A blog about server hosting

New product and service information, along with general ramblings about the web hosting industry from the Melbourne team.

For Sales Please Call: 0800 915 8771

For Support Please Call: 0800 915 8772

Ubuntu back in the cloud

August 31st, 2010

With the release of Ubuntu 10.04 LTS, the more observant of you may have noticed Ubuntu snuck itself back onto the list of available operating systems for the UltraVM Cloud Platform.

Ubuntu 10.04 is the latest generation of the long term supported codebase, and brings with it a number of technological advances, including kernel modules enabling it to plat nicer in a virtualized environment, as well as adding support for our cloud platform.

After performing a closed beta and numerous performance tests, we have seen Ubuntu server out perform a number of already available Linux OS including CentOS, whilst the management tools available make it a breeze to maintain.

It is for this reason, that we recently made the decision internally to freshen our Linux environment, replacing a mixture of operating systems and architectures with Ubuntu 10.04. As we go through this process, we will be posting a number of useful tips & tricks to effectively manage your Ubuntu server.

Rob Greenwood – Technical Lead

Melbourne in the Community

August 6th, 2010

This week I’ve been doing my bit for local, national and even international communities by speaking about and demonstrating the Melbourne skills….

On Tuesday I met with Tatsiana Ramanovich, a Master’s student at Manchester Business School, studying the Corporate Communications and Reputation Management course. We shared our experiences in launching social media strategies and maintaining related activities, interesting findings and challenges which we face in social media communications. Tatsiana very generously brought cake to the Melbourne office!

On Wednesday I was invited by the CEO of Manchester Science Park to speak to Dean Bing-Huei Lin, Professor Ming-Huei Chen and 5 other visitors from the College of Social Sciences and Management of National Chung Hsing University of Taiwan. NCHU is based in the City of Taichung, the third largest city in Taiwan.
The delegation made the visit to Manchester to learn about successful companies at Manchester Science Park and to listen to the Melbourne introduction and business model.

On Thursday, Steven and I  gave a Melbourne introduction to 10 visitors from Young Rewired State which is a collection group of young people using government data to create apps. We gave them a guided tour of the Datacentres to show them why our customers put their trust in us to keep them online 24×7. The guys showed their appreciation by parading around Piccadilly gardens sporting our new stickers (see below)!

After this I went along to the Northern Digital BLAB event at MadLab in the Northern Quarter, Melbourne was kindly asked to sponsor the event by providing drinks. The night was a fantastic success with 100 people attending and we were treated to talks from Brendan Dawes, Creative Director of Manchester’s Magnetic North and Technical Director of Brighton’s Plug-in Media Seb Lee-Delisle speak about their work, their ideas and their views.

YRS manchester post melbourne tour

Chris Marsh, Business Development Manager

Manchester Digital BBQ sponsored by Melbourne

August 2nd, 2010

Manchester’s digital and creative industry enjoyed burgers, chilli, pizza and free mojitos on Wednesday @ Atlas Bar for Manchester Digital’s Summer Barbecue which Melbourne was kindly asked to sponsor.

The event was also sponsored by CTI Digital, Fudge, and Creative Times.

Many thanks to Richard Hudson, Shaun Fensom and the rest of the Manchester Digital and MDDA guys for arranging such a successful event! We’re looking forward to the next one already!

Chris Marsh, Business Development Manager

Chris, Sim and Dan from Melbourne with Hannah from pr2go and Kate from Francesco

Melbourne’s Summer Sale – Half price service for 3 months

August 1st, 2010

So your sausages might not be sizzling on the BBQ anymore but hopefully we’ve got something to keep Summer alive with our fantastic amazing Summer Sale…

Any orders for new services placed during August will receive 3 months half price.

Dedicated Servers, Virtual Servers, Co-location, rackspace, Managed Backup and UltraSpam Anti-Spam all included of course. Click here for more information or contact your account manager.

Melbourne take part in the Urbanathlon

July 26th, 2010

On Sunday 25th July, three of the team from Melbourne Server Hosting took part in the Urbanathlon around East Manchester which consisted of running between obstacles on a 5Km trail.  Starting at the City of Manchester Stadium, we ran up steps, climbed walls, scaled haystacks, crawled through tubes, jumped over cars and made our way through various other challenging activities over changing terrains all in the name of charity.

