Friday, March 30, 2012

Amazon's Cloud Powered by Estimated 454,400 Servers

endless server roomEver wonder what it takes to run a cloud operation? What kind of infrastructure is needed and what kind of hardware is used? Probably not because most typical users never really get a chance to see the entire infrastructure that supports the plethora of services they use on something like Amazon's Elastic Compute Cloud. However, it was recently estimated by by Huan Liu, Research Manager for Accenture, that an astonishing 454,000 individual blade servers are currently being used to power it.

Liu made the estimate in a personal blog post recently, stating that he used a combination of data and DNS queries within EC2, all of which were publicly available, to come up with that number. The number indicates just how many physical server racks are used by Amazon's Cloud Service multiplied by the number of individual servers that could be housed in each rack.

However, Liu did mention that there are a number of different obvious holes in his number. Liu notes that the total number he gave is a complete estimation on his part and that Amazon could very well configure its systems differently than he thinks. In addition to that, if Amazon has any racks without an active server running on it then it would be impossible to count, which would also displace Liu's accuracy in the total.

Regardless, Liu's post has stirred up quite the buzz in the media, though that could be because it is one of the best estimates to Amazon's cloud size currently on the web. Amazon is pretty secretive with their information on their Elastic Compute Cloud, making these hypotheses a necessity.

Source: PC World - Nearly a Half Million Servers May Power Amazon Cloud
Renting projectors for meetings, events, trade shows, and projectors is easy at Rentourprojectors.com! You can rent projectors by the day, week, or month!

Sunday, March 18, 2012

First Licensed Server Refurbishing Plant Opened in China by IBM

IBM buildingLast month, IBM announced that it had just opened its first facility in China with the main purpose of refurbishing and reselling old computer servers. Financially, this is a great move for IBM as the market for refurbishing and reselling computer servers is expected to increase to $2 billion in China by 2014.

The United States and Europe's exporting of electronic waste to Asia over the past 20 years has brought up some major concerns about the impact this has on local environments as well as the low-paid workers who are in charge of dismantling the toxic-heavy computers and other components to recover valuable metals and parts.

However, the increasingly profitable economy in China has created a significant e-waste problem of its own. China's government even has a 5-year economic plan that encourages recycling and remanufacturing computers in order to keep them out of landfills. According to General Manager of IBM Global Asset Recovery Services Richard Dicks, "In China, they'll use them for five, seven or nine years and they're basically landfill when they come out."

IBM's plant opened back in February in Shenzhen, very close to another IBM factory. The factory is expected to refurbish 100,000 servers and PCs every year by 2014. This feat will be accomplished by installing new memory and storage and packaging them for resale to the domestic Chinese market. According to Dicks, "The Chinese market is huge from a server perspective."

The supply of old servers came mainly from China as equipment leases expired and customers started to turn in old machines and equipment. IBM also operates other refurbishing plants around the world, taking in 33,000 metric tons of old equipment every week. That diverts nearly 97% of the weight of old machines away from landfills according to IBM.

Dicks also stated that IBM had also been negotiating with the government in China for the last 2 years to license the Shenzhen refurbishing plant and that he expects IBM's competition to eventually establish their own facilities. "The thing we talked to the Chinese government about is that it's really easy to buy a new computer but it's really hard to get rid of one. We're the first licensed facility and we have a first-to-market advantage," Dicks said.

Source: Forbes - IBM Opens China's First Factory To Refurbish Old Computers, Tapping A $2 Billion Market

Sunday, March 4, 2012

Windows Server 8 Beta Now Live

Microsoft, right on the heels of its public viewing of Windows 8, has just released a beta version for the company's Windows Server 8 operating system. Windows Server 8, which was officially announced last September, updates the code base for Microsoft's flagship server OS, the current version of which is Windows Server 2008.

The beta version will allow administrators to test the operating system and give feedback to Microsoft who will then use that feedback to finalize the software for commercial release. However, Microsoft did not disclose any information on when the final production ready version of Windows Server 8 would be available for purchase.

Windows Server 8 is a very major update for the operating system and contains a plethora of improvements to virtualization, multi-machine management and application hosting capabilities, according to Corporate Vice President for Server and Cloud at Microsoft Bill Laing.

In terms of virtualization, Windows Server 8 will allow administrators to create virtual networks, allowing different business units or customers to share one physical network while simultaneously maintaining complete independence from the other virtual networks. Another new feature will allow you to move shared files between nodes without ever having to stop the server applications that use these files, which will help greatly in disaster recovery and maintaining continuity in operations.

