Showing posts with label domain. Show all posts
Showing posts with label domain. Show all posts

Tuesday, 6 December 2016

A New ICANN Policy Is Now In Force

ICANN – the Internet Corporation for Assigned Names and Numbers, has enforced a new policy that affects all Whois updates regardless of whether a change of registrant or just a simple Whois modification is taking place. The policy is effective December 1, 2016.
The new policy has been imposed on all registrars and, as an ICANN-accredited registrar, we’ve taken all due steps to implement it throughout our system.
The implementation will affect all domain registrants who attempt to make modifications to the Whois contact information of their domain names  (.COM, .NET, .ORG, .BIZ or .INFO). This includes changes to the registrant’s name, organization or email address.

What is the new policy about?

ICANN’s new policy represents an essential revision of its Inter-Registrar Transfer Policy (IRTP), which covers the authorization procedures registrants need to pass through prior to initiating a transfer.
The new revision also covers the process of transferring domain ownership from one registrant to another, which now entails a series of confirmation and notification emails.
In addition to transfers, the new policy revision also affects simple Whois data updates, which may include changes to the registrant’s first name, last name, organization or email address.

How will the new policy affect registrants?

The new policy has introduced a few significant changes to the Whois management process, which can be summarized as follows:
  • registrants will no longer be able to make simple modifications to their Whois data with a click of the mouse;
  • any changes made to the first name, the last name, the organization or the email address, will now trigger an email confirmation procedure;
  • the procedure includes obtaining confirmation from both the current and the new registrant before the change is completed;
  • after the Whois update has been completed, the current and the new registrant will receive a confirmation email informing them that the change is reflected in the Whois database;
  • whenever a Whois modification has been implemented, the associated domain will enter into a 60-day transfer-lock period;
  • if a Whois change is made before initiating a domain transfer, the present registrant will be able to opt out of the 60-day lock, so that the domain can be transferred to the new registrant as soon as the Whois update confirmation procedure has been completed;

How does the new policy work?

The newly revised policy will come into effect every time a change is made to the Whois data, be it a registrant change or a simple Whois modification. Here are the steps involved in the Whois update procedure on our platform:
  1. The domain owner submits a Whois modification request;
  2. We send a Whois update confirmation request to the new registrant, asking them to approve or to decline the change of registrant;
  3. We send a Whois update confirmation request to the current registrant, asking them to approve or to decline the change of registrant; In the event of a transfer, we give the current registrant the option to opt out of the 60-day transfer lock that is imposed on a domain after a Whois update is confirmed. This way, they will be able to initiate the transfer as soon as the Whois update request is confirmed;
  4. Once the Whois change has been approved by the registrant(s), we will complete the update and send a final confirmation to both the current and the new registrant notifying them of the completed process. No further response is required from the registrant(s) at this point.
In case the current or the new registrant does not approve the change within 5 days of receiving the update confirmation request from us, the latter will be terminated and the current Whois information will not be modified.
NOTE: Even if the registrant just wants to make a correction to their name or organization, for example, the policy mandates that we send two separate emails in this case as well.
The afore-described Whois update confirmation procedure will not affect ID-protected domain names.
To make this possible, we have changed our Terms-of-Service agreement.
Of course, we will always opt out of the 60-day transfer lock on behalf of the given registrant, allowing transfers to take place.

Evostrix Web Hosting

Sunday, 4 December 2016

The Dirty COW Linux Exploit Patched Successfully

It has been some time since the nightmarish Poxy and Poodle vulnerabilities scared Internet users out of their wits, and now the web faces a new security exploit – a Linux kernel flaw bearing the ‘user-friendly’ name “Dirty COW”.
Dirty COW represents a privilege-escalation vulnerability that hackers can exploit and do harm to web servers using any Internet-connected device.
We’ve managed to address the issue on time and apply the necessary patches to our Linux-based system.

What is the Dirty COW security bug about?

In fact, the Dirty COW vulnerability is not new, at least not to Linux’s founder Linus Torvalds who admits to having uncovered it 11 years ago.
A bug fix patch was released in due time, but 3 years later it was undone by another security fix, leaving the Linux kernel vulnerable to network attacks for a period of 9 years. It was not until a couple of days ago that the ‘dirty’ Linux kernel threat re-surfaced online again.
According to Red Hat, the Dirty COW security flaw has left the Linux kernel vulnerable to unprivileged users who want to gain root access in order to increase their privileges and compromise the given server’s security.
This allows local users to gain write access to read-only memory mappings and hijack an Internet-connected device within practically a few seconds.
It is namely the broken copy-on-write (COW) mechanism in the Linux kernel that the flaw has been named after.

