A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.
Please welcome our newest member, Jors308932!
Spice up your web site with the ultimate community message board solution!
Fake Id'sGet fake Id's made right now!
vBSEOSearch Engine Optimization for your VBulletin Forum.
AdminFusion
»
Protecting your Admincp from hackers
| | #1 |
| | ||
|
| Wanted to share an experience and help others from our dilemma. One of our other forums is in a highly competitive area. We support satellite receiver manufacturers. We had a hacker try and take down our site and we think he was paid by one of the receiver manufacturers. Dude was intense, he was able to log in as my name, mess with the site, and then wipe out the admin log. I have the db backed up every hour because the site is so big so it wasn't that big of an ordeal with him erasing info or changing settings. It was crazy though because he wouldn't do anything like catastrophic like wipe out the forum contents, he would go and change permissions to forums and post as other users. So we would ban the ip addresses as we would see them come on, of course he was using a proxy so we had to just stay on it. We further changed the location of the admincp. I would suggest everyone do this. Instead of making it forum/admincp make it something totally unique. Also, its useless to change the location of it, if you don't also remove the link from the footer. It leads you right to it. For an added level of protection, put an htacess in the admincp folder and password and ip block access to allow only those who should be allowed. Many times sites will only have one or two admins so it is not a big deal. Once we limited the admincp to only certain ip's the attacks died down to him logging in as other users and posting bogus info. We just had to stay on it and block the ip's as we saw him log on. Here are some other tips that i learned through this 5 day ordeal.
I'll post more as i think of it, but it was quite an ordeal we went through and i think this sums up the steps we took. Anywho, please protect yourselves so this doesn't happen to you.
__________________ FTA Files -- Free to Air Satellite Helper Forum Bush Says Drill, Drill, Drill — and Oil Drops $9... | |
| |
| | #2 |
| | |||||
|
Title: Join Date: Feb 2006 Posts: 3,030 Location: Michigan, US ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Recent Blog: New Screenshots Released | Thanks for sharing that Eric. A lot of good advice to keep your forum secure. I just went and removed some plugins that were disabled but still installed. I also had some users who had their passwords the same as their usernames which comes up if you have the latest version of vB, so I reset all their passwords and sent emails out. None of them were mods or admins though. I also have it set to force me to change my password every few months.
__________________ World of Warcraft Forums - Your #1 place to discuss all things World of Warcraft. | ||||
| |
| | #3 |
| | ||
|
| excellent.......
__________________ FTA Files -- Free to Air Satellite Helper Forum Bush Says Drill, Drill, Drill — and Oil Drops $9... | |
| |
| | #4 |
| | #5 |
| | #6 |
| | |||||
|
Title: Forum Junkie Join Date: Feb 2006 Posts: 3,623 Location: Holmfirth, England ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Nice list of things to check and fix there, thanks. you're doing it wrong, see here for reference, kay? http://heylarryhughespleasestoptakin...-excellent.jpg
__________________ | ||||
| |
| | #7 |
| | |||||
| Title: Apprentice Join Date: Jun 2006 Posts: 264 Location: Earth, The Federation ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Good advise. ![]() I would also recommend that you tell you admins the adminCP location in a email or IM, not in a forum post or PM.
__________________ vBulletin SEO Services You online source for Windows 7, win7mag.com PDC is almost here! | ||||
| |
![]() |
| Tags |
| admincp, hackers, ip blocking, protection, safety, tips, vbulletin |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Where do I edit the Signature Perms in the VB admincp? | Theforumplace | vBulletin | 3 | 09-12-2007 06:30 PM |
| Legal action against hackers? | CultZero | Security and Legal Issues | 24 | 12-23-2006 04:03 AM |
| The Hackers List | gprime | Handling Problem Members | 6 | 05-16-2006 02:27 AM |
| No admincp section when adding hacks | kpr | vBulletin | 2 | 03-20-2006 10:36 PM |
| Malicious Hackers Exploit Windows Flaw | shellspeare | Off Topic | 0 | 12-30-2005 12:07 PM |
