The latest insights from the load balancing experts | Loadbalancer.org
  • Support
  • Blog
  • +1 833 274 2566
  • Solutions
  • Services
  • Products
  • Resources
  • Get Started
  • Support
  • Blog
Schedule your demo
  • Solutions
  • Services
  • Products
  • Resources
  • Get Started
  • Support
  • Blog

The latest insights from the load balancing experts | Loadbalancer.org

  • Latest posts Security
  • By topic
    • How Tos
    • Events
    • Guest Blogs
    • Top Ten Blogs
    • HA Proxy
  • By sector
    • Healthcare
    • Storage
    • Security
    • Print
    • Microsoft

Sector: Security

Not all exploits are created equal - but security will always come first. Let’s tackle some bugs.

Find out more about this sector
  • How-To's
  • HAProxy
  • High Availability
  • Just for Fun
  • Security
  • Events
  • News
  • Amazon AWS
  • Linux
  • Healthcare
  • Top 10 Blogs
  • Reviews and Comparisons
  • SSL
  • Web Application Firewall (WAF)
  • Case Studies
  • Microsoft Azure
  • Disaster Recovery
  • Direct Server Return (DSR)
  • Microsoft Exchange
  • Global Server Load Balancing (GSLB)
  • Microsoft
  • Print
  • Denial of Service
  • Microsoft Remote Desktop Services
  • Web Filters / Proxy
  • Object Storage
  • Broadcast Media
  • X-Forwarded-For Header (XFF)
  • Guest Blogs
  • Google Cloud Platform (GCP)
  • VMware
  • Nutanix
  • open source
See more tags
How-To's
How-To's
29 Oct 2020
How to train your Web Application Firewall (WAF) Aaron West
Training a WAF can be difficult - but not impossible. Find out how we recommend doing it, and how our tools make the whole process easier.

11 min read

Read more
HAProxy
HAProxy
27 Jul 2020
How to tackle bugs and vulnerabilities – a solutions architect’s opinion Himakshi Goswami
Dealing with bugs and vulnerabilities is quite common in the tech space. Aaron West, the head of Solutions at Loadbalancer.org shares some insights about our approach of tackling such issues, and more.

9 min read

Read more
Security
Security
18 Jun 2020
Healthcare IT should listen to Amazon's Werner Vogels: “Dance Like Nobody’s Watching. Encrypt Like Everyone Is” Aaron West
Find out why Werner Vogels' comments ring especially true for healthcare data.

5 min read

Read more
Security
Security
2 Apr 2020
Update on HAproxy HTTP/2 HPACK Decoder Vulnerability (2 April 2020) Tom Hopkins
A critical vulnerability in HAProxy’s HTTP/2 HPACK decoder in versions 1.8 and above has been discovered. This does not impact the majority of Loadbalancer.org customers.

1 min read

Read more
Security
Security
20 Jun 2019
SACK Panic: What is it, and is it actually time to panic? Andrew Howe
Four closely related vulnerabilities regarding TCP handling in the Linux and FreeBSD kernels were publicly disclosed on 17 June 2019. Dubbed as “SACK Panic”, the main vulnerability can cause a Linux operating system to crash

2 min read

Read more
News
News
23 May 2019
Huawei root access is BAD! VERY, VERY BAD: Or, how we reasoned ourselves out of root access by default Malcolm Turnbull
As you probably know, the notorious Chinese tech company was blacklisted by Google on the instructions of the Trump administration. All this high-profile paranoia about security got me thinking about our approach to the subject as we prepare to release v8.3.7 of the load balancer appliance...

4 min read

Read more
How-To's
How-To's
7 May 2019
How do I secure my load balancer with Active Directory, LDAP or RADIUS? Neil Hosking
I’ve noticed a lot more of our customers are asking to use their Active Directory login details with the load balancer appliance. And it can get a bit fiddly, so I wanted to write

4 min read

Read more
Security
Security
1 Mar 2019
FTPS Implicit vs FTPS Explicit: Who will win? Imannuel Graham
“Load balancing FTP can be loads of fun for system and network administrators alike!” - said nobody ever. Implementation of FTP and configuration of your firewalls can be cumbersome, especially when it comes to being

4 min read

Read more
Just for Fun
Just for Fun
31 Jan 2019
What is a load balancer? Annu Sroa
We explain the concept of load balancing, what it's for - and what a load balancer actually does.

4 min read

Read more
HAProxy
HAProxy
8 Jan 2019
New year, new vulnerability: HAProxy critical security update Annu Sroa
The Christmas tree is still up, you’ve barely swept away the used party poppers and champagne corks from your New Year celebrations - and already, there’s a new security issue to be aware

4 min read

Read more
Web Application Firewall (WAF)
Web Application Firewall (WAF)
2 Nov 2018
Brute force login: Simple protection techniques with the ModSecurity WAF Andrei Grigoras
The web-based login to your application is a juicy target for hackers. And once they get past the login, they can cause you some serious pain. If you have a WAF (Web Application Firewall), though,

5 min read

Read more
Web Application Firewall (WAF)
Web Application Firewall (WAF)
22 Oct 2018
Darktrace: When looks aren't everything Malcolm Turnbull
These are scary times when it comes to cybersecurity. Following on from high-profile breaches at Equifax, British Airways, Ticketmaster, Newegg and more, it’s not surprising that companies are prepared to pay top dollar for

4 min read

Read more
HAProxy
HAProxy
20 Sep 2018
HAProxy critical security update — to avoid simple(ish) DoS attack (20 September 2018) Annu Sroa
A critical security issue has been found in HAProxy, leaving certain systems vulnerable to remote attack. We want to keep you informed, and we understand that this news might cause you some anxiety. But be reassured - most of our customers won’t be affected.