As far as hosting applications are concerned, Windows Server 8 will also include a copy of .NET Framework 4.5, which also includes new capabilities to run a program concurrently across multiple processor cores. The Web server software Internet Information Server (IIS) has also been upgraded to provide better security isolation as well as manage more sites per server. The PowerShell command line interface has also been increased with the addition of 2,300 commands.

If you want to give the free beta version a run through, then all you need is a 1.4 GHz 64-bit processor, a minimum of 512MB of working memory and 32GB on a disk. In addition to that, users have the ability to upgrade to the new beta operating system from existing versions of Windows Server 2008 and Windows Server 2008 R2 though you will be unable to upgrade to subsequent releases from this release. Click here if you want to download the Windows Server 8 beta.

Source: PC World - Microsoft Releases Windows Server 8 Beta

Rack-Mount Server rentals are ideal if your company needs an extra storage unit for company information while you are testing various types of storage solutions.

Whether you need a short-term rental or a long-term lease, we have the right kind of server for your needs.

Friday, February 17, 2012

Parts of Internet Could Disappear Amid FBI Server Shutdown

FBI OfficersIn late 2011 the Federal Bureau of Investigation (FBI) set up a bunch of secure servers to replace the ones created by seven individuals that were arrested for internet fraud. According to a statement by the FBI at the time of the arrests, "The dismantling of the defendants' rogue DNS servers - to which millions of computers worldwide had been redirected - would potentially have caused all of those computers, for all practical purposes, to lose access to websites."

Any company in the world that had a website hosted on one of those servers had only 120 days to knock out all the malware known as DNSChanger Trojan before the servers would be shut down by the FBI. Well, those 120 days of grace have almost run their course and any site that doesn't or hasn't cleaned out the malware could see their website erased from the internet entirely come March 8. If this happens, then we could also very well see a sizable piece of the internet disappear on that day as well.

Brian Krebs, a security expert, has claimed that nearly half of the world's Fortune 500 companies and personal computers at almost 50% of all federal government agencies still have the malware on their networks. If that is true, then there are a lot of companies, important ones, that will lose their websites and access to them in just a couple of weeks.

According to President and Chief Technology Officer for Internet Identity, "Yes, there are challenges with removing this malware, but you would think people would want to get this cleaned up. This malware was sometimes bundled with other stuff, but it also turns off antivirus software on the infected machines and blocks them from getting any security updates from Microsoft."

Source: Mashable - FBI's Looming Server Shutdown Could Leave Chinks of the Internet Dark


Find out what is going on in the Tech Army World.



What are the Top 10 Money Making Missions?

What other companies have joined and what do they do?

How do I join the
Tech Army Organization ?

Friday, February 3, 2012

Apache Releases v2.2.22 for Apache HTTP Server

ApacheThe release of Apache HTTP Server v2.2.22 has just been announced by both the Apache Software Foundation and the Apache HTTP Server Project. The Apache HTTP Server Project has stated that this release is definitely the best version of Apache HTTP Server released so far and is encouraging all of its users to to upgrade as soon as possible.

Version 2.2.22 of Apache HTTP Server 2.2.22 is mainly an update that fixes security issues and bugs. However, there are a number of significant security fixes that are included in v2.2.22. These include:



  • Reject requests when the request-URL doesn't match HTTP specification.

  • Fix integer overflow in ap_pregsaub().

  • Resolve additional cases of URL rewriting with ProxyPassMatch or RewriteRule.

  • Fix segfault when the '%{cookiename}C' log format string is in use and a client sends a nameles, valueless cookiee, causing a DoS.

  • Fix scoreboard issue which could allow an unprivileged child process to cause the parent process to crash and shutdown in stead of terminating cleanly.

  • Fixed an issue in error responses that could expose "httpOnly" cookies when no custom ErrorDocument is specified for status code 400.

Version 2.2.22 of Apache HTTP Server is currently available for download if you want it. The CHANGES_2.2 file, which is found on the download page, has the entire list of everything that is changed in v2.2.22 and a condensed list, known as CHANGES_2.2.22, includes only those changes since the prior release of v2.2. If you want to, you can also view an entire summary of all the security vulnerabilities addressed in this release, as well as earlier releases.