In total, over 900 runners took part on the day to raise money and awareness for charities such as ‘Street Games’ a new National Charity delivering ‘Sport in Deprived Communities’, The North West Kidney Patient Association, The New Children’s Hospital Appeal, UNICEF and Brain Tumour UK.

Although it showed just how unfit we all are, we had a very enjoyable day and look forward to more events to raise money for charity soon.

completing the Urbanathlon

Sim, Dan and Chris completing the Urbanathlon

Chris Marsh, Business Development Manager

Automatically get rewarded for referring customers to us!

July 16th, 2010

We’ve had a referral program for quite a while. We get a lot of our new customers this way, and it’s always made me really proud just how often our customers refer us to their colleagues. It helps us know that we’re doing our job well.

Anyway, we’ve now made it easier for customers to make sure they get their referral reward every time they send someone our way.

Basically, if you’re kind enough to link to us from your website, you can now add a suffix containing your client ID, which means that anyone who you referred placing an order will notify us, allowing us to attribute the sale back to you.

After that you get your referral gift, which is a choice of:

  • A case of 6 bottles of quality wine, sourced from family-owned producers, from local wine merchant Reserve Wines.
  • An ipod shuffle in your choice of colours.  Don’t worry we won’t have it engraved with any terse ‘thank you’ message!
  • A £50 (including VAT) credit to your account.
  • A £50 donation to the charity of your choice.

(we’ll email you to ask which you’d prefer).

Find out more details of our referral program.

Social Media Day 2010

July 6th, 2010

Last week the world celebrated Social Media Day and Melbourne Server Hosting were invited to support the Manchester event at The Study in the Living Room.

The event focused on the impact which Twitter and Facebook (amongst others) has had on society and business. John Greenway from Manchester Airport spoke about how Twitter helped keep in touch with the public during the ash cloud days and heavy snowfall during December and January. There was also talks from Martine Alexander on how Twitter has helped promote her Styling business, Rick Guttridge on how it is used with PR, Chi-chi Ekweozor on promoting and using social media on her charitable project 7 wonders in 7 days, and finally Dom Hodgson on the pros and cons you should be aware of when tweeting to the masses…

Nigel and the rest of the team from Studio Skylab put in great effort to make sure the event was promoted and went without any hiccups with video links to similar set ups in Portugal and California (we even made ABC News that evening which you can view on our Facebook page ).

Chris Marsh,  Business Development Manager

Managed backup pricing reduced

June 24th, 2010

We’re delighted to announce that we’ve been able to reduce the monthly charges of our recently launched UltraVault™ managed backup service.

Due to a very competitive licensing deal we’ve just signed with the software vendor, R1Soft, we can now offer managed backup for just £5 per month per server, or free if you’re a managed server customer.  Data stored on the backup server is charged at the low cost of £0.50 per GB per month.

Existing customers will be contacted by their account managers to arrange to have the rental charges reduced from their next invoices.

To find out more information about the service please see our UltraVault™ Managed Backup section or speak to your account manager today.   UltraVault™ is available to customers with virtual, dedicated or colocated servers, and customers with rackspace.

The five dangers of Virtual Servers – Part 4

June 13th, 2010

Welcome to the fourth and final part of our series of posts on The five dangers of Virtual Servers.

Danger 4: The danger of over-contention

There’s a potential for over-selling with virtual servers, as the provider may not tell you how many virtual machines they intend running on one physical node, whether memory and CPU time are contended, or how fast the physical node is uplinked to the network.

The whole point is to put limitations in-place to stop one virtual server from hogging the resources at a performance cost to neighbouring virtual servers.

A responsible provider uses a virtualisation technology that does not allow memory or disk space to be contended, and has fixed parameters in place to ensure CPU and network resources are fairly shared out.  This includes setting an upper limit to the number of virtual machines that can run on a physical node, and also ensuring the physical nodes are uplinked to the ‘net at a suitable speed such that every server gets a decent sized connection.  For example a gigabit connection shared between 30 virtual machines gives an average throughput capacity of approximately 30Mbps to each virtual machine, whereas a 10Mbps connection shared by the same 30 virtual machines would give a measly 0.3Mbps average to each VM.

