Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,900 Members
165,091 Posts
38 Users Online

Please welcome our newest member, Jors308932!

Affiliates
Go Back AdminFusion » Management » Security and Legal Issues » Protecting your Admincp from hackers
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 10-09-2008, 08:48 PM   #1

lafsunlmtd's Avatar

Title: Site Owner

Points: 4,224, Level: 18Points: 4,224, Level: 18Points: 4,224, Level: 18
Level up: 19%, 26 Points neededLevel up: 19%, 26 Points neededLevel up: 19%, 26 Points needed
Activity: 32%Activity: 32%Activity: 32%

Join Date: May 2006

Posts: 450

lafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of light

 
 
Exclamation Protecting your Admincp from hackers

Wanted to share an experience and help others from our dilemma. One of our other forums is in a highly competitive area. We support satellite receiver manufacturers. We had a hacker try and take down our site and we think he was paid by one of the receiver manufacturers.

Dude was intense, he was able to log in as my name, mess with the site, and then wipe out the admin log. I have the db backed up every hour because the site is so big so it wasn't that big of an ordeal with him erasing info or changing settings.

It was crazy though because he wouldn't do anything like catastrophic like wipe out the forum contents, he would go and change permissions to forums and post as other users.

So we would ban the ip addresses as we would see them come on, of course he was using a proxy so we had to just stay on it. We further changed the location of the admincp. I would suggest everyone do this. Instead of making it forum/admincp make it something totally unique. Also, its useless to change the location of it, if you don't also remove the link from the footer. It leads you right to it.

For an added level of protection, put an htacess in the admincp folder and password and ip block access to allow only those who should be allowed. Many times sites will only have one or two admins so it is not a big deal.

Once we limited the admincp to only certain ip's the attacks died down to him logging in as other users and posting bogus info. We just had to stay on it and block the ip's as we saw him log on.

Here are some other tips that i learned through this 5 day ordeal.
  1. If you don't use a plugin or addon anymore, don't just disable it, remove it
  2. Go through and remove files from previos versions of Vbulletin or other hacks that aren't used. You can check this by going into the maintenance section of the admincp and going through "Suspect File Versions" It lists all of the files and compares them with what should be in the original package. We had stuff in the directory from 2004
  3. Remove all of the upgrade and install files in your /install folder. these can be used to gain access or mess with your db. Just delete them!
  4. Require your mods and admins to change their passwords every few months. Many times people will use one password for multiple sites, if one of these is hacked, the hacker then has access to everything they can find. Its as easy as searching for the username on google to see where else the hacker can try the password.
  5. Change the location of your admincp. Make it something unique. Remove the code in the footer that dynamically creates a link to your admincp so it can't be found.
  6. Create an .htaccess file for your admincp and protect the directory by requiring a un/pw and by only allowing certain ip addresses.
  7. Be careful to give mods, super mods, and admins, only the powers that they need. The less the better, because if their account gets hacked you are in more danger if they have powers enabled that they don't even use.
  8. Do a search for your mods and admins usernames with google to see if you can find a password with their username for another site. If you can, just change their password and have them reset it.

I'll post more as i think of it, but it was quite an ordeal we went through and i think this sums up the steps we took. Anywho, please protect yourselves so this doesn't happen to you.
__________________
FTA Files -- Free to Air Satellite Helper Forum

Bush Says Drill, Drill, Drill — and Oil Drops $9...
Reply With Quote
Old 10-09-2008, 09:26 PM   #2

Moelman's Avatar

Title: I went to buy some shoes - and I came back with Life On Mars

Points: 14,771, Level: 36Points: 14,771, Level: 36Points: 14,771, Level: 36
Level up: 37%, 79 Points neededLevel up: 37%, 79 Points neededLevel up: 37%, 79 Points needed
Activity: 100%Activity: 100%Activity: 100%

Join Date: Feb 2006

Posts: 3,030

Location: Michigan, US

Moelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond repute

Send a message via AIM to Moelman  
 
Thanks for sharing that Eric. A lot of good advice to keep your forum secure. I just went and removed some plugins that were disabled but still installed. I also had some users who had their passwords the same as their usernames which comes up if you have the latest version of vB, so I reset all their passwords and sent emails out. None of them were mods or admins though. I also have it set to force me to change my password every few months.
__________________
World of Warcraft Forums - Your #1 place to discuss all things World of Warcraft.
Reply With Quote
Old 10-09-2008, 09:30 PM   #3

lafsunlmtd's Avatar

Title: Site Owner

Points: 4,224, Level: 18Points: 4,224, Level: 18Points: 4,224, Level: 18
Level up: 19%, 26 Points neededLevel up: 19%, 26 Points neededLevel up: 19%, 26 Points needed
Activity: 32%Activity: 32%Activity: 32%