The summary includes version 1.4.5 of Apache Portable Runtime (APR) as well as APR Utility Library (APR-util) version 1.4.2, which is also paired with the tar and zip distributions. The Apache Portable Runtime libraries libapr and libaprutil, as well as Win32, libapriconv v.1.2.1, must all be updated for binary compatibility and to address a lot of known security and platform bugs.

Whenever you do decide to upgrade or install v2.2.22, keep in mind that if you are going to be using Apache HTTP Server with a threaded MPM other than the Prefork MPM, you need to ensure that all modules you will be using, as well as their libraries, are thread-safe.

Source: Connectwww.com - Apache HTTP Server 2.2.22 Released
Server Watch - Apache HTTP Server 2.2.22 Released


Find out what is going on in the Tech Army World.



What are the Top 10 Money Making Missions?

What other companies have joined and what do they do?

How do I join the
Tech Army Organization ?

Friday, January 20, 2012

Vulnerability in X Server Allows the Unlocking of Computer

A very interesting, and potentially very harmful, vulnerability has been discovered in X.orgs's X Server that allows users to gain access to a locked computer. By pressing the Ctrl key, Alt key and * key simultaneously one can disable a user's screensaver and unlock the computer, a glitch discovered by French blogger "Gu1". The technique has already been verified to work on versions 1.11 and higher of X.org's X Server.

According to Gu1, the vulnerability is caused by something known as the "AllowClosedownGrabs" debug option. If this debug option is activated, pressing that key combination will cause any processes that calculate mouse or keyboard inputs to shut down. In the case of the key inputs above, the computer's screensaver, which usually prevents a locked computer from being accessed, is disabled.

Gu1 also says that this debug option had existed up until 2008, though at that time it was disabled by default and well-documented. It has also been mentioned that the developers explicitly pointed out the potential security problems that may arise when this is used in combination with screensavers. In addition to that, developers were able to use an API to disallow the function for their processes.

The function was re-introduced last year though was enabled by default and was not clearly documented and not easily configurable according to Gu1. Developer at X.org Peter Hutterer stated, "This was caused by a miscommunication within the development team." After the function was re-introduced, developers failed in removing the keyboard combination from the default keymap.

Gu1 also mentioned that any Linux distributions that use version X Server v1.11 are vulnerable and added that he was able to reproduce the problem with Debian and GNOME 3 and even with Arch Linux and GNOME 3 and Slock and Slimlock. It is also reported that KDE can also be unlocked this way.

Source: The H - X.org server allows anyone to unlock computer

Power Point Projectors
Most business class projectors will do a good job displaying your PowerPoint presentation. If you have a small presentation group, a 2000 lumen LCD projector will be able to produce a nice and clear picture. For larger audiences you should consider a 5000 lumen LCD projector.

Friday, January 6, 2012

New Denial of Service Attack Takes Its Time on Your Server

DeniedOn Thursday a researcher published a proof-of-concept code that takes a new look on the slow HTTP Denial-of-Service (DoS) attack by simply dragging out the whole process of reading the server's response and, eventually, overwhelming it. Senior Software Engineer at Qualys Sergey Shekyan also added this modified Denial-of-Service attack, which he dubs a Slow Read attack, to his Slowhttptest tool.

As far as the attack goes, Slow Read basically sends a legitimate HTTP request and then takes an excruciatingly long time reading the response. By doing so, the Slow Read attack keeps as many open connections as possible and eventually causes a Denial-of-Service attack.

The Slowhttptest attack tool developed by Shekyan was inspired by related open-source tools Slowloris and OWASP's Slow HTTP Post. Slowloris keeps connections open by sending partial HTTP requests and then sends headers at regular intervals in order to prevent the sockets from closing.

OWASP's Slow HTTP Post Distributed Denial-of-Service (DDoS) tool simulates an attack using POST headers that have a legitimate content-length field. This allows a web server to know just how much data is arriving. Once the headers are delivered, the POST message body is transmitted slowly and gridlocks the connection, as well as the server resources.

Slow HTTP attacks are becoming increasingly more popular, especially among hackers, as a way to quietly insert a Denial-of-Service attack due to the fact that these hacks are relatively simple to perform, require minimal computing resources and are often hard to detect until it is too late.

Source: InformationWeek - New Denial of Service Attack Cripples Servers Slowly

Rack-Mount Server rentals are ideal if your company needs an extra storage unit for company information while you are testing various types of storage solutions.

Whether you need a short-term rental or a long-term lease, we have the right kind of server for your needs.