goHost

Call: 1-866-464-6781 Subscribe to our RSS feed

Maintenance Window, February 25, 2012

Based on our schedule we will have a maintenance window to make configuration changes and apply security updates to our hosting infrastructure:

DATE: Saturday, February 25th, 2012
START TIME: 12:00 AM EST
END TIME: 2:00 AM EST
DURATION: Up to 2 hours

During this maintenance window our operations team will be:

  • Applying recently released security updates and patches to managed Windows servers.
  • Applying recently released security updates and patches to managed Linux servers.

goHost at Parallels Summit 2012

goHost is going to be at the Parallels Summit in Orlando next week, February 14-16. At Parallels Summit 2012 we will be networking and hearing from industry leaders, hosting experts, and various service providers as we address some of the most important issues in the industry today.

Several goHost team members will also attend Parallels training programs and receive certifications.

goHost names Robert Moses as CTO

goHost, a provider of secure cloud hosting, names Robert Moses the new Chief Technology Officer. Robert brings a wealth of experience in hosting, virtualization, data center technology and Internet security.

Speaking about his new role Robert said, “I am very excited to help direct, improve and increase goHost’s capabilities to bring effective and accessible secure hosting services to all types of customers.

Maintenance Window, January 14, 2012

Based on our schedule we will have a maintenance window to make configuration changes and apply security updates to our hosting infrastructure:

DATE: Saturday, January 14th, 2012
START TIME: 12:00 AM EST
END TIME: 2:00 AM EST
DURATION: Up to 2 hours

During this maintenance window our operations team will be:

  • Applying recently released security updates and patches to managed Windows servers.
  • Applying recently released security updates and patches to managed Linux servers.

2012 Maintenance Schedule

We schedule regular maintenance activities on our network to allow for upgrades, enhancements and other routine tasks that are required to maintain the best operating performance, stability and security.

Read more →

2012: New Year and New Things

Happy New Year!

It is a bit cliche but we can’t help it. All of us at goHost are excited about 2012! We worked hard behind the scenes in 2011 laying the ground work for some new things we have in store this year.

In the coming weeks expect to see a number of new services, upgrades, and enhancements to our existing services. We have a lot of things in the pipeline and will be rolling out changes slowly at first. Many of the new services will be focused on helping all our customers get and stay secure in the cloud.

As we grow our service offerings, please share with us your thoughts, concerns or even any ideas.

Thank you all for your support and we look forward to working with you in 2012.

HashDoS Web Scripting Vulnerability

Security Reasearchers have discovered a long standing vulnerabilty in many popular web application languages that can lead to a denial of service (DoS) attack. Most programing languages including PHP, Java, Python and ASP.NET are vulnerable to this HashDos vulnerabltily.

A denial-of-service attack (DoS) overloads the server with multiple requests, effectively making it unable to serve a website to new visitors. Usually such an attack strong enough to overwhelm a server requires a lot of horsepower on the attacker’s side. This vulnerability however makes things significantly easier for an attacker.

Microsoft has released an emergency/out-of-band update (KB2659883 and MS11-100) to mitigate this issue in ASP.NET and .NET Frameworks.

All our Windows Server systems have already been patched with MS11-100.

Researchers recently presented their research at the 28c3 Security Conference. The specific details relate to hashing algorithms and managing hash collisions. A specially crafted request can force a website to consume all CPU resources in an effort to resolve and manage the hash collisons. The net effect of this increased CPU load can lead to a DoS on the website.

Without fixing the core hashing algorithims and functions there are a number of workarounds that can be used to mitigate the impact of the HashDos vulnerability.

  • Reduce the length/size of HTTP parameters that can send via POST.
  • Reduce the number of HTTP parameters accepted by the web application framework.
  • Limit the amount of CPU time that any given thread is allowed to run.

These workarounds may negatively impact the operations of your web application and should be reviewed and tested before being deployed into a production enviroment.

References and further reading:

  • http://en.wikipedia.org/wiki/Denial-of-service_attack
  • http://en.wikipedia.org/wiki/Hash_collision
  • http://technet.microsoft.com/en-us/security/advisory/2659883
  • http://technet.microsoft.com/en-us/security/bulletin/ms11-100
  • http://blogs.technet.com/b/srd/archive/2011/12/29/asp-net-security-update-is-live.aspx
  • http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx

Maintenance Window, December 17, 2011

Based on our schedule we will have a maintenance window to make configuration changes and apply security updates to our hosting infrastructure:

DATE: Saturday, December 17th, 2011
START TIME: 12:00 AM EST
END TIME: 2:00 AM EST
DURATION: Up to 2 hours

During this maintenance window our operations team will be:

  • Applying recently released security updates and patches to managed Windows servers.
  • Applying recently released security updates and patches to managed Linux servers.

Robert Moses featured in Web Application Security Virtual Conference

goHost Director of Technology Robert Moses will be a panel member in a Web Application Security Virtual Conference hosted by Applicure on December 7th.

Details: On December 7th Applicure Technologies will host a Virtual Conference which includes a panel of security experts and Web hosting market leaders. The panel will feature in-depth discussion of defense techniques for the most common attacks and security vulnerabilities as well as methods to increase revenue while reducing support costs.

Read more about our Web Application Firewall service.

Now Available: Parallels Plesk Panel 10.4

Parallels Plesk Panel 10.4 is now available with any dedicated server or virtual server plan.

Parallels Plesk Panel Boxshot

This updated version of Plesk includes a number of new features and many performance improvements including:

  • New! Configurable PHP settings
  • New! Support for Web Deploy and Web Matrix
  • New! Control over Apache Modules
  • New! Quick Preview of websites
  • New! Mobile Server Monitor and Mobile Server Manager

You can read more about the features of Plesk 10.4 or contact us to get Plesk 10.4 today.