Pages

Wednesday, June 6, 2018

Publishing Static Website on AWS using S3 bucket with a custom domain name

Hi Friends,

I am starting a new series on my blog related to AWS.

As the first post under AWS series , I will show : 


How to publish a Static Website on AWS using S3 Bucket with custom domain name



Solution :



Prerequisites: We will need following prerequisites to host our static website on AWS using S3 Bucket with a custom domain name

1. A domain name (e.g. lalitgolani.tk) registered with a domain name registrar (like godaddy.com).
2. An AWS subscription (I am using the free tier subscription for this demo)
3. Static HTML files that you will upload to your website hosted on S3 bucket in AWS



Steps: 



Create a S3 bucket :

Create a S3 bucket with the same name as your domain name is: (in this example : lalitgolani.tk)

  • Log on to your AWS subscription 
  • Go to Services and select S3 under Storage section
  • click on Create Bucket button
  • At the next screen type the name of the bucket same as your custom domain name (in this example : lalitgolani.tk)
  • Click Next and keep the settings intact in "Properties" section, click next
  • In the Permissions tab on the create bucket window, select "Grant Public Read Access to this bucket"
  • Click Next to reach to review window and click "Create Bucket".




  • Once the your S3 bucket is created. Now its time to enable "Static Website Hosting" property on it.
  • Go to the S3 area of your AWS subscription and select the S3 bucket you just created (lalitgolani.tk)
  • Then go to its properties and select "Static Website Hosting" property
  • Select the first radio button "Use this bucket to host a website" and in the next text box put the name of the default page of your static website you want to display on your website as homepage. (e.g. index.html)
  • Click "Save" and get out of the properties of your S3 Bucket.




Register your Custom Domain Name (host name) with Route53.


  • Route53 is an excellent DNS service provided by AWS to route your request to other DNS name and register DNS names of your choice.
  • Go to Services and then Select "Network & Content Delivery" section and select Route53 
  • On Route53 page , select "Hosted Zones" under "DNS Management" category


  • Now enter the name of your custom domain registered with domain registrar in the "Create Hosted Zone" . This should be exactly same as your website name that you want to publish.
  • Select "Public Hosted Zone" in Type property.
  • Lastly click on "Create" button

  • As soon as you click on Create you will see a "Hosted Zone" with name (lalitgolani.tk in our case) has been created.

  • Select that hosted zone that you just created, you will notice that 2 Record Sets have already been created (One NS record and one SOA)
  • Copy the NS (Name Server) record set details in the Notepad as these will be used to update the Name Server records for your website name on the domain registrar's website where you have registered your custom domain from.

  • Now create a new Record Set (Similar to Host A Record) on the Route53 console which will point to your S3 bucket (which we had created in previous step)


  • On the Create Record Set window keep the Name field untouched as we have already mentioned our domain name (lalitgolani.tk)
  • Make sure the Type field is selected as A-IPv4 Address
  • Click on Alias and select Yes
  • In the next field "Select the S3 Bucket" you had created in previous step. 
  • This will make the Hosted Zone as an Alias of S3 bucket (Host A record in DNS language)
  • Click on Create.
  • You will see a new Record Set create pointing to S3 Bucket. 




Now 70% of your task has been done.

Updating Name Server Details for your Domain name on Domain Registrars website. 


This is an important step when you are hosting your website on S3 bucket with a custom domain name of your choice. (like lalitgolani.tk)

  • Go to your Domain Registrars Website where you bought your custom domain from (for example Godaddy.com)
  • Login to your account.
  • Go to the properties of your domain (in our case lalitgolani.tk)
  • Select Name Server details and update these name server details as per record sets we had copied in Notepad.
  • Note that changing the Name Server details on your custom domain name registrar's website may take 24 hours to 48 hours to reflect for all. This depends on the frequency of publishing Name Server details set by your Domain Registrar. 




Upload the Website files (html files) on your S3 Bucket to be published


Now as the last step you will upload your web files (html) that you want to publish using S3 bucket and Route53 hosting facility of AWS.

  • Go to your S3 bucket you had created in previous step and select that (here lalitgolani.tk)
  • Click on Upload button then select add files
  • Navigate to the location on your local computer where your html files have been kept , select them and click Open.
  • Now click next and in the "Set Permission" section select "Grant Public Read Access to this object(s) under Manage Public Permissions.  (Setting public Read access permission is necessary to enable these files to be accessible to public on your website hosted on S3 Bucket")
  •  and then click on upload.
  • These files will be uploaded to the S3 bucket root 




  • Once you upload your html files to your S3 buckets they are visible under your bucket as following : 


And thats it, you have completed all the steps to host your custom domain website on AWS S3 bucket through Route53 feature.

