Previous Thread
Next Thread
Print Thread
Rate Thread
#173080 01/19/2002 7:43 PM
Joined: Nov 2001
Posts: 7
Junior Member
Junior Member
Offline
Joined: Nov 2001
Posts: 7
Hello,

Can anyone point me to an article that outlines the security steps one should take to protect a board from being hacked? Or, just offer some brief steps on what every admin should do security-wise?

Thanks!

slacker_100

Sponsored Links
#173081 01/19/2002 8:15 PM
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
Admin Emeritus
Joined: Jan 2000
Posts: 5,073
1) Turn HTML off
2) Keep the Members directory below the web rot
3) Don't use the same password you use elsewhere

Tada. That's it.


UBB.classic: Love it or hate it, it was mine.
#173082 01/19/2002 8:59 PM
Joined: Aug 2000
Posts: 874
Moderator / Developer
Moderator / Developer
Offline
Joined: Aug 2000
Posts: 874
if you cant do step 2, putting a .htaccess file in the members dir, one that denys from all, would be a good idea.

imo it is a good idea to have the variables dir seperate from the cgi-bin, and set up the cgi-bin so it is non writeable. then keep both the members dir and the variables dir below the web root...

#173083 01/19/2002 9:27 PM
Joined: Aug 2000
Posts: 335
Member
Member
Offline
Joined: Aug 2000
Posts: 335
"below the web root" = "outside the web root" (less ambiguous )

#173084 01/19/2002 11:07 PM
Joined: Sep 2000
Posts: 4,211
Master Hacker
Master Hacker
Joined: Sep 2000
Posts: 4,211
You could even put your member files on a totally separate drive or partition.

Sponsored Links
#173085 01/20/2002 2:42 AM
Joined: Nov 2001
Posts: 7
Junior Member
Junior Member
Offline
Joined: Nov 2001
Posts: 7
Can you give me an example of what kind of damage can be done by someone using an HTML script? Can the password be obtained this way, or is it more a doing-damage/wreaking-havok thing?

[ 01-20-2002 01:44 AM: Message edited by: slacker_100 ]

#173086 01/20/2002 4:31 AM
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
Admin Emeritus
Joined: Jan 2000
Posts: 5,073
Why are you so interested?


UBB.classic: Love it or hate it, it was mine.
#173087 01/20/2002 5:51 AM
Joined: Nov 2001
Posts: 7
Junior Member
Junior Member
Offline
Joined: Nov 2001
Posts: 7
Just trying to gain a little knowlege, that's all. I'm a believer in knowing your enemy (and his methods).

If it's too sensitive a subject here, I'll ask elsewhere. Thanks for the info everybody.

#173088 01/20/2002 7:13 AM
Joined: Mar 2001
Posts: 7,394
LK Offline
Admin / Code Breaker
Admin / Code Breaker
Offline
Joined: Mar 2001
Posts: 7,394
For example, in UBB 6.1.0.3 or 6.2.0 Beta Release 1.0 and above there is a huge bugs that lets the users... I won't tell you. wink ... you can change anything. It's the best to hide vars_config.cgi and such. Also that they can't find members path... I won't tell you why .

#173089 01/20/2002 8:01 AM
Joined: Nov 2001
Posts: 198
Member
Member
Offline
Joined: Nov 2001
Posts: 198
lol smile


Just another boring 17-year-old
and yes, I like smilies/graemlins
Sponsored Links

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
JAISP
JAISP
PA
Posts: 449
Joined: February 2008
Forum Statistics
Forums63
Topics37,575
Posts293,930
Members13,823
Most Online6,139
Sep 21st, 2024
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2025 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.1
(Snapshot build 20240918)