Join Date: May 2006

Posts: 450

lafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of light

 
 
excellent.......
__________________
FTA Files -- Free to Air Satellite Helper Forum

Bush Says Drill, Drill, Drill — and Oil Drops $9...
Reply With Quote
Old 10-09-2008, 10:37 PM   #4

DannyH's Avatar

Title: Member

Points: 1,675, Level: 11Points: 1,675, Level: 11Points: 1,675, Level: 11
Level up: 12%, 175 Points neededLevel up: 12%, 175 Points neededLevel up: 12%, 175 Points needed
Activity: 16%Activity: 16%Activity: 16%

Join Date: May 2007

Posts: 122

Location: Sheffield, UK

DannyH is on a distinguished road

Recent Blog: Upgrades
 
 
I did it so all my members had to change their passwords every 2 months, however a few reported that the page where it asks you to change your password didn't exist.

Anyway, thanks for the tips
I'm gonna make a few changes to my forum on Sunday, and they will be on of them
__________________
www.forumize.net - Free PHPBB Forum
www.simalert.org - Free Sim Card Alerts
Reply With Quote
Old 10-09-2008, 11:49 PM   #5

BamaStangGuy's Avatar



Title: Forum Enthusiast

Points: 14,699, Level: 36Points: 14,699, Level: 36Points: 14,699, Level: 36
Level up: 37%, 151 Points neededLevel up: 37%, 151 Points neededLevel up: 37%, 151 Points needed
Activity: 8%Activity: 8%Activity: 8%

Join Date: Sep 2005

Posts: 2,478

Location: Alabama

BamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond repute
Send a message via AIM to BamaStangGuy  
 
I do this on my largest site.
__________________
Ford Mustang Forums - F-Series Trucks
Reply With Quote
Old 10-10-2008, 12:52 AM   #6

Jolteon's Avatar

Title: Forum Junkie

Points: 18,082, Level: 41Points: 18,082, Level: 41Points: 18,082, Level: 41
Level up: 42%, 868 Points neededLevel up: 42%, 868 Points neededLevel up: 42%, 868 Points needed
Activity: 24%Activity: 24%Activity: 24%

Join Date: Feb 2006

Posts: 3,623

Location: Holmfirth, England

Jolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant future
Send a message via MSN to Jolteon  
 
Nice list of things to check and fix there, thanks.


Quote:
Originally Posted by lafsunlmtd View Post
excellent.......
you're doing it wrong, see here for reference, kay? http://heylarryhughespleasestoptakin...-excellent.jpg
__________________
http://EasyToHide.Info
Visit my proxy for anonymous surfing!

Reply With Quote
Old 10-17-2008, 03:41 AM   #7

Cool_Guy's Avatar

Title: Apprentice

Points: 3,927, Level: 18Points: 3,927, Level: 18Points: 3,927, Level: 18
Level up: 19%, 323 Points neededLevel up: 19%, 323 Points neededLevel up: 19%, 323 Points needed
Activity: 4%Activity: 4%Activity: 4%

Join Date: Jun 2006

Posts: 264

Location: Earth, The Federation

Cool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to behold
Send a message via MSN to Cool_Guy  
 
Good advise.

I would also recommend that you tell you admins the adminCP location in a email or IM, not in a forum post or PM.
Reply With Quote
Reply

Tags
admincp, hackers, ip blocking, protection, safety, tips, vbulletin



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Where do I edit the Signature Perms in the VB admincp? Theforumplace vBulletin 3 09-12-2007 06:30 PM
Legal action against hackers? CultZero Security and Legal Issues 24 12-23-2006 04:03 AM
The Hackers List gprime Handling Problem Members 6 05-16-2006 02:27 AM
No admincp section when adding hacks kpr vBulletin 2 03-20-2006 10:36 PM
Malicious Hackers Exploit Windows Flaw shellspeare Off Topic 0 12-30-2005 12:07 PM

AdminFusion

All times are GMT +1. The time now is 01:32 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72