|
Joined: Nov 2001
Posts: 7
Junior Member
|
Junior Member
Joined: Nov 2001
Posts: 7 |
Hello,
Can anyone point me to an article that outlines the security steps one should take to protect a board from being hacked? Or, just offer some brief steps on what every admin should do security-wise?
Thanks!
slacker_100
|
|
|
|
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
|
Admin Emeritus
Joined: Jan 2000
Posts: 5,073 |
1) Turn HTML off 2) Keep the Members directory below the web rot 3) Don't use the same password you use elsewhere
Tada. That's it.
UBB.classic: Love it or hate it, it was mine.
|
|
|
|
Joined: Aug 2000
Posts: 874
Moderator / Developer
|
Moderator / Developer
Joined: Aug 2000
Posts: 874 |
if you cant do step 2, putting a .htaccess file in the members dir, one that denys from all, would be a good idea.
imo it is a good idea to have the variables dir seperate from the cgi-bin, and set up the cgi-bin so it is non writeable. then keep both the members dir and the variables dir below the web root...
|
|
|
|
Joined: Aug 2000
Posts: 335
Member
|
Member
Joined: Aug 2000
Posts: 335 |
"below the web root" = "outside the web root" (less ambiguous  )
|
|
|
|
Joined: Sep 2000
Posts: 4,211
Master Hacker
|
Master Hacker
Joined: Sep 2000
Posts: 4,211 |
You could even put your member files on a totally separate drive or partition. 
|
|
|
|
Joined: Nov 2001
Posts: 7
Junior Member
|
Junior Member
Joined: Nov 2001
Posts: 7 |
Can you give me an example of what kind of damage can be done by someone using an HTML script? Can the password be obtained this way, or is it more a doing-damage/wreaking-havok thing?
[ 01-20-2002 01:44 AM: Message edited by: slacker_100 ]
|
|
|
|
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
|
Admin Emeritus
Joined: Jan 2000
Posts: 5,073 |
Why are you so interested?
UBB.classic: Love it or hate it, it was mine.
|
|
|
|
Joined: Nov 2001
Posts: 7
Junior Member
|
Junior Member
Joined: Nov 2001
Posts: 7 |
Just trying to gain a little knowlege, that's all. I'm a believer in knowing your enemy (and his methods). If it's too sensitive a subject here, I'll ask elsewhere. Thanks for the info everybody. 
|
|
|
|
Joined: Mar 2001
Posts: 7,394
Admin / Code Breaker
|
Admin / Code Breaker
Joined: Mar 2001
Posts: 7,394 |
For example, in UBB 6.1.0.3 or 6.2.0 Beta Release 1.0 and above there is a huge bugs that lets the users... I won't tell you.  ... you can change anything. It's the best to hide vars_config.cgi and such. Also that they can't find members path... I won't tell you why  .
|
|
|
|
Joined: Nov 2001
Posts: 198
Member
|
Member
Joined: Nov 2001
Posts: 198 |
lol 
Just another boring 17-year-old and yes, I like smilies/graemlins
|
|
|
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
|
|
Posts: 449
Joined: February 2008
|
|
Forums63
Topics37,575
Posts293,930
Members13,823
|
Most Online6,139 Sep 21st, 2024
|
|
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
|
|
|
|