Previous Thread
Next Thread
Print Thread
Rate Thread
#311245 08/12/2006 10:13 PM
Joined: Aug 2006
Posts: 14
Newbie
Newbie
Offline
Joined: Aug 2006
Posts: 14

I started with UBBThreads a few years ago, with a then new forum hosted on a cheapo server.

We had a "competitor" who hacked us the day he opened his own forum, and pretty much killed our forum. (We didn't consider him a "competitor", and had no ill feelings toward him, but he apparently thought so of us...)

As the resident IT guy, I insisted on being allowed to move the forum to Infopop's server, where it was more secure. Infopop's techs then did a tremendous job of resurrecting what should have been pretty much unressurectable, and we got our forum back, a few weeks later.

Now, the owners want to move servers again.

Again, because of cost.

To be honest, seeing the deal they have gotten on the new server, and adding to that, their current and future needs... I can't say that I can blame the owners.

What they really need would cost thousands at Infopop, and they simply do not have that kind of money.

So the bottom line is this... I am curious about what I can do in the move... What I can do on the new server... What I can do in any other way at all, to make our forum as secure as possible ???

We are currently running version 6.5.5

Thank you.

smile

Sponsored Links
Joined: Jul 2001
Posts: 808
Coder
Coder
Joined: Jul 2001
Posts: 808
Threads V6.5.5 has closed all known holes. I see no more announces on the bug track sites (do you know holes for 6.5.5?)

The main thing is turn of register globals in your server envoiroment. This is the main break in point. With this off most problems are gone.

Be carefull with add ons. Most hacks seems to be unsafe and can be open a new hole.

Joined: Aug 2006
Posts: 14
Newbie
Newbie
Offline
Joined: Aug 2006
Posts: 14

Thank you Zarzal.

No, I don't know of any holes, myself. That was why I was asking.

smile

I followed the instructions for turning off register globals, but I am not sure it worked.

Nothing has been written to the file since I did that.

I suppose that could simply be because no one has tried anything against my forum, though. LOL

Good point about the add-ons. Better stay away from that ThreadsDev place, right ?

wink

LOL


Joined: Jul 2001
Posts: 808
Coder
Coder
Joined: Jul 2001
Posts: 808
I think this is a good point to notify all people to take more care. A add-on Hack is done in V6.x very fast and simple, but most times no one check any side effects to the security.

My Threads V6.5x was hacked 3 times in May, all over holes in conjunction with register globals. My server dont let me switch this off and using of htaccess for this was not possible with a Zeus Server.

The easy way on Apache is using the htaccess to switch of register globals.


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
isaac
isaac
California
Posts: 1,157
Joined: July 2001
Forum Statistics
Forums63
Topics37,575
Posts293,931
Members13,823
Most Online6,139
Sep 21st, 2024
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,834
Greg Hard 4,625
Top Posters(30 Days)
Gizmo 1
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2025 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.1
(Snapshot build 20240918)