Categories
security server admin

HOWTO: Prevent SEO scam Referrer traffic … AND … Install Mod-Security on Debian

UPDATE: there were several bugs in my original version – by Debian standards, ModSecurity is damn hard to configure correctly, mainly because the Debian packager has left out so much that’s essential! This version is fully tested and working…

Mod Security is an awesome, open-source product for Apache that will protect your webserver against attackers, using a custom rules-language that lets you easily filter for any kind of website attack. Even better, it comes with a pre-built (and regularly updated) set of “official” default rules for cutting out the majority of common internet attacks.

But, pretty shocking … I tried 10 different tutorials / HOWTO’s for this, and each one was wrong. Out of the 10, 6 of them lead to fundamentally insecure / misconfigured systems.

Mostly it’s the vendor’s fault for providing huge long-winded webpages in place of basic install instructions. Partly, it’s the Debian packager’s fault for both mis-packaging, and also “forgetting” to document what they’d done (e.g most of the README’s are empty. Grr!). Whatever. Here’s my HOWTO for doing it correctly, and picking up the excellent default security rules, that *should* work with most installs of Debian.

Categories
entrepreneurship

Get VC funding for your startup: the process

One of the most useful (and short) posts I’ve ever seen (*) on raising VC money. This post from Mark Suster encapsulates key things that every VC knows and feels is so obvious they wont even mention … But which new entrepreneurs have no way of knowing:

http://www.bothsidesofthetable.com/2011/01/11/going-to-raise-vc-heres-a-primer-on-process-people-deck/

…and if you’re raising money in europe (by which i mean “london”, in practice), i encourage you to benchmark your experience against this list.

There are still, even today, plenty of so-called VC firms in London whose processes are opaque, elongated, archaic, or pointlessly troublesome. If your VC wont stick to this process demand to know why not – and ask yourself how much trouble it will cause you down the line?

E.g. If your VC is a spinout from a London hedge fund, they may have an investment banking twist on process, that anyone from the city would recognize, but whose origins are in servicing a very different audience from entrepreneurs.

(*) – of course, im assuming you read http://venturehacks.com already. If not, youve got a lot of reading to do, and probably need to start again from scratch on your funding strategy :).

Categories
games industry games publishing

Codemasters forgets to renew codemasters.com?

Oh dear..