Wednesday, November 29, 2006

Pleth's Default DNS Settings

In the past we have been asked what DNS settings are put in place for our clients domains when we add their sites to our servers, hopefully the information below will provide the answers for you. If not, please do not hesitate to contact our support department about any questions you might have prior to transferring your domain regarding your DNS zone files.

Occasionally our clients will have their own mail servers, such as Microsoft Exchange that they prefer to run in tandem with their websites in which we host for them. We can accommodate these needs for clients without any problems, in fact through the PLESK control panel, our clients have the ability to edit their own zone files, or we can handle it for them.

yourwebsite.com. NS ns.yourwebsite.com.
mail.yourwebsite.com. A 70.86.194.00
ns.yourwebsite.com. A 70.86.194.00
yourwebsite.com. A 70.86.194.00
webmail.yourwebsite.com. A 70.86.194.00
ftp.yourwebsite.com. CNAME yourwebsite.com.
www.yourwebsite.com. CNAME yourwebsite.com.
yourwebsite.com. MX (10) mail.yourwebsite.com.
70.86.194.00 / 24 PTR yourwebsite.com.

Friday, November 10, 2006

Avoiding SQL Injections

Since it first saw success as a powerful web development platform, PHP has suffered from the ease of use that bred that success. Inexperienced developers can all too easily build applications that are vulnerable to attack, and one of the most common vulnerabilities is the SQL injection.

From Kees Kodde of Qrios Web Design: “In most security related articles about web development, the threat of SQL injections is mentioned, and there seem to be a lot of ways to defend against this. What is, in your opinion, the most simple and effective way to filter possible SQL injections out of user input?”

The biggest challenge of defending against SQL injection attacks is understanding them, so let’s start with a simple example in PHP. This script fragment determines the price of a product given its ID as submitted by the browser:

$id = $_POST['id'];$sql = "SELECT price FROM
products WHERE id = $id";$result = mysqli_query($db, $sql);$row =
mysqli_fetch_row($result);$price = $row[0];


The problem here, as in most scripts vulnerable to SQL injection attacks, is that an assumption has been made about a value that is being received from the browser. The code assumes that the ‘id’ value sent by the browser will be a number, and can be placed into a string to form an SQL query like this:

SELECT price FROM products WHERE id = 123


But what if the ‘id’ value contains a maliciously-crafted string instead? When the value is placed into the string, it could instead form a query like this:

SELECT price FROM products WHERE id = 123 OR price
<>


That’s an SQL injection. In this example, it will fool the script into fetching a price less than 10 (assuming there is another product with such a price in the database) instead of the actual price. In other cases, SQL injections can be used to bypass password checks when logging into a site, and in some rare cases even modify the data stored in the database.

In general, the solution to SQL injection attacks is to enforce every assumption you make about any value that you insert into an SQL query. You can either do this manually, or use a pre-built library to do it for you. The above example could be modified to force the ‘id’ value to be interpreted as an integer:

$id = (int) $_POST['id'];


For numbers like this, you can force the language to convert values to numbers. For strings to be included in SQL queries, you need to use tools like PHP’s mysqli_escape_string function to convert special characters like quotes into a form that will not interfere with the query’s operation.But relying on yourself and your fellow developers to remember to enforce these rules for all browser-submitted data is problematic. Instead, you should use some library that will do it for you.

PHP5.1’s PHP Data Objects (PDO) API allows you to place values into SQL queries safely, specifying the expected data type.

$stmt = $db->prepare('SELECT price FROM products
WHERE id = :id');$stmt->bindValue(':id', $_POST['id'],
PDO::PARAM_INT);


So to answer your question, the simplest way to defend against SQL injection attacks is to avoid building your own SQL queries, and instead to use an API like PDO that will do it for you, safely. Indeed, PHP is one of the few languages where building SQL queries by combining strings is a common practice, and I’d say the prevalence of SQL injection attacks on PHP-based applications can be largely attributed to this.

Thursday, October 5, 2006

2 New Sites Launched!

Cotton Rohrscheib, Partner and Co-Founder of Pleth, LLC, announced today that his firm had recently launched two new client projects.…

Holidays In the Rock
Brought to you by The Little Rock Conventions and Visitors Bureauwww.holidaysintherock.com

Holidays in the Rock was developed by Pleth, LLC and Strategic Partner, the Angela Rogers Group of Little Rock. Holidays in the Rock showcases the breathtaking foliage, harvest celebrations, haunted museums, historical home tours, cultural attractions, flavorful gourmet dining and more that is going on in Little Rock this holiday season! A treasure of festivals, live entertainment, exciting events and special promotions showcase just a few of the things brought to you from the Little Rock Convention and Visitors Bureau.

“Everything from where to have dinner to the best places to shop and stayover can be found on this website,” said Greg Smart, Founding Partner and Project Manager for Pleth, LLC. “The site is also very dynamic in that it will be evolving the closer we get to the Holiday Season. The site is also open to the public to submit events for inclusion on the widely publicized holiday calendar, those interested should contact the Angela Rogers Group or send an email to: brenda@theangelarogersgroup.com.” added Smart.

Re-Elect Valley for Mayor
Brought to you by The Committee to Re-Elect James Valley, Mayor
www.valleyformayor.com

Valley for Mayor is the official re-election website for James F. Valley, Helena – West Helena, Arkansas’ Incumbent Mayor and local attorney. Since Mr. Valley’s victory in the previous election he has worked very hard in establishing Arkansas’ newest city as a competitor again for commerce and industry. Mayor Valley was also pivotal in the drive to have Helena and West Helena consolidated.

