Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,917 Members
165,164 Posts
53 Users Online

Please welcome our newest member, clairlim!

Affiliates
Go Back AdminFusion » Getting Started » Domains and Hosting » How to keep hackers from hacking your site
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 12-21-2007, 03:07 AM   #1

malektaus's Avatar

Title: Member

Points: 546, Level: 5Points: 546, Level: 5Points: 546, Level: 5
Level up: 6%, 4 Points neededLevel up: 6%, 4 Points neededLevel up: 6%, 4 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Oct 2007

Posts: 54

Location: Tx

malektaus is on a distinguished road
 
 
How to keep hackers from hacking your site

This is not fool proof by any means but it can help you alot.

1. Think like a hacker, well most of you can't do that. So here is what they look for. Normal passwords to areas of your site that are common words. Avoid words like admin, bible, 12345, or other words and common items in the english language. It's best to use either a foreign language for a PW or use a variable of numbers and symbols together.

2. Change your PWs on the ACP and FTP at least 4 times a year or more. This helps prevent PW generators which take a long time from finding out your PW. Yes I said PW generators, they do exist and they are rather affective.

3. Make sure your FTP isn't accessible via the net in general as hackers can gain access to certain files that can give them your PWs for all areas. You can change this in your CP.

4. Just as a backup make sure to DL your DB about 4 times a year so you can easily rebuild your site if it does get hacked. You may have lost some content but your still online.

5. Make sure you choose a host client that can give you all the support you need if you can no longer get into your account. If you are already with a host that can't do this then you need to look elsewhere for hosting. Sometimes when your hacked it takes more than you to regain comtrol of your site and there's only 1 other person that can do that, your host.

Being hacked is not fun and sometimes it comes from the inside as I have seen. Be certain that the people you give access to your site are fully trusted by you and even at that when they don't need access still change your PWs and only give them to them when they are needed.
__________________
Reply With Quote
Old 12-21-2007, 03:09 AM   #2

Foxx's Avatar

Title: Apprentice

Points: 2,914, Level: 15Points: 2,914, Level: 15Points: 2,914, Level: 15
Level up: 16%, 136 Points neededLevel up: 16%, 136 Points neededLevel up: 16%, 136 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Sep 2006

Posts: 274

Location: Long Island, New York

Foxx is a jewel in the roughFoxx is a jewel in the roughFoxx is a jewel in the roughFoxx is a jewel in the rough
Send a message via MSN to Foxx  
 
Getting hacked is definitely not fun.
__________________
-Foxx
Major vBulletin Fan... Nothing Else.
I dream I will own a big-board one day. Yeah, one day...
Reply With Quote
Old 12-21-2007, 04:28 AM   #3

Title: Apprentice

Points: 2,171, Level: 13Points: 2,171, Level: 13Points: 2,171, Level: 13
Level up: 14%, 279 Points neededLevel up: 14%, 279 Points neededLevel up: 14%, 279 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Aug 2006

Posts: 277

Location: Crownsville, MD

bmelton is a jewel in the roughbmelton is a jewel in the roughbmelton is a jewel in the rough
Send a message via AIM to bmelton Send a message via MSN to bmelton Send a message via Yahoo to bmelton  
 
If you're on a dedicated host, make sure your OS is patched.

I run all my sites on Debian Stable servers, which has a solid reputation for being stable and secure. With apt-get, I can cron hourly security updates to occur, so that I'm as patched as I can reasonably be.

Another common thing to avoid is FTP. If you have SSH access to your box, then you should switch to using SCP (WinSCP for Windows). It's basically the same as FTP, so there's very little learning curve, only uses encryption for your passwords, whereas FTP (and telnet for that matter) send passwords in plaintext. If you're being targetted by a hacker, Telnet and FTP are easy ways for them to get in.
__________________
Hero Chat - Comic, SciFi, Games, Movies and TV Community.
Reply With Quote
Old 12-21-2007, 05:25 AM   #4

Jolteon's Avatar

Title: Forum Junkie

Points: 18,096, Level: 41Points: 18,096, Level: 41Points: 18,096, Level: 41
Level up: 42%, 854 Points neededLevel up: 42%, 854 Points neededLevel up: 42%, 854 Points needed
Activity: 23%Activity: 23%Activity: 23%

Join Date: Feb 2006

Posts: 3,624

Location: Holmfirth, England

Jolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant future
Send a message via MSN to Jolteon  
 
Also, consider changing your Admin Control Panel & Mod control panel (if applicabe to your software) On vBulletin and MyBB this is relatively simple, just rename the directory (ANY valid foldername is OK!) then go to your config file (the file you configured during installation, it is usually inside the folder /inc or /includes) and change the option to the new directory. This auto changes all links inside the forum too. However for increased security, you may wish to edit templates to rermove this link, so you NEED to know the directory your control panels reside in, or you ain't going no where through the CPs.
Important: I have only done this on vBulletin and MyBB, I cannot gurantee this method (specifically configuring the config file) works on other software!
__________________
http://EasyToHide.Info
Visit my proxy for anonymous surfing!

Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Google Ranking Explained Ryan Search Engine Optimization 27 01-22-2008 11:42 AM
Need Tips with creating TOS & Privacy Statement etc TimmyC Security and Legal Issues 2 12-24-2006 08:22 PM
Getting Site User Feedback shellspeare Handling Problem Members 2 03-09-2006 08:34 PM
What should be the google page rank?!! Danecookie Search Engine Optimization 2 11-18-2005 05:46 AM

AdminFusion

All times are GMT +1. The time now is 10:22 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved


From:
Title:

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72