Citrix XenServer XS62E015 update failing to apply

If you’re using XenServer 6.2, you may have some problems installing the XS62E015 update from CTX140808. You go through the normal update procedure – download XS62E015.zip from the CTX140808 Citrix knowledge base article, extract it and upload the XS62E015.xsupdate file to the pool, then apply UUID c8b9d332-30e4-4e5e-9a2a-8aaae6dee91a to the pool, which promptly fails with: The uploaded patch file is invalid....

eBay and PayPal DNS hijacked by Syrian Electronic Army

Earlier today, the nameservers on the ebay.co.uk and paypal.co.uk domain were changed to ns1.dnforu.com and ns2.dnforu.com in an apparent hijack. It seems that the Syrian Electronic Army are now claiming responsibility for this on Twitter. They have posted screenshots of the eBay/PayPal MarkMonitor account where they were able to manage the domains in question as well as seemingly had access...

Tags used by OWASP CRS ModSecurity rules

I couldn’t find a definitive list of the tags used by the OWASP CRS ModSecurity rules, so after a bit of faffing around, here’s what I’ve come up with for the “base” rules in OWASP CRS version 2.2.9 (current at the time of writing). I’ve tried to group them together as best I can: Web Attack: OWASP_CRS/WEB_ATTACK/XSS OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL OWASP_CRS/WEB_ATTACK/RFI OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION...