Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,899 Members
165,083 Posts
45 Users Online

Please welcome our newest member, jevs!

Affiliates
Go Back AdminFusion » Getting Started » Software » The Best Ever Way to protect a bulletin board...
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 01-28-2006, 02:30 PM   #1

imported_Link's Avatar

Title: Apprentice

Points: 2,285, Level: 13Points: 2,285, Level: 13Points: 2,285, Level: 13
Level up: 14%, 165 Points neededLevel up: 14%, 165 Points neededLevel up: 14%, 165 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jan 2006

Posts: 220

imported_Link is on a distinguished road
 
 
The Best Ever Way to protect a bulletin board...

In my opinion, other than the 'given' methods of removing one time installation scripts, not enabling html/java/flash and upgrading every time a patch comes out, the most important thing for a bulletin board owner is to hide his board version number if he can't upgrade as soon as a software patch is released.

Why?

Because as far as I am concerned, you can never protect yourself against 0-days hacks unless your are insanely good at web security and run your forums off a server you have full access too.

However bearing this in mind, when patches for your software are released, it's fair to say that version specific bugs are publically known to hacking groups. They can then google for e.g. "Powered by vBulletin Version 3.5.3" and hack every single board they encounter in a systematic fashion with their publically known hacks.

In conclusion, I feel removing your version number from website footer (especially if due to a heavily hacked board you can't upgrade quickly) is the best security measure you can do.
Reply With Quote
Old 01-28-2006, 02:45 PM   #2

gprime's Avatar

Title: Forum Addict

Points: 7,237, Level: 25Points: 7,237, Level: 25Points: 7,237, Level: 25
Level up: 26%, 313 Points neededLevel up: 26%, 313 Points neededLevel up: 26%, 313 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Aug 2005

Posts: 1,741

gprime is on a distinguished road
 
 
Interesting ideas. And for BBS options where that doesn't violate the TOS, it would be well worth it.
Reply With Quote
Old 01-28-2006, 04:05 PM   #3

imported_Link's Avatar

Title: Apprentice

Points: 2,285, Level: 13Points: 2,285, Level: 13Points: 2,285, Level: 13
Level up: 14%, 165 Points neededLevel up: 14%, 165 Points neededLevel up: 14%, 165 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jan 2006

Posts: 220

imported_Link is on a distinguished road
 
 
I was just checking this at vb.com, and you are allowed to do this with vb.
http://www.vbulletin.com/forum/showt...d_by_vbulletin

In the 'powered_by_vbulletin' phrase, I changed:
Code:
Powered by vBulletin Version {1}<br />Copyright &copy;2000 - {2}, Jelsoft Enterprises Ltd.

Content Relevant URLs by vBSEO 3.1.0
to:
Code:
Powered by vBulletin Version 3.5<br />Copyright &copy;2000 - {2}, Jelsoft Enterprises Ltd.

Content Relevant URLs by vBSEO 3.1.0
The 3.5 for benefit of those who recognise the difference between 3.0 and 3.5 obviously.
Reply With Quote
Old 01-28-2006, 07:40 PM   #4

AZbb's Avatar

Title: Groupie

Points: 1,750, Level: 11Points: 1,750, Level: 11Points: 1,750, Level: 11
Level up: 12%, 100 Points neededLevel up: 12%, 100 Points neededLevel up: 12%, 100 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jan 2006

Posts: 41

Location: London, U.K.

AZbb is on a distinguished road
 
 
That will only work with real newbies.

Experienced hackers use bots and that doesn't check the version number. If you have access to your server logs, especially the error log, you will see a sequential bot exploit checkers.

__________________
AZbb :: AZ Bulletin Board - Secure PHP BBS script, front page CMS, Chat, No Database
Reply With Quote
Old 01-28-2006, 07:43 PM   #5

imported_Link's Avatar

Title: Apprentice

Points: 2,285, Level: 13Points: 2,285, Level: 13Points: 2,285, Level: 13
Level up: 14%, 165 Points neededLevel up: 14%, 165 Points neededLevel up: 14%, 165 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jan 2006

Posts: 220

imported_Link is on a distinguished road
 
 
^ ^
I did place my point in context however. It's my opinion you can never be 100% secure against real hackers. However people googling for exploits who then google for outdated vbs shouldn't have things so easy.
Reply With Quote
Old 01-28-2006, 08:03 PM   #6

AZbb's Avatar

Title: Groupie

Points: 1,750, Level: 11Points: 1,750, Level: 11Points: 1,750, Level: 11
Level up: 12%, 100 Points neededLevel up: 12%, 100 Points neededLevel up: 12%, 100 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jan 2006

Posts: 41

Location: London, U.K.