“In addition to James being a long-time client, he has also been a good friend for several years.” said Rohrscheib. “James is a very intelligent person, and an extremely hard worker that knows how to rally people to work together for a common goal.”

While the Valley for Mayor website was launched this week, there are some components of the website that will be following in the weeks to come. “We have officially launched the website, but a lot of the functionality hasn’t been developed just yet. With Mayor Valley currently in office, the time that we get to spend w/ him is limited so there are items we are waiting on that will have to come later such as content for some sections of the website. Also, we are awaiting processor information for his campaign contributions module,”

“Currently the site isn’t barren though, we do have a large number of photographs available online from the past term that were provided by Mayor Valley’s Office, as well as a few family photos of Mayor Valley. The photos section will also see quite a few new photos added on a daily basis as we get closer to the election. A new section has also been added to the site this year that will allow voters and constituents the opportunity to create an account and interact with Mayor Valley about any issues they would like to discuss,” said Rohrscheib, who assists Mayor Valley in monitoring the site’s blog traffic.

In addition to launching these two new projects, the Pleth, LLC development team has been very busy as of late. Last Month, a major development project for Wal-Mart sponsored Hofi, Inc. Kids All-American Fishing was launched. The Team has continued to monitor the solution with the client to iron out any bugs that might exist with a new solution this detailed.

New Contracts Announced…

Stephen Smart, Founding Partner of Pleth, LLC also announced today that three new clients had signed Contracts with Pleth, LLC to begin work on web development projects. These new clients include: the New York Based, InternetLawFirm.com, the Oklahoma Association of Health Care Providers, and Hagan’s Auto, located in Morrilton, Arkansas with a new location opening very soon.

Friday, September 1, 2006

Pleth, LLC Launches EzCya


EZCYA.com, a Division of PLETH Networks, LLC has launched their website and service. At this time the EZCYA.com website offers a simple description of EZCYA’s services and outlines their current pricing structure.


“In the very near future we plan to add total automation to our offsite data warehousing business,” said Cotton Rohrscheib, Partner of PLETH Networks, LLC. “We plan to allow visitors to EZCYA.com the ability to purchase storage space online, and then access their products and services online instantly using the credentials they provide.”


It has been rumored that PLETH Networks, LLC will soon be announcing a strategic partnership with Modernbill, a totally automated accounting solution geared toward Web Hosting Providers. No specific date has been named as the target date for this announcement.

Thursday, August 31, 2006

Uniforms Worldwide Launched!

August 29, 2006 — Batesville, Arkansas. Greg Smart, of Pleth, LLC announced today that his firm had launched a new e-commerce project for Uniforms World Wide. Uniforms World Wide, A Florida Based Corporation specializing in the Sale of Medical, Industrial, and Food Service Uniforms. The new website allows visitors to place orders from their extensive online catalog and offers convenient shopping cart functionality with ssl encryption for added security.

In addition to web development and hosting services, Uniforms Worldwide has also contracted Pleth to manage their PPC and online marketing campaign. For additional information about Uniforms World Wide, or this new website, please visit:
www.uniformsworldwide.com or contact Pleth, LLC, corporate@pleth.com for details…

Pleth Meets with Planet CEO

In this month's Telemetry Newsletter from the Planet,
which goes out to all of their clients and probably released to countless media
outlets that serve the technology industry there is a photo of Doug Erwin, the
new Planet CEO, discussing future plans and answering feedbacks from leaders in
the hosting industry. You guessed it, the guys from Pleth made the
photo...


CEO Doug Erwin is focusing on getting to know you, our customers. He recently said, “Listening to our customers is absolutely a priority for me. Our success depends on being in tune with our customers’ needs.”

Since joining the company in July, Erwin visited with our clients at HostingCon as part of an open-forum session. Customers asked questions about the company and provided us with valuable feedback. He has also made personal phone calls to many of you, soliciting your opinions on the challenges and benefits of being our customer.

Continuing his open dialogue, Erwin conducted a candid online chat with our customers on September 9th. He plans to continue this conversation with you several times a year.
Erwin has also pored over your ideas and suggestions from the recent customer survey and products are launching in response to those results.

Highlights from the recent customer survey include:

  • 1,309 customers completed the survey
  • More than 80% have been with us for over a year.
  • 70% of you work for a start-up or a small business.
  • Most of you are very interested in security audits and hourly system administration support, with a tech staff that is a scalable, on-demand extension to your team.
  • Only 5% of you maintain servers with both Houston and Dallas.
  • We are integrating our order systems, making it easier for customers to access the best services we have to offer.
  • 85% of respondents expect growth in the coming year
  • 75% plan to order new servers or upgrades from us.

Wednesday, August 9, 2006

Press Release: Pleth Updates Control Panel

08/09/2006 04:04:58 AM - DALLAS, TX: While locating their Server Farm to the PLANET NOC in Dallas, Texas, PLETH Networks, LLC made the switch from Ensim to PLESK as their primary Control Panel Software Solution. PLETH and their 300 licensed clients have utilized the PLESK Control Panel Solution on both Microsoft and Linux Hosting Platforms with great success since the migration.

On April 3rd, SWSOFT, Inc. announced the release of PLESK 8.0. The PLETH Team implemented the upgrade to 8.0 from 7.5.4 on April 4. During the upgrade only isolated accounts of interruption was experienced by PLETH and it’s clients. During the installation, the PLETH team was assisted by the Award Winning Support Team at the PLANET NOC.