5. The danger of not having tools to help yourself in the case of emergency.

You would generally want KVM over IP and remote reboot facilities on a dedicated server, to give you “sat in front of the machine” access in the case of a major OS failure, or to correct network settings when the machine is otherwise inaccessible.

The same should apply to a virtual server.  This technology can be a life-saver when you need to work on a virtual server at 2am without waiting for your provider to respond to help you out.  It gives you complete self-sufficiency.

Conclusion

There’s plenty of scope for virtual server providers to cut corners.  That said, if you research your provider well, using the above questions as part of your decision-making process, you’re likely to find a service that’s a high-availability and high-performance alternative to dedicated servers.

To sum up make sure that any virtual server provider can meet the following criteria and you’ve done your utmost to mitigate the dangers we’ve described:

  1. Uses SAN Storage
  2. SAN and host servers have redundant critical components
  3. Nodes dual-uplinked through two switches (front-end and backend)
  4. You have your own VLAN
  5. Provides a hardware firewall
  6. No kernel sharing between host node and virtual machines
  7. Has a reasonable SLA
  8. Console access with reboot facility
  9. Has support that is responsive and knowledgeable
  10. Knows how to look after customers

As you’ll have no doubt guessed, Melbourne’s UltraVM™ Cloud Servers come up trumps on all of these points.

Daniel Keighron-Foster, Managing Director

PCI Compliance: SSL

June 10th, 2010

Over the coming weeks, I’ll be covering a number of technical aspects required to achieve PCI compliance. For information on what PCI compliance is and when you’ll require it, see this detailed wikipedia entry. For now, let’s move onto our first topic:

Disable SSLv2 and Weak Ciphers

Section 4.1 of the PCI-DSS states that you are required to “Use strong cryptography and security protocols such as SSL/TLS or IPSEC to safeguard sensitive cardholder data during transmission over open, public networks.”

Put simply; you will need to ensure that any web servers running SSL in your PCI environment, are configured to use strict set of security rules including disallowing Secure Socket Layer (SSL) version 2 as well as all weak cryptography.

Even if you’re not interested in PCI compliance, the techniques documented within are still extremely important as they disable a number of vulnerable protocols and encryption cyphers.

How to test for SSL V2:

In order to perform the following tests, you will need to have OpenSSL installed. Once installed, run the following command:

openssl s_client -ssl2 -connect SERVER:44

If SSL V2 is already disabled, you should see the following:

2295:error:1407F0E5:SSL routines:SSL2_WRITE:ssl handshake failure:s2_pkt.c:428:

How to disable SSLv2 in Apache 2:

You will need to replace the SSLProtocol directive in either httpd.conf, apache2.conf or ssl.conf dependant on your distribution.

The following configuration will selectively enable only SSLv3 and TLSv1

SSLProtocol -ALL +SSLv3 +TLSv1

Restart the web service and run the check again to ensure connections are no longer accepted.

How to disable SSL V2 in IIS:

You will need to apply the follow keys into the Windows registry:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server]
“Enabled”=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server]
“Enabled”=dword:00000000

Restart the server and run the check again to ensure connections are no longer accepted.

How to test for weak cyphers:

In order to perform the following tests, you will need to have OpenSSL installed. Once installed, run the following command. Alternatively, an open source utility known as SSLScan is available to do the checks for you.

# openssl s_client -connect SERVER:443 -cipher LOW:EXP

If weak cyphers are already disabled, you should see the following:

2362:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:188:

How to disable weak cyphers in Apache 2:

You will need to replace the SSLCipherSuite directive in either httpd.conf, apache2.conf or ssl.conf dependant on your distribution.

The following will disable all cyphers except for those classed as high security, and therefore PCI compliant:

SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH

Restart the web service and run the check again to ensure connections are no longer accepted.

How to disable weak cyphers in IIS:

You will need to apply the follow keys into the Windows registry:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56]
“Enabled”=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL]
“Enabled”=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128]
“Enabled”=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 56/128]
“Enabled”=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128]
“Enabled”=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128]
“Enabled”=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC464/128]
“Enabled”=dword:0000000

Restart the server and run the check again to ensure connections are no longer accepted.

At this point, scans performed against the SSL boxes in your PCI environment should pass all tests covering section 4.2 of the compliance requirements, as well as a number of non-PCI security scans covering SSL vulnerabilities.

Rob Greenwood, Technical Lead