AZbb is on a distinguished road
 
 
That is true. However, script-kiddies do not usually have access to 0-day exploits.

Admins should regularly check with the forum software developer to make sure their software is up-to-date. I have seen some ancient version of software running in some places.

And finally, choosing a software that is fundamentally secure, and resisting the urge to install mods written by unknown parties, will greatly reduce the risk.

Good luck
AZ
__________________
AZbb :: AZ Bulletin Board - Secure PHP BBS script, front page CMS, Chat, No Database
Reply With Quote
Old 02-01-2006, 07:38 PM   #7

Title: Apprentice

Points: 2,580, Level: 14Points: 2,580, Level: 14Points: 2,580, Level: 14
Level up: 15%, 170 Points neededLevel up: 15%, 170 Points neededLevel up: 15%, 170 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Oct 2005

Posts: 253

abcde is on a distinguished road
 
 
I think it's was a good decision of the phpBB group to hide the version number. They have an automatic update check so that you are informed when a new version of phpBB is avaible.

You can disable posts by guests, that will make it much hard for spambots. You can also enable visual confirmination this will result in that bots can't register at your site. And like you also said in your startpost: disable HTML in posts.

Further you could block know spambots and other bots through .htaccess or the IIS version. You could SEND (I'm not talking about storing and comparing) the passwords encrypted. You can disable image tags. You could disable remotley hosted avatars, if you allow avatar uploading a stricter image check would be good or just disable avatar uploading.
__________________
.premodded - Premodded phpBB.
Reply With Quote
Old 02-22-2006, 11:57 PM   #8

imported_Link's Avatar

Title: Apprentice

Points: 2,285, Level: 13Points: 2,285, Level: 13Points: 2,285, Level: 13
Level up: 14%, 165 Points neededLevel up: 14%, 165 Points neededLevel up: 14%, 165 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jan 2006

Posts: 220

imported_Link is on a distinguished road
 
 
To bump my thread, with vb 3.5.4 out, here's best board sitting around with 3.5.3 in its footer.

If I knew the 3.5.3 exploit (which I don't but give me time) I would know straight away I could abuse it here.

My board is both upgraded and hiding its version number of course ^_^
Reply With Quote
Old 02-23-2006, 01:05 AM   #9

BamaStangGuy's Avatar



Title: Forum Enthusiast

Points: 14,699, Level: 36Points: 14,699, Level: 36Points: 14,699, Level: 36
Level up: 37%, 151 Points neededLevel up: 37%, 151 Points neededLevel up: 37%, 151 Points needed
Activity: 8%Activity: 8%Activity: 8%

Join Date: Sep 2005

Posts: 2,478

Location: Alabama

BamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond repute
Send a message via AIM to BamaStangGuy  
 
I have been doing this for awhile on my sites.
__________________
Ford Mustang Forums - F-Series Trucks
Reply With Quote
Old 02-23-2006, 02:26 AM   #10

gprime's Avatar

Title: Forum Addict

Points: 7,237, Level: 25Points: 7,237, Level: 25Points: 7,237, Level: 25
Level up: 26%, 313 Points neededLevel up: 26%, 313 Points neededLevel up: 26%, 313 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Aug 2005

Posts: 1,741

gprime is on a distinguished road
 
 
Quote:
Originally Posted by Link View Post
To bump my thread, with vb 3.5.4 out, here's best board sitting around with 3.5.3 in its footer.

If I knew the 3.5.3 exploit (which I don't but give me time) I would know straight away I could abuse it here.

My board is both upgraded and hiding its version number of course ^_^
Well, you are a valid license holder. So you could compare the current files to the updated ones and probably figure it out from there.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Bulletin Board List & Version Chris Software 2 03-20-2006 10:43 PM
Internet Bulletin Board Database - Add Your Board BGray Buy and Sell 11 03-10-2006 11:14 PM
Which Is The Best Free Bulletin Board? unknownz Software 12 02-28-2006 09:24 PM

AdminFusion

All times are GMT +1. The time now is 10:04 PM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72