Evostrix Web Hosting

Evostrix Web Hosting Blog News

Saturday, 26 November 2016

A new Python Manager is now available in the Control Panel

Following the feedback of web developers, we’ve added a new functionality to the Advanced section of the Hepsia Control Panel – the Python Manager.The new Python Manager will allow users to edit the current Python version and to enable Python-compatible applications for their projects. Located right next to PHP Settings, it gives you one-click access to various Python management options.

From the Python Manager section of the Control Panel, you’ll be able to set the Python version for your account. You can choose between Python 2.7, Python 3.1 and the latest version – Python 3.5.

Ready to order? Visit Evostrix Today:
Evostrix Web Hosting

Wednesday, 28 September 2016

Why Us?

Why Us?

At Evostrix Web Hosting, our aim is to provide innovative shared hosting technologies. Our website hosting services arrive with lavish disk drive storage space and web traffic allotments, domain registration & transfer options, modern Domain and Email Managers, multi-website hosting options, as well as free extras, such as a 1-click web apps installer and a site builder. All accounts can be easily administered via our multi-language web hosting Control Panel. A round-the-clock customer care service is available too.

Evostrix Web Hosting Site Speed



Evostrix Professional Web Hosting plans provide you with a fantastic
value for your money. The SSD–equipped servers will help your web sites
function far better than those of the competitors. In addition, you can
make your sites considerably quicker with just a couple of mouse–clicks
with the web accelerators included in our easy–to–navigate Control
Panel, and maintain your data secured with the ZFS–based file storage
and Mod Security firewall implemented on our servers. You won't be
disappointed with our service or reliability.
To top it all, our hosting service is 100% risk–free and we offer a 30–day money–back guarantee.
We
offer FREE 30-day trial period For All Web Hosting Packages, during
which you can evaluate our services at your leisure. Sign Up today and
get your 30 day trial free with Evostrix Web Hosting: Try for Free. No
Credit Card Required.

Visit Evostrix Web Hosting

Saturday, 23 July 2016

httpoxy – a CGI application vulnerability now under control on our servers

A recently re-discovered server-side application vulnerability has been sending shivers down Internet users’ spine for a couple of days now.
The so-called ‘httpoxy’ vulnerability affects applications whose code is executed in CGI or other CGI-like environments.
To address this critical issue, we have enabled automatic website and app protection for managed solutions on our web hosting platform.

What is the httpoxy vulnerability about?

The new httpoxy vulnerability opens up ‘a green corridor’ for attackers to exploit the communication between a web application and other external applications via API.
If a vulnerable web application makes an outgoing HTTP connection, this could lead to a few critical consequences:
  • the outgoing HTTP requests could be proxied;
  • the server could be configured to send private information to a particular address and port;
  • the server resources could be exhausted by forcing the application to use a malicious proxy;
An outgoing connection could be exploited when the hacker makes a request that includes a ‘Proxy’ request header.
The CGI then turns the header into an environment variable called HTTP_PROXY, which is used to configure an outgoing proxy.
The web application in turn makes a request to a hacker-defined destination instead of the particular API. Let’s see how this translates in a real-life scenario.

Protection measures against httpoxy (Managed Services):

As soon as the httpoxy vulnerability was announced, we took immediate measures to patch all web hosting services, which are under our control.
These include:
  • All shared web hosting services;
  • All semi-dedicated servers;
  • Hepsia Control Panel-managed OpenVZ Virtual Private Servers;
  • Managed OpenVZ Virtual Private Servers;
  • Hepsia Control Panel-managed dedicated servers;
  • Managed dedicated servers;

Protection measures against httpoxy (Unmanaged Services):

If you are using a non-managed OpenVZ server, a KVM VPS or a dedicated server, or/and do not use the Hepsia Control Panel, then you will need to take immediate measures to protect your applications from the httpoxy vulnerability.
First of all, keep in mind that your applications are in fact immune to the httpoxy vulnerability in the following cases:
  • if your applications are making API requests over an encrypted (SSL/TLS/HTTPS) connection; httpoxy only affects unencrypted requests;
  • if you are not using CGI, but instead faster and better code environment alternatives that have been introduced over the last few years;
If you are using CGI, but have not yet made use of an encrypted connection, then you can easily prevent any exploit attacks by blocking the ‘Proxy’ header.

Ready to order? Visit Evostrix Today:
Evostrix Web Hosting