Activity Stream
48,167 MEMBERS
6925 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 1 of 2 12 LastLast
Results 1 to 10 of 13
  1.     
    #1
    Member
    Website's:
    Rapidforums.org AmarGram.com

    Default How To Make My Forums More Secure

    Here's some things you can do to increase the level of security for your forums:

    1. Always upgrade to the latest stable version.

    2. Do not install any unofficial hacks or plugins as they are not written or reviewed by our developers.

    3. Password protect your Administrator and Moderator Control Panels directories using .htaccess/.htpassword http://www.javascriptkit.com/howto/htaccess3.shtml

    4. Make sure the tools.php (vB3) file is NOWHERE on your website.

    5. Although this is only a potential problem if someone gets a hold of your customer number, you should remove the upgrade* files from the install directory.
    6. Remove the ImpEx files if you had used this import system.

    7. If you have phpMyAdmin make sure it's password protected.

    8. If you suspect a hacking attempt, ask your host to change the login password for your web account.

    9. Make sure all the Admin and Mod passwords are secure. Change them if you have any doubts. And use hard to guess passwords.

    10. Enable the 'strikes' system which will help thwart brute force password attempts:

    Admin CP -> vBulletin Options -> General Settings -> Use Login "Strikes" System -> Yes

    11. NEVER allow HTML in posts, PMs or in sigs.

    12. Make absolutely sure there are no viruses, trojans or keylogger spyware on your PC. Any of these could steal your password and other personal info.

    13. Do NOT upload the directory called do_not_upload/

    14. Use a different password for each forum you sign up with. Use a different password for your forum as you do for the .htaccess directory password.

    15. Update the config.php file and set yourself as undeletable user so they can't touch your admin account.

    Note your forums are only as secure as the passwords you use and the server it is on. If the server is accessed then there's nothing vB can do to prevent potential security violations.
    kamrul Reviewed by kamrul on . How To Make My Forums More Secure Here's some things you can do to increase the level of security for your forums: 1. Always upgrade to the latest stable version. 2. Do not install any unofficial hacks or plugins as they are not written or reviewed by our developers. 3. Password protect your Administrator and Moderator Control Panels directories using .htaccess/.htpassword http://www.javascriptkit.com/howto/htaccess3.shtml 4. Make sure the tools.php (vB3) file is NOWHERE on your website. Rating: 5

  2.   Sponsored Links

  3.     
    #2
    Member
    Website's:
    Rapidforums.org AmarGram.com
    If you are on a shared hosting server, make sure all your vBulletin PHP files are chmod 644

    cd /path/to/your/vbulletin
    chmod -R 644 *.php

  4.     
    #3
    Member
    Website's:
    Rapidforums.org AmarGram.com
    Renaming Admincp and Modcp Folders For Additional Security

    Every hacker knows the default paths to the vbulletin admincp and modcp control panels. www.yoursite.com/forum/admincp or www.yoursite.com/forum/modcp By knowing these paths, hackers by pass going through the forums first before attempting to hack into your admincp or modcp.

    If you rename the admincp and modcp folders, they will have to hack your log in for the forums first before they are able to find these folders. You can rename these folders anything you like. Here are a couple of examples: www.yoursite.com/forum/firstcp and www.yoursite.com/forum/secondcp

    Rename these two folders on your ftp site and change your config.php file to match the names of the new folders.

    If you rename your admincp and modcp folders, you MUST change the names of the these in the config.php file to match what you renamed them.

    Tip: If you are upgrading your forums make sure you don't forget to rename the directories again!

  5.     
    #4
    Member
    Website's:
    Rapidforums.org AmarGram.com
    Pick your staff members wisely. You give them access to more commands which allows them to harm your site.

    Once they are a moderator they can ruin the mood on your site, they can mass delete posts if they have the permission and they can edit the posts of existing members. Super moderators can do this in every forum.

    Super Moderators and Moderators have access to the modcp/ directory, but not the admincp/ directory.

    If you give someone Administrator access on your forum you basically give them full access to your site (except for FTP). They can download your database or delete forums and usergroups, delete threads and posts or change settings, etc. So check your admin permissions on a per admin user. And think twice before you give someone admin access to your forum.

    Link > Administrator Permissions

    Tip: I don't recommend to give other admins access to the phpmyadmin or ftp or control panel of your site, and especially not to the members area on vbulletin.com (Because giving someone else access to your members area means they can take over your vbulletin account; Also note that the vbulletin staff will never ask you for your customer password in full)

    Tip: For added security check the control panel log history and set up password history so important usergroups are more secure by having to change their password once in a while. And request them to use a hard to guess password.

  6.     
    #5
    Member
    Nice info..
    Thanks, m8..

    Share Hosting: He will suspend you with High Resource uses reason, and he said you must move to SDH..
    SDH: He will suspend you with un-closed MySQL access reason and your invoice will come faster than normal invoice date.. :)

  7.     
    #6
    Member
    Website's:
    crackingforum.com linkparadox.com crackz.me
    Official post is on vBulletin.org


  8.     
    #7
    Member
    @Profit:
    But much webmaster didn't get license.. lol..

    Share Hosting: He will suspend you with High Resource uses reason, and he said you must move to SDH..
    SDH: He will suspend you with un-closed MySQL access reason and your invoice will come faster than normal invoice date.. :)

  9.     
    #8
    Banned
    @OP

    http://scriptraid.com/admincp/

    If find this ironic..

    You should ALWAYS change your admincp dir. and Modcp dir.

    edit both folder names then update in the config.php file in /includes/ dir.

  10.     
    #9
    Member
    lol @ chris..

    so TS didn't implement this post before post it..

    Share Hosting: He will suspend you with High Resource uses reason, and he said you must move to SDH..
    SDH: He will suspend you with un-closed MySQL access reason and your invoice will come faster than normal invoice date.. :)

  11.     
    #10
    Member

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. How To Make VPNs Even More Secure
    By ShareShiz in forum Tutorials and Guides
    Replies: 6
    Last Post: 31st May 2012, 01:12 PM
  2. [Selling] Make Your Datalife Engine 100% Secure (2$)
    By prateek in forum Completed Transactions
    Replies: 0
    Last Post: 5th Jul 2010, 12:59 PM
  3. Top 15 Wordpress Plugins to Make Your Blog Secure
    By SLiMRiDER in forum Useful Sites
    Replies: 3
    Last Post: 2nd Jun 2010, 05:05 PM
  4. how to make forums like this
    By GeForcezZ.=) in forum vBulletin
    Replies: 28
    Last Post: 9th Jan 2010, 11:11 AM
  5. how to Make your Forum Secure and Protected
    By xwarlordx in forum Tutorials and Guides
    Replies: 12
    Last Post: 27th Nov 2009, 06:29 PM

Tags for this Thread

BE SOCIAL