Quick Login   
 
Register AdminFusion Tutorials Post Fusion Forum Matrix
 
Go Back AdminFusion » Management » Security and Legal Issues » Protecting your Admincp from hackers
Reply
 
LinkBack
Old 10-09-2008, 07:48 PM   #1
The OLD Site Owner
 
lafsunlmtd's Avatar
 
Join Date: May 2006
Posts: 505
lafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of light
Exclamation Protecting your Admincp from hackers

Wanted to share an experience and help others from our dilemma. One of our other forums is in a highly competitive area. We support satellite receiver manufacturers. We had a hacker try and take down our site and we think he was paid by one of the receiver manufacturers.

Dude was intense, he was able to log in as my name, mess with the site, and then wipe out the admin log. I have the db backed up every hour because the site is so big so it wasn't that big of an ordeal with him erasing info or changing settings.

It was crazy though because he wouldn't do anything like catastrophic like wipe out the forum contents, he would go and change permissions to forums and post as other users.

So we would ban the ip addresses as we would see them come on, of course he was using a proxy so we had to just stay on it. We further changed the location of the admincp. I would suggest everyone do this. Instead of making it forum/admincp make it something totally unique. Also, its useless to change the location of it, if you don't also remove the link from the footer. It leads you right to it.

For an added level of protection, put an htacess in the admincp folder and password and ip block access to allow only those who should be allowed. Many times sites will only have one or two admins so it is not a big deal.

Once we limited the admincp to only certain ip's the attacks died down to him logging in as other users and posting bogus info. We just had to stay on it and block the ip's as we saw him log on.

Here are some other tips that i learned through this 5 day ordeal.
  1. If you don't use a plugin or addon anymore, don't just disable it, remove it
  2. Go through and remove files from previos versions of Vbulletin or other hacks that aren't used. You can check this by going into the maintenance section of the admincp and going through "Suspect File Versions" It lists all of the files and compares them with what should be in the original package. We had stuff in the directory from 2004
  3. Remove all of the upgrade and install files in your /install folder. these can be used to gain access or mess with your db. Just delete them!
  4. Require your mods and admins to change their passwords every few months. Many times people will use one password for multiple sites, if one of these is hacked, the hacker then has access to everything they can find. Its as easy as searching for the username on google to see where else the hacker can try the password.
  5. Change the location of your admincp. Make it something unique. Remove the code in the footer that dynamically creates a link to your admincp so it can't be found.
  6. Create an .htaccess file for your admincp and protect the directory by requiring a un/pw and by only allowing certain ip addresses.
  7. Be careful to give mods, super mods, and admins, only the powers that they need. The less the better, because if their account gets hacked you are in more danger if they have powers enabled that they don't even use.
  8. Do a search for your mods and admins usernames with google to see if you can find a password with their username for another site. If you can, just change their password and have them reset it.

I'll post more as i think of it, but it was quite an ordeal we went through and i think this sums up the steps we took. Anywho, please protect yourselves so this doesn't happen to you.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
-- Free to Air Satellite Helper Forum


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
lafsunlmtd is offline   Reply With Quote
Old 10-09-2008, 08:26 PM   #2
The Webmaster
 
Moelman's Avatar
 
Join Date: Feb 2006
Location: Michigan, USA
Posts: 3,328
Moelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond reputeMoelman has a reputation beyond repute
Send a message via AIM to Moelman
Thanks for sharing that Eric. A lot of good advice to keep your forum secure. I just went and removed some plugins that were disabled but still installed. I also had some users who had their passwords the same as their usernames which comes up if you have the latest version of vB, so I reset all their passwords and sent emails out. None of them were mods or admins though. I also have it set to force me to change my password every few months.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- The Largest LucasArts Gaming Community on the Internet

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- tell me your comments!

