Setup and enter the details given above in the next set of steps.</p>
<p>btw, if you use Outlook or any other email client on your desktop, please note that setting up Blackberry device to link to your mail account does not cause any sync action with your email client on your desktop.</p>
<p>Any mail deletion on Outlook will delete the mail from the mail server but not the Blackberry device. Similarly any mail deletion on Blackberry client will delete the mail from the mail server, but not on the Blackberry device.  That will definitely be a limitation as both the Blackberry and Outlook use POP3 and SMTP to interact with the mail server.</p>
<p>We use this limitation to our advantage. When this happens, we always have a copy of mails on my Outlook, which remains locally forever. All blackberry mails are set to be deleted from the device after 30 days (If you want to save any mail longer than this, you have to open the message and &#8216;Save it&#8217; and it will then get saved permanently in &#8216;Saved Messages&#8217; on the blackberry).</p>
<p>Hope this helps.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2010/09/08/blackberry-using-smtp-and-pop3/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Server Hardening at Auro Infotech</title>
		<link>http://blogs.auroinfotech.com/2010/09/08/server-hardening-at-auro-infotech/</link>
		<comments>http://blogs.auroinfotech.com/2010/09/08/server-hardening-at-auro-infotech/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 09:26:11 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>
		<category><![CDATA[Web Hosting]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=767</guid>
		<description><![CDATA[At Auro Infotech, we always perform a task called Server Hardening which involves taking care of certain changes on the server, to make it more secure and efficient. This post explains the steps involved in the server hardening task carried out at Auro Infotech on all new servers. New server checklist &#8211; General 1. Setting [...]]]></description>
			<content:encoded><![CDATA[<p>At Auro Infotech, we always perform a task called Server Hardening which involves taking care of certain changes on the server, to make it more secure and efficient.</p>
<p>This post explains the steps involved in the server hardening task carried out at Auro Infotech on all new servers.</p>
<p><span id="more-767"></span></p>
<p><strong>New server checklist &#8211; General</strong><br />
1. Setting up hostname, add additional ip addresses<br />
2. Setting up of name servers in case of availability of control panel else add it to dnsmadeeasy.<br />
3. Setting highly complex mysql password.<br />
4. Tweaking php.ini values like increasing upload_limit, memory_limit.<br />
5. Tweaking mysql values like log-slow-queries.<br />
6. Tweaking apache values.<br />
7. Checking and installing MRTG graph.<br />
8. Creating Packages for the Accounts.<br />
9. Creating Accounts.<br />
10. Creating a test site and making it work.<br />
11. Adding Server to Monitis/Nagios for internal and external agents.<br />
12. Adding backup if the site is set up.<br />
13. Adding the server to the Systems sheet.<br />
14. Anti Virus and Spam solutions.<br />
15. DO NOT CREATE auroinfotech.com DOMAIN FOR ANY RESELLER ACCOUNTS. THIS IS CREATING ISSUES WITH EMAILS LATER.</p>
<p>Specific to LINUX servers<br />
1. Limit root access using SUDO &#8211; This will make sure no one can login to the server directly with the root username. First we should create a user for login. We are using &#8220;aiadmin&#8221; as primary login on all our servers followed by root password.</p>
<p>2. setting up highly complexity aiadmin / root password</p>
<p>3. Checked password policy inside /etc/login.defs file</p>
<p>4. Configuring Iptables (Firewall).</p>
<p>5. Anti-Virus installation &#8211; ClamAV</p>
<p>6. Apache security<br />
a) Make sure only root has read access to apache&#8217;s config and binaries<br />
chown -R root:root /usr/local/apache</p>
<p>b) Don&#8217;t allow apache to follow symbolic links</p>
<p>This can again can be done using the Options directive inside a Directory tag. Set Options to either None or -FollowSymLinks</p>
<p>Options -FollowSymLinks</p>
<p>7. Remote Access and SSH Basic Settings<br />
It is suggested to  run ssh on an alternate port other than 22 .<br />
If we want to deny users from accessing ssh , then we need to add allow and deny entry to that file.</p>
<p>8. Warning Banners<br />
This will be created under /etc/motd file</p>
<p>9. Only allow root to access CRON</p>
<p>The following commands will<br />
Establish root as the only user with permission to add cron jobs.</p>
<p>cd /etc/<br />
/bin/rm -f cron.deny at.deny<br />
echo root &gt;cron.allow<br />
echo root &gt;at.allow<br />
/bin/chown root:root cron.allow at.allow<br />
/bin/chmod 400 cron.allow at.allow</p>
<p>10. Check for security on Key files<br />
a) /etc/fstab: make sure the owner &amp; group are set to root.root and the permissions are set to 0644 (-rw-r&#8211;r&#8211;)<br />
b) verify that /etc/passwd, /etc/shadow &amp; /etc/group are all owned by &#8216;root&#8217;<br />
c) verify that permissions on /etc/passwd &amp; /etc/group are rw-r&#8211;r&#8211; (644)<br />
d) verify that permissions on /etc/shadow are r&#8212;&#8212;&#8211; (400)</p>
<p>11. Disable any unneccessary sservices.</p>
<p>Windows servers<br />
1. In windows 2003 server, We should run security configuration wizard and configure it accordingly. This will help in configuring all services and disable it if not needed.</p>
<p>2. Rename default administrator username to aiadmin</p>
<p>3. setting up high complexity password.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2010/09/08/server-hardening-at-auro-infotech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress upgradation from 2.9.2 to wordpress-3.0.1</title>
		<link>http://blogs.auroinfotech.com/2010/09/06/wordpress-upgradation-from-2-9-2-to-wordpress-3-0-1/</link>
		<comments>http://blogs.auroinfotech.com/2010/09/06/wordpress-upgradation-from-2-9-2-to-wordpress-3-0-1/#comments</comments>
		<pubDate>Mon, 06 Sep 2010 12:23:03 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Auro News]]></category>
		<category><![CDATA[Auro Team]]></category>
		<category><![CDATA[Auro Technology Research Program]]></category>
		<category><![CDATA[eCommerce]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Web Design]]></category>
		<category><![CDATA[Web Hosting]]></category>
		<category><![CDATA[Aravind]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[WordPressMU]]></category>

		<guid isPermaLink="false">http://blogs.auroinfotech.com/?p=754</guid>
		<description><![CDATA[From our previous post We have successfully upgraded our wordpressmu from 2.9.2 to 3.0.1 Here are the steps we followed for this upgradation http://wpmu.org/how-to-upgrade-wpmu-2-9-2-to-wordpress-3-0-in-5-easy-steps/ We have also upgraded all our plugins and we are happy to say that we are in WordPress-3 club. Have fun!!]]></description>
			<content:encoded><![CDATA[<p>From our <a href="http://blogs.auroinfotech.com/2010/08/18/wordpress-v-301-released/">previous post</a></p>
<p>We have successfully upgraded our wordpressmu from 2.9.2 to 3.0.1</p>
<p>Here are the steps we followed for this upgradation</p>
<p>http://wpmu.org/how-to-upgrade-wpmu-2-9-2-to-wordpress-3-0-in-5-easy-steps/</p>
<p>We have also upgraded all our plugins and we are happy to say that we are in WordPress-3 club.</p>
<p>Have fun!!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.auroinfotech.com/2010/09/06/wordpress-upgradation-from-2-9-2-to-wordpress-3-0-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

