SERVER MAINTENANCE: 24th May – 30th May 2009
Dear Just X-Cart client,
As part of our server maintenance, we will be performing a range of upgrades and security checks on your server in the next few days. There are a range of changes and enhancements so I will explain them individually. These include:
KERNEL UPGRADE
The kernel on your server will be upgraded this week and a reboot will be scheduled for 10pm AEST on Saturday 30th May to apply the kernel. The reboot should only take a few minutes to perform.
APACHE/PHP UPGRADE-SECURITY ENHANCEMENT
Apache and PHP will be upgraded on all servers that are currently running older versions to Apache 2.2.11 and PHP 5.2.9, some security adjustments to Apache and PHP will be made, including the introduction of Suhosin, a PHP hardening module to the server. Most changes should cause no effect to client sites however there could possibly be a few sites with older scripts etc that may require adjustment. If anyone has any issues please contact us immediately.
SUHOSIN – HARDENED PHP
Suhosin is an advanced protection system for PHP installations. It is designed to protect servers and users from known and unknown flaws in PHP applications and the PHP core and on our cPanel servers will tie directly into the Firewall system to block offending users illegally accessing scripts on the server.
We have a well developed ruleset that we have been running and testing on our cPanel hosting servers for some time now and we believe the settings we will be applying will cause no issues to any clients, however if any issues please open a ticket at the helpdesk.
EMAIL SPAM ENHANCEMENTS
In a bid to reduce spam and to enhance email security cPanel has introduced SPF records and Domain Keys to the mail system and we strongly advise all clients to login to cPanel and enable these functions. Details about SPF records can be found at http://www.openspf.org and information on Domain Keys at http://www.dkim.org.
Clients can access and enable these functions by clicking on the Email Authentication link in their email hosting cPanel (X-Mail). See your ‘Welcome email’ for email hosting console link and your username and password.
FTP SECURITY
We have found an increasing amount of websites, in particular insecure PHP websites, being infected with Javascript and other related worms, trojans and hack attempts. A lot of these are caused by insecure scripts, which should be checked and upgraded or secured where possible, however an increasing amount of people are having these sorts of hacks caused via insecure FTP connections.
We strongly advise clients to either set their FTP programs to use secure FTP (FTPS) which is accessible on port or to use SFTP on port 22351 to ensure security of uploaded content.
Clients will need to check their FTP programs to see what options they have available to them.
Further to this, despite previously recommending Filezilla to clients, we now advise against using Filezilla FTP client as we have seen a number of clients report connection issues. A number of people have issues with Filezilla and the global connection setting when they upload it causes too many simultaneous connections and they get blocked by the firewall.
Try using another FTP client such as:
Kind Regards,
If anyone has any queries or concerns, or find your site experiencing any problems, please do not hesitate to contact us for assistance.
Kind Regards,
Natalie Verhoek
Head of Technical, Data & Training





