Featured Articles

Useful

OpenSSL Cheat Sheet: Common SSL / TLS Commands

Never forget an OpenSSL command again. This comprehensive cheat sheet covers certificate conversion (PFX, PEM, DER), CSR generation, and remote SSL / TLS verification for Windows and Linux admins.


Latest articles

Windows Server

Last updated:

Create strong passwords in Windows

Learn how to create strong and unique passwords in Windows using PowerShell, because the use of those unique and strong passwords is important.

Useful

Last updated:

Calculate SHA-256 checksums in PowerShell

Learn how to calculate and create file checksums with PowerShell's Get-FileHash and certutil.exe. Use this to validate file integrity in Windows (Windows Server).

Padlock Locked on Gate

Windows Server

Last updated:

Install SSL / TLS certificates in Windows Server using PowerShell

Use PowerShell to install SSL certificate in Windows Server and change its FriendlyName property. As a bonus, I show you how to verify a certificate's Common Name (Subject) and Subject Alternative Name (SAN) using certutil.exe and PowerShell Get-PfxCertificate.

Spider

GNU/Linux, Web applications

Last updated:

Blocking bad bots and search engines using .htaccess

Take control of your server resources by learning how to block aggressive bots and unwanted search engines using .htaccess and mod_rewrite. This guide provides copy-paste ready configurations to prevent bandwidth theft, stop scrapers, and ensure that only relevant search engines crawl your website.

Windows Server

Last updated:

YubiKey support in OpenSSH for Windows 11

YubiKey support in ssh for Windows: secure your Windows environment by moving SSH private keys to hardware. Learn how to configure YubiKey FIDO2/U2F support in native OpenSSH, manage the ssh-agent, and eliminate file-based credential risks.

Windows Server

Last updated:

3 Ways of blocking sendmail.php on IIS webserver

Block PHP files like sendmail.php on Windows Server IIS webservers. This comes in handy if a websites on your webserver sends out spam and you need to block access to a script on a specific website or globally in IIS. Here are 3 methods.

OpenSSH logo

Security, Windows Server

Last updated:

Retrieve SSH public key from Active Directory for SSH authentication

Storing SSH public keys in Windows Server Active Directory gives you a single location where you manage public SSH keys instead of on numerous separate servers. This is easier than distributing and managing numerous unmanaged authorized_keys files across your network and servers.

Windows Server

Last updated:

Add, list and remove IP addresses in Windows Firewall

Add, list, and remove IP addresses in Windows Firewall (PowerShell & netsh): How to bulk add IP addresses in Windows Firewall, list an IP address and how to remove all IP addresses from Windows Defender Firewall with Advanced Security...

Apache HTTP server logo

GNU/Linux

Last updated:

Force HSTS in Apache .htaccess

Learn how to enable HSTS (HTTP Strict Transport Security) in Linux Apache .htaccess. I wrote about enabling HTTP Strict Transport Security (HSTS) in IIS earlier. But what about enabling HSTS in Apache .htaccess? Here is how.

wpcount registered users at a glance dashboard

WordPress

Last updated:

Count and display number of WordPress users in your Dashboard

Show the number of registered WordPress users in a At-a-Glance widget. This is particular handy as an indicator of compromise (IoC), when a hacker has registered numerous new users in your WordPress database for spam purposes.

WordPress

Last updated:

Disallow direct access to PHP files in wp-content/uploads/

Securing the WordPress uploads folder is important. In many hacked WordPress sites, a PHP backdoor is found within the WP_CONTENT_DIR/uploads directory. Often because this is the location where uploads are placed automatically. From the backdoor within wp-content/uploads other backdoors are uploaded to various locations, and scripts are injected with malware.

Lego security officer keeping your sites secure

Security

Last updated:

.htaccess security best practices in Apache 2.4.6+

Since Apache 2.4.6, a new module is used to configure and set up access control for websites: mod_authz_core. This means you have to use a different syntax for allowing or blocking hosts and IP addresses to your website. Apache Access Controle done right in WordPress .htaccess.