Activity Stream
48,167 MEMBERS
6325 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 1 of 2 12 LastLast
Results 1 to 10 of 17
  1.     
    #1
    Member
    Website's:
    unknown-bb.com

    Default securing vb forum

    my forum has been messed up twice over the weekend by x0r the wanker he makes the site redirect we changed everything new files etc etc and he still got in

    1 how does he do this
    2 how can we prevent him gaining access again?
    lenney Reviewed by lenney on . securing vb forum my forum has been messed up twice over the weekend by x0r the wanker he makes the site redirect we changed everything new files etc etc and he still got in 1 how does he do this 2 how can we prevent him gaining access again? Rating: 5

  2.   Sponsored Links

  3.     
    #2
    Banned
    did you remove the "install" folder? rename the admincp modcp etc?

  4.     
    #3
    Member
    Website's:
    unknown-bb.com
    yup he got access to mysql we think im about to download the latest version of vb and try that way

  5.     
    #4
    Respected Member
    I would suggest moving hosts as soon as possible if you've tried everything than he could have gotten access by hacking into your host if that's the case then there's nothing you could do.
    "Maybe this world is another planet's Hell"

  6.     
    #5
    Member
    Website's:
    unknown-bb.com
    thats the worst thing we moved servers over the weekend aswell

  7.     
    #6
    Member
    Website's:
    MovieBin.org TVBin.org MusicBin.org HDBin.org TheBinNetwork.org
    Rename you admincp and modcp directorys to something like:
    "FoVCPY6ANhYXl73lwmCTjZ8gxYWUzGu5uG79e4ArbYFDW8oJl r"
    Use tubenets pass generator to get dir names. http://tubenow.net/pass-generator/

    Password protect admincp and modcp, (once again safest bet use a pass generator http://tubenow.net/pass-generator/)

    Remove the thread.php file from modcp as that is what they can use to prune the forum, As your smods shouldn't really need to mass prune as they can do it through the forum.

    Make sure you use secure email accounts. best option is to use a personal one like [email protected] so people cant revert it like at hotmail. also make sure all mods don't use hotmail as it is easy to revert.

    Also what you could do is if you admin account keeps getting hacked is setting up a user account random make that full admin but make it look like a normal user and just use that to do admin stuff then make you account have no options in admincp or very few so people will try to hack you account and if they do they can't do fuck all with it.
    TheBinNetwork - MovieBin | TVBin | MusicBin | HDBin
    TheBinNetworks News!
    Happy Hardcore and Drumb & Bass kick ass!

  8.     
    #7
    Member
    Check your files again.

  9.     
    #8
    Member
    Website's:
    unknown-bb.com
    thanx sherwood i have done them all now and badboy i have uploaded a clean set of files with no mods done

  10.     
    #9
    Banned
    lenny change the db username like if its warezto_forum change it to warezto_jhf56hfc4 <--- or something like that plus change that pass

  11.     
    #10
    Banned
    Website's:
    SmartWarez.org SwoImage.com MazaOnline.com
    That's from vbulletin...

    How To Make My Forums More Secure
    Here's some things you can do to increase the level of security for your forums:

    1. Always upgrade to the latest stable version.

    2. Do not install any unofficial hacks or plugins as they are not written or reviewed by our developers.

    3. Password protect your Administrator and Moderator Control Panels directories using .htaccess/.htpassword http://www.javascriptkit.com/howto/htaccess3.shtml

    4. Make sure the tools.php (vB3) file is NOWHERE on your website.

    5. Although this is only a potential problem if someone gets a hold of your customer number, you should remove the upgrade* files from the install directory.
    6. Remove the ImpEx files if you had used this import system.

    7. If you have phpMyAdmin make sure it's password protected.

    8. If you suspect a hacking attempt, ask your host to change the login password for your web account.

    9. Make sure all the Admin and Mod passwords are secure. Change them if you have any doubts. And use hard to guess passwords.

    10. Enable the 'strikes' system which will help thwart brute force password attempts:

    Admin CP -> vBulletin Options -> General Settings -> Use Login "Strikes" System -> Yes

    11. NEVER allow HTML in posts, PMs or in sigs.

    12. Make absolutely sure there are no viruses, trojans or keylogger spyware on your PC. Any of these could steal your password and other personal info.

    13. Do NOT upload the directory called do_not_upload/

    14. Use a different password for each forum you sign up with. Use a different password for your forum as you do for the .htaccess directory password.

    15. Update the config.php file and set yourself as undeletable user so they can't touch your admin account.

    Note your forums are only as secure as the passwords you use and the server it is on. If the server is accessed then there's nothing vB can do to prevent potential security violations.


    If you have and the other admins have a unique IP address you can edit the .htaccess file in your admincp directory with.

    order allow,deny allow from <your IP>
    allow from <admin2's IP>
    deny from all

    This way the directory should not load for anyone whose IP doesnt match this list.

    __________________

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Securing php-fpm with nginx
    By masterb56 in forum Technical and Security Tutorials
    Replies: 4
    Last Post: 29th Aug 2011, 08:46 AM
  2. [TUT] Securing /tmp and /dev/shm partion
    By .:Raymond:. in forum Technical and Security Tutorials
    Replies: 6
    Last Post: 9th Jun 2011, 08:47 AM
  3. [TUT] Securing SSH a bit ;)
    By .:Raymond:. in forum Technical and Security Tutorials
    Replies: 13
    Last Post: 9th Jun 2011, 08:29 AM
  4. Need help securing VPS!!
    By lukip006 in forum Server Management
    Replies: 5
    Last Post: 31st Aug 2009, 04:14 PM
  5. VBulletin Forum Securing Service - Cheap, Reliable, and Worth It.
    By wildfire95 in forum Completed Transactions
    Replies: 6
    Last Post: 20th Jun 2009, 02:39 PM

Tags for this Thread

BE SOCIAL