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- Your #1 place to discuss all things World of Warcraft.
Moelman is offline   Reply With Quote
Old 10-09-2008, 08:30 PM   #3
The OLD Site Owner
 
lafsunlmtd's Avatar
 
Join Date: May 2006
Posts: 505
lafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of lightlafsunlmtd is a glorious beacon of light
excellent.......
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
-- Free to Air Satellite Helper Forum


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
lafsunlmtd is offline   Reply With Quote
Old 10-09-2008, 09:37 PM   #4
Member
 
DannyH's Avatar
 
Join Date: May 2007
Location: UK
Posts: 134
DannyH is on a distinguished road
I did it so all my members had to change their passwords every 2 months, however a few reported that the page where it asks you to change your password didn't exist.

Anyway, thanks for the tips
I'm gonna make a few changes to my forum on Sunday, and they will be on of them
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- BassLine Chat forum!

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- Free Sim Card Alerts
DannyH is offline   Reply With Quote
Old 10-09-2008, 10:49 PM   #5
Forum Enthusiast


 
BamaStangGuy's Avatar
 
Join Date: Sep 2005
Location: Alabama
Posts: 2,483
BamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond reputeBamaStangGuy has a reputation beyond repute
Send a message via AIM to BamaStangGuy
I do this on my largest site.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
More to be listed soon.
BamaStangGuy is offline   Reply With Quote
Old 10-09-2008, 11:52 PM   #6
Forum Junkie
 
Jolteon's Avatar
 
Join Date: Feb 2006
Location: Holmfirth, England
Posts: 3,699
Jolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant future
Send a message via MSN to Jolteon
Nice list of things to check and fix there, thanks.


Quote:
Originally Posted by lafsunlmtd View Post
excellent.......
you're doing it wrong, see here for reference, kay? http://heylarryhughespleasestoptakin...-excellent.jpg
__________________
Ack, no currently active projects
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Jolteon is offline   Reply With Quote
Old 10-17-2008, 02:41 AM   #7
Apprentice
 
Cool_Guy's Avatar
 
Join Date: Jun 2006
Location: Earth, The Federation
Posts: 269
Cool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to beholdCool_Guy is a splendid one to behold
Send a message via MSN to Cool_Guy
Good advise.

I would also recommend that you tell you admins the adminCP location in a email or IM, not in a forum post or PM.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

PDC is almost here!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Cool_Guy is offline   Reply With Quote
Old 12-06-2008, 08:23 PM   #8
Rookie
 
Join Date: Jun 2008
Posts: 25
spurssheriff is on a distinguished road
Unhappy

Damn.. I wish I had read this a few months ago. Some a-holes came in and wiped our forum clean. They deleted the whole site, nothing is left. The owner called his hosting company and asked them for a back up. They told him it was extra so they don't have one. We've asked several people to help and they tried but couldn't recover anything. The owner stumbled upon a back up hidden away from 2007. I told him to re-install it and he did but he's having a lot of trouble with bringing the site back up... what a mess.

Those people don't realize SpursReport.com is a business not just a fan forum. What repercussions can be done if we find out who actually did this?

Any help or advice would be appreciated.

Thanks.
spurssheriff is offline   Reply With Quote
Reply

Tags
admincp, hackers, ip blocking, protection, safety, tips, vbulletin


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Where do I edit the Signature Perms in the VB admincp? Theforumplace vBulletin 3 09-12-2007 05:30 PM
Legal action against hackers? CultZero Security and Legal Issues 24 12-23-2006 03:03 AM
The Hackers List gprime Handling Problem Members 6 05-16-2006 01:27 AM
No admincp section when adding hacks kpr vBulletin 2 03-20-2006 09:36 PM
Malicious Hackers Exploit Windows Flaw shellspeare Off Topic 0 12-30-2005 11:07 AM

AdminFusion

All times are GMT +1. The time now is 05:38 PM. Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

© 2009 AdminFusion | Advertising Opportunities | Legal | A member of the Crowdgather Forum Community
 
From:
Title:

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77