Now its time to test.


Go to your web browser and type the name of your website you have configured on AWS S3 bucket in previous steps (here lalitgolani.tk)

And here you go................










Enjoy!!! Feel free to comment on this blog post.















Thursday, December 7, 2017

How To Remediate Server_Info and Server_Status Information Disclosure vulnerabilities from Apache http server

If you are an administrator or webmaster of an internet facing website, it becomes mandatory for you to keep your website safe and secure from seen \ unforeseen threats.

Many a time your organization's security team or the PCI compliance team scans your webserver to check the robustness and security of your server. 
In my today's post , we will discuss : 

How to Remediate Server_Info and Server_Status vulnerabilities on Apache HTTP Server.


When you get the vulnerability scan report  for your Apache HTTP server , the above mentioned vulnerabilities may be listed like following : 
  •  Apache mod_info /server-info Information Disclosure Vulnerability - Apache mod_info is a module package in Apache which provides a comprehensive overview of the server configuration.
  • Apache /server-info Information Disclosure - An information disclosure vulnerability in the Apache Web server allows attackers to view system configuration data.
  • Apache /server-status Information Disclosure - An information disclosure vulnerability in the Apache Web server allows attackers to view sensitive configuration data on the targeted host.

If they find any vulnerability on your webserver they come up with the vulnerability \ threat report and you are asked to remediate \ mitigate these vulnerabilities as soon as possible.

/Server_Info & /Server_Status are two important tags in Apache HTTP server which are used by the Webmasters, or Web Server Administrators to check the status and details of the server, But both of these pages can be exploited by attackers out there with malign intentions. So it becomes imperative for the administrator to either disable these 2 pages or restrict there access.


In an ideal situation , Server_Info and Server_Status pages should only be accessible locally from the web server but not from the out side of the server.


Solution: 

To restrict the access of /server_info & /Server_Status pages only to locally :
  1. Log on to the server where Apache is installed.
  2. Go to Apache installation directory
  3. Navigate to Conf folder 
  4. Take a backup of httpd.conf file
  5. Now Edit the http.conf file and update following 2 sections as given below:
      

<Location /server-status>
      SetHandler server-status
      Order deny,allow
      Deny from all
      Allow from 127.0.0.1
  </Location>

  <Location /server-info>

      SetHandler server-info
      Order deny,allow
      Deny from all
      Allow from 127.0.0.1
  </Location>

Save the httpd.conf file and restart the Apache services on your server.

These settings will enable Apache Http Server to display the /server_info   & /Server_status pages only when they are accessed locally (means from the same server where Apache is installed). All other requests coming from other sources to access these 2 settings will get "Access denied" error.

That's it!!!!



Note : If you have installed Apache as a subproduct of XAMPP then you will have to update the httpd_info.conf file instead of httpd.conf

The next time you get your Apache server scanned for vulnerabilities, you will not find the vulnerabilities listed above.
        

Wednesday, November 29, 2017

Manage your Own Pageviews doesn't work in Blogger with Custom Domains

If you are in to Blogging and writing blogs using Blogger or Blogspot, on any topic of your choice. I am sure that you will be concerned about your page views and its reach to your audience. In this tryst you keep watching the stats of your blog posts to see who is watching your blog posts and from where.

Tracking of pageviews of your blogposts give you an absolute idea that how can you make your blog more interactive and increase its reach to more audience.

Tracking of your blogpost views is quite simple in Blogger. 

You just need to log on to Blogger --> select the blog (From drop down menu at the Top Left corner) --> click to Stats

It will give you the detailed view of all pageviews (location and date wise) in tabular as well as graphical format.

But these stats also include your own pageviews that you might have clicked to see the look and feel of your blog posts. 

Being an honest blogger you will never want to show your own pageviews in overall statistics of your blog posts. Specially when you show your overall pageviews on your blog.

How to stop tracking your own page views in Blogger : 


Scenario 1: 


If you are using simple blog name like https://<yourblogname>.blogspot.com then it is quite easy to stop tracking your own page views.

Just follow these steps : 



     
  1. Log on to Blogger
  2. Select your blog from the drop down menu in the top left corner of the screen
  3. Click on Stats
  4. In the upcoming page , click on "Manage tracing your own page views" (See Pic 1)
  5. In the next page check the Check Box " Don't Track my pageviews for this blog (Pic 2).
Pic 1 : Manage Tracking your page views



Pic.2 : Manage Tracking your page views



And that's it. It will tell the Blogger to not to track the page views from your this browser.


