A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.
Please welcome our newest member, jevs!
Spice up your web site with the ultimate community message board solution!
Fake Id'sGet fake Id's made right now!
vBSEOSearch Engine Optimization for your VBulletin Forum.
AdminFusion
»
The Best Ever Way to protect a bulletin board...
| | #1 |
| | #2 |
| | #3 |
| | |||||
| Title: Apprentice Join Date: Jan 2006 Posts: 220 ![]() | I was just checking this at vb.com, and you are allowed to do this with vb. http://www.vbulletin.com/forum/showt...d_by_vbulletin In the 'powered_by_vbulletin' phrase, I changed: Code: Powered by vBulletin Version {1}<br />Copyright ©2000 - {2}, Jelsoft Enterprises Ltd.
Code: Powered by vBulletin Version 3.5<br />Copyright ©2000 - {2}, Jelsoft Enterprises Ltd.
| ||||
| |
| | #4 |
| | |||||
| Title: Groupie Join Date: Jan 2006 Posts: 41 Location: London, U.K. ![]() | That will only work with real newbies. Experienced hackers use bots and that doesn't check the version number. If you have access to your server logs, especially the error log, you will see a sequential bot exploit checkers.
__________________ AZbb :: AZ Bulletin Board - Secure PHP BBS script, front page CMS, Chat, No Database | ||||
| |
| | #5 |
| | #6 |
| | |||||
| Title: Groupie Join Date: Jan 2006 Posts: 41 Location: London, U.K. ![]() | That is true. However, script-kiddies do not usually have access to 0-day exploits. Admins should regularly check with the forum software developer to make sure their software is up-to-date. I have seen some ancient version of software running in some places. And finally, choosing a software that is fundamentally secure, and resisting the urge to install mods written by unknown parties, will greatly reduce the risk. Good luck AZ
__________________ AZbb :: AZ Bulletin Board - Secure PHP BBS script, front page CMS, Chat, No Database | ||||
| |
| | #7 |
| | |||||
| Title: Apprentice Join Date: Oct 2005 Posts: 253 ![]() | I think it's was a good decision of the phpBB group to hide the version number. They have an automatic update check so that you are informed when a new version of phpBB is avaible. You can disable posts by guests, that will make it much hard for spambots. You can also enable visual confirmination this will result in that bots can't register at your site. And like you also said in your startpost: disable HTML in posts. Further you could block know spambots and other bots through .htaccess or the IIS version. You could SEND (I'm not talking about storing and comparing) the passwords encrypted. You can disable image tags. You could disable remotley hosted avatars, if you allow avatar uploading a stricter image check would be good or just disable avatar uploading. | ||||
| |
| | #8 |
| | |||||
| Title: Apprentice Join Date: Jan 2006 Posts: 220 ![]() | To bump my thread, with vb 3.5.4 out, here's best board sitting around with 3.5.3 in its footer. If I knew the 3.5.3 exploit (which I don't but give me time) I would know straight away I could abuse it here. My board is both upgraded and hiding its version number of course ^_^ | ||||
| |
| | #9 |
| | #10 |
| | ||||||
| Title: Forum Addict Join Date: Aug 2005 Posts: 1,741 ![]() | Quote:
| |||||
| |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Bulletin Board List & Version | Chris | Software | 2 | 03-20-2006 10:43 PM |
| Internet Bulletin Board Database - Add Your Board | BGray | Buy and Sell | 11 | 03-10-2006 11:14 PM |
| Which Is The Best Free Bulletin Board? | unknownz | Software | 12 | 02-28-2006 09:24 PM |