3 min read

Read more
SSL
14 Sep 2018
Let's Encrypt — how did we survive without it? Rob Congalton
Let’s Encrypt is awesome! Not only is it more secure than your existing certificate authority. It's also reliable, scalable, fully automated — and free!

7 min read

Read more
SSL
27 Apr 2018
How to add Cloudflare in front of HAProxy Thorsten Wetzig
What is Cloudflare? Cloudflare provides a content delivery network (CDN). A CDN is a worldwide network of servers that delivers web content to clients based on the geographic location of the client. Using the Cloudflare

12 min read

Read more
Security
Security
26 Sep 2017
Security through obscurity - double login protection made easy... Malcolm Turnbull
Security through obscurity is not a great idea when it is your ONLY protection technique. For example moving your SSH port from 22 -> 23 won't fool any hackers for long! However, I've always liked putting a 'double login' in front of important web sites to frustrate simple automated hacking tools.

3 min read

Read more
HAProxy
HAProxy
15 Aug 2017
Client Certificate Authentication with HAProxy Aaron West
Using client certificates for security is a pretty cool idea! You can protect an entire application or even just a specific Uniform Resource Identifier (URI) to only those that provide a valid client certificate.

9 min read

Read more
How-To's
How-To's
5 Jul 2017
How to stop web form spam — use a simple honey pot trap in ModSecurity... Aaron West
How frustrating do you find it when hackers or robots fill in your website forms with "Buy Viagra Now!" type spam?

4 min read

Read more
Security
21 Jun 2017
Stack Clash and Loadbalancer.org Dave Saunders
Background I was reading about the Stack Clash vulnerability last night and it seems that this is something which has been around before, been fixed twice and then another method to trigger the exploit has

2 min read

Read more
Web Filters / Proxy
Web Filters / Proxy
14 Jun 2017
Transparent vs Explicit proxy — which method should I use? Neil Hosking
Different vendors have widely different opinions on which method should be used to deploy web filters or SWGs (secure web gateways). Historically, vendors struggled to implement authentication in Transparent mode, and maybe they remember some

5 min read

Read more
Security
Security
22 Feb 2017
Not so sweet, Sweet32 vulnerability... Dave Saunders
It's a little bit late but I wanted to write a short entry about how to deal with the Sweet32 vulnerability which was announced towards the end of last year.  I'm going to avoid regurgitating

1 min read

Read more
Security
Security
19 Oct 2016
Blocking Japan with ModSecurity and Maxmind Lite Theo Garvey
Accessibility is the magic word for todays blog. If you’re lucky enough to run a website, then the whole world has access to it by default! Now lets imagine that the website you’re

2 min read

Read more
Security
9 Nov 2015
New PuTTY vulnerability "vuln-ech-overflow" identified - upgrade to 0.66 to protect your environment Dave Saunders
Information It has been identified that versions of PuTTY, PutTTYtel and pterm are vulnerable to a potential exploit in the handling of ECH (erase characters), affecting versions 0.54 to 0.65. Due to the

1 min read

Read more
News
3 Sep 2015
Loadbalancer.org partner with Sucuri for cloud based WAF & DDOS protection Andrew Zak
During the last year at Loadbalancer.org we have spent a lot of time and effort researching WAF (Web Application Firewall) solutions. The integrated WAF in version 8 of the Loadbalancer.org appliance has been

3 min read

Read more
News
News
20 Aug 2015
It's great to be v8 Dave Saunders
As the evolution of of Loadbalancer.org continues, we are proud to present our latest software release, v8.0. New features such as the Web Application Firewall (WAF) spearheading our increased focus on security and

2 min read

Read more
Denial of Service
18 May 2015
Blocking invalid range headers using ModSecurity and/or HAProxy (MS15-034 - CVE-2015-1635) Malcolm Turnbull
Microsoft quietly patched a fairly nasty little bug (MS15-034) in IIS last month: A simple HTTP request with an invalid range header field value to either kill IIS, reveal data or remotely execute code! We

4 min read

Read more
Denial of Service
Denial of Service
6 Mar 2015
Simple Denial of Service DOS attack mitigation using HAProxy Malcolm Turnbull
Denial of Service (DOS) attacks can be especially effective against certain types of web application. If an application is highly dynamic or database-intensive it can be remarkably simple to degrade or cripple the functionality of

4 min read

Read more

Get started

Get in touch

Start a conversation about the right solution for your business.

Get in touch

Create your quote

Transparent pricing you can see straight away.

Create your quote

Download now

Try us free for 30 days – see why our customers love us.

Download now

Schedule a virtual meeting with us

Working remotely or from home? Let’s meet on a call or online.

Let's meet

Follow Loadbalancer.org

+1 833 274 2566
  • Company
    • Solutions
    • Services
    • Load balancer
    • Why Loadbalancer.org
    • Blog
    • Professional services
    • Sitemap
  • Load balancer
    • Get a quote
    • Free trial
    • Online demo
  • Resources
    • Manuals
    • Deployment guides
    • Applications
    • White papers
    • Case studies
    • Solutions
  • Support
    • FAQ's
    • Open a ticket
    • Security news
  • Applications
    • Healthcare
    • Storage
    • Print
    • Security
    • Microsoft
The latest insights from the load balancing experts | Loadbalancer.org

The latest insights from the load balancing experts | Loadbalancer.org. All rights reserved

  • Contact Us
  • Terms & Conditions
  • Privacy Policy