Scenario 2 : 


When you are using a custom domain name (www.yourwebsite.com) where your blog is getting redirected to and you have not configured https (SSL) on that domain name like in my case (www.lalitgolani.com). 

When you click on ""Manage tracing your own page views" you run in to following error : 

"This site can't be reached. www.sitename.com unexpectedly closed the connection.

Error on Manage Tracking page

Reason : 

You face this issue because you are (1) Using the custom domain name for your website and (2). You have not enabled HTTPS on your custom domain name. Blogger enables SSL by default on your normal blog name which ends with "Blogspot.com" but if you are using custom domain name for your blog then you will need to buy an SSL certificate and configure it with your website name. And this incurs cost.

Solution : 

To solve this problem and enable yourself to "Manage Tracking your Own Pageviews" with the custom domain name of your Blog , just remove "HTTPS" from the address bar and hit enter.

This will lead you to the same page where you can manage your page view tracking settings.



Note: If you are using more than one browser on your machine and want to stop Blogger to track all your own page views, you will need to follow the above steps from all your browsers.


This solution worked for me like a charm. Hope it will work for you guys too !!!!!!!





Monday, November 27, 2017

Generating Self Signed SSL Certificate using OpenSSL on Windows machine


In my last post , we had learned How To Generate CSR using OpenSSL

Now when we have created CSR , we will use this CSR (Certificate Signing Request) to create a Self Signed Certificate.

So Lets get Ready for 

Generating Self Signed SSL Certificate using OpenSSL on Windows

For generating a Self Signed Certificate using OpenSSL on a windows machine we need following 3 things : 


  • OpenSSL installed on the machine.
  • A root CA (Certification Authority
  • A Private Key
  • A CSR file

We have already created a CSR in my last post but here we will create another CSR after we create the CA and Intermediate CA in OpenSSL

Creating Root CA in OpenSSL

For creating a Root CA in OpenSSL follow these steps from your OpenSSL console in Command Prompt.

1. Generate Root CA key through this command 

           genrsa -out lalitca.key 4096

         This command will generate a 4096 bit strong RSA key for our Root CA 
         and will store it in key file with name lalitca.key.


Note : If you want to password protect this key , simply add the -des3 option in the above command. For the sake of simplicity I have just skipped this option.

2. Now based on this CA Key we will create our Root CA certificate. We will have to give our Root CA an identity like Country, State, Location, Organization, OU, CommonName etc. Put in all this information carefully.

           req -new -x509 -days 3652 -key Lalitca.key -out Lalitca.crt



Note :  We using -x509 switch to create self-signed certificate and -days 3652 switch insures that this RootCA certificate will be valid for 10 years.


Now we have the Root CA in place. We are all set to create a CSR which will be used to create a self Signed certificate signed by this Root CA.

Creating a CSR 

Execute following 2 commands in same order to generate Private Key and CSR file.

                               genrsa -out test.key 4096

                         req -new -key test.key -out test.csr

Put in all required information again (Country, State, Location, Organization, Organization Unit, Common Name) Etc.

Note : Make sure you give a different Common Name (in this step) than Root CA. Otherwise you will run in to an error at later stage.





Now we have all 3 things in place (OpenSSL, RootCA and CSR). Its now time to generate our first Self-Signed certificate from OpenSSL.

Execute following command to create the certificate based on CSR and get it signed by RootCA we created in above steps.


x509 -req -days 1095 -in test.csr -CA lalitCA.crt -CAkey lalitca.key -set_serial 01 -out lalit.crt

This command will give you results like following : 

Signature ok
subject=C = US, ST = Arizona, L = Tempe, O = Lalit, CN = web.lalitgolani.com
Getting CA Private Key



And that's it.

You have successfully created your RootCA and first Self-Signed certificate using OpenSSL on a windows Machine.


In my next post , I will show how to convert the .CRT file in to .P12 (PFX) file and install it on IIS.
    

Friday, November 24, 2017

How To Generate Certificate Signing Request (CSR) or Private Key Using OpenSSL on Windows Machine

In my last post we had learned  How to Install OpenSSL on Windows Machine.

Now When we have successfully installed Open SSL on our windows machine , its time to use the OpenSSL for all stuff related to SSL.

In my following post , we will learn how generate Certificate Signing Request (CSR) file or Private Key which we send to Certification Authority to create SSL against. 



How to Generate CSR \ Private Key using OpenSSL


Step 1. To Generate a CSR using OpenSSL on Windows machine 
            open the Command Prompt as Administrator and navigate to 
            C:\OpenSSL-Win32\bin and type openssl.exe and hit enter.

            


Step 2.  Once the OpenSSL command line interface is visible, type following 
            command to create the Private key. This Private Key will be used to 
            create the CSR file.

            genrsa -out "C:\OpenSSLCertificates\private-key.key" 2048
            
            on successful execution of above command , you will get following 
            output in command window.

Note :  I have specified the path (C:\OpenSSLCertificates) to save all keys and files at centralized location and for the sake of convenience. 
            

Step 3.  Now execute the following command to generate CSR file out of Private 
            Key created in Step 2.


              req -new -key C:\OpenSSLCertificates\private-key.key -out         
              C:\OpenSSLCertificates\www_lalitgolani_com_csr.txt


As soon as you hit the enter button , you will be asked to fill in following details to complete the CSR creation request. Fill in all this information with utter attention to avoid any issues at later stage.

  • Country Name: Put in the first 2 letters of country where the site belongs to. Example : IN
  • State or Province: Spell the complete name of State , Example : Rajasthan
  • Locality or City: Enter your town name :  For example : Jaipur
  • Company: Enter the Company Name if you have any
  • Organizational Unit: Enter the department name which this website is for. You can leave this blank if you dont want to reveal the department name.
  • Common Name: This field is most important. Put in the full name of your website for which you want to create the SSL certificate. Make sure you put the correct name of the website because the SSL certificate will be created based on the this common name only. In your example I have put the Common name as : www.lalitgolani.com 

Note :  Please make sure to not to enter an email address, challenge password or an optional company name when generating the CSR.

 As soon as you complete the above details and hit enter a CSR file will be generated at path which you have mentioned in above command. In our case it will be created on path C:\OpenSSLCertificates with name www_lalitgolani_com_csr.txt



Step 4 :  Now the CSR file (.txt) for your SSL certificate is ready. Just pick the CSR file and send it to any certification authority like Digicert, Verisign etc to get SSL certificate generated against it.


In my Next post I will show how to create the self signed certificate using Open SSL.



Thursday, November 23, 2017

Install OpenSSL on Windows

Being a webserver administrator , you are many a times required to request SSL certificates, install them on websites, or need to convert them to other formats like .Crt, .Pfx, .p12 etc....

Though there are many tools available in the market \ internet which can convert your SSL certificate to other formats bus the best and handy tool , i suppose, is OpenSSL.

OpenSSL can be installed on your local machine (Windows or Unix) and you can play around with it , tweek things, and learn how does it operate.

In this blog post I will share : 

How to Install OpenSSL on Windows

Step 1:  Download the Windows version of OpenSSl from here. You wouldn't 
             find the binaries on Openssl.org site. I would suggest to download the 
             full version (around 30 MB) as it will give you more options to play 
             around. ( Latest OpenSSL version for Windows 32 
             bit is Win32 OpenSSL v1.1.0g

Step 2:  Save the exe file at any location of your system and double click it.

Note :  You may run in to following error if Microsoft Visual C++ Redistributable Package is not installed on your machine. It is prerequisite to have it installed before you go for OpenSSL installation. You can download it from Microsoft's Download store.

                               

Step 3: Click next and keep the default path of installation as C:\OpenSSL-  Win32.

             

Step 4: Leave the default settings as it is for next screen and click Next 


                               

Step 5:  Once all parameters are set, click Install


                               

If all is fine on your machine it will install OpenSSl on your machine in less than 2 minutes. For my machine it took exactly 1 minute 32 seconds.

Once the OpenSSL is installed , just click finish. 

If you you want to donate few bucks to OpenSSL select any of the check box.

                               


Step 6 :   I want to create the certificates in folder C:\OpenSSLCertificates. So 
               create a folder called OpenSSLCertificates in C drive of your machine.


Step 7 : Now start a command prompt as administrator and go to 
            C:\OpenSSLCertificates.

Step 8 : Once OpenSSL has been successfully installed on your 
            Windows machine and you have created a folder to store certificates , 
            you will obviously want to run it. But before running it you should set 
            following 2 Environment Variables. 

            Put the following 2 commands in your command window

               set RANDFILE=c:\OpenSSLCertificates\.rnd

               set OPENSSL_CONF=C:\OpenSSL-Win32\bin\openssl.cfg


                            


Step 9 : Now you are all set to run OpenSSL.  To run it go to path C:\OpenSSL-
            Win32\bin and Right Click OpenSSL.exe and select Run As 
            Administrator


                               

Step 10 :  If you have followed all above steps properly , you should see 
               following screen 


                              



Your comments are welcome about this post!!!!!