| | #1 |
| The OLD Site Owner ![]() Join Date: May 2006
Posts: 505
![]() ![]() ![]() ![]() ![]() ![]() | Wanted to share an experience and help others from our dilemma. One of our other forums is in a highly competitive area. We support satellite receiver manufacturers. We had a hacker try and take down our site and we think he was paid by one of the receiver manufacturers. Dude was intense, he was able to log in as my name, mess with the site, and then wipe out the admin log. I have the db backed up every hour because the site is so big so it wasn't that big of an ordeal with him erasing info or changing settings. It was crazy though because he wouldn't do anything like catastrophic like wipe out the forum contents, he would go and change permissions to forums and post as other users. So we would ban the ip addresses as we would see them come on, of course he was using a proxy so we had to just stay on it. We further changed the location of the admincp. I would suggest everyone do this. Instead of making it forum/admincp make it something totally unique. Also, its useless to change the location of it, if you don't also remove the link from the footer. It leads you right to it. For an added level of protection, put an htacess in the admincp folder and password and ip block access to allow only those who should be allowed. Many times sites will only have one or two admins so it is not a big deal. Once we limited the admincp to only certain ip's the attacks died down to him logging in as other users and posting bogus info. We just had to stay on it and block the ip's as we saw him log on. Here are some other tips that i learned through this 5 day ordeal.
I'll post more as i think of it, but it was quite an ordeal we went through and i think this sums up the steps we took. Anywho, please protect yourselves so this doesn't happen to you.
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. -- Free to Air Satellite Helper Forum To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| | |
| | #2 |
| The Webmaster ![]() | Thanks for sharing that Eric. A lot of good advice to keep your forum secure. I just went and removed some plugins that were disabled but still installed. I also had some users who had their passwords the same as their usernames which comes up if you have the latest version of vB, so I reset all their passwords and sent emails out. None of them were mods or admins though. I also have it set to force me to change my password every few months.
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - The Largest LucasArts Gaming Community on the Internet To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - tell me your comments! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - Your #1 place to discuss all things World of Warcraft. |
| | |
| | #3 |
| The OLD Site Owner ![]() Join Date: May 2006
Posts: 505
![]() ![]() ![]() ![]() ![]() ![]() | excellent.......
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. -- Free to Air Satellite Helper Forum To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| | |
| | #4 |
| Member Join Date: May 2007 Location: UK
Posts: 134
![]() | I did it so all my members had to change their passwords every 2 months, however a few reported that the page where it asks you to change your password didn't exist. Anyway, thanks for the tips ![]() I'm gonna make a few changes to my forum on Sunday, and they will be on of them
__________________ █ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - BassLine Chat forum! █ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - Free Sim Card Alerts |
| | |
| | #5 |
| Forum Enthusiast ![]() ![]() ![]() | I do this on my largest site.
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. More to be listed soon. |
| | |
| | #6 |
| Forum Junkie ![]() | Nice list of things to check and fix there, thanks. you're doing it wrong, see here for reference, kay? http://heylarryhughespleasestoptakin...-excellent.jpg
__________________ Ack, no currently active projects To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| | |
| | #7 |
| Apprentice | Good advise. ![]() I would also recommend that you tell you admins the adminCP location in a email or IM, not in a forum post or PM.
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. PDC is almost here! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| | |
| | #8 |
| Rookie Join Date: Jun 2008
Posts: 25
![]() | Damn.. I wish I had read this a few months ago. Some a-holes came in and wiped our forum clean. They deleted the whole site, nothing is left. The owner called his hosting company and asked them for a back up. They told him it was extra so they don't have one. We've asked several people to help and they tried but couldn't recover anything. The owner stumbled upon a back up hidden away from 2007. I told him to re-install it and he did but he's having a lot of trouble with bringing the site back up... what a mess.Those people don't realize SpursReport.com is a business not just a fan forum. What repercussions can be done if we find out who actually did this? Any help or advice would be appreciated. ![]() Thanks. |
| | |
![]() |
| Tags |
| admincp, hackers, ip blocking, protection, safety, tips, vbulletin |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Where do I edit the Signature Perms in the VB admincp? | Theforumplace | vBulletin | 3 | 09-12-2007 05:30 PM |
| Legal action against hackers? | CultZero | Security and Legal Issues | 24 | 12-23-2006 03:03 AM |
| The Hackers List | gprime | Handling Problem Members | 6 | 05-16-2006 01:27 AM |
| No admincp section when adding hacks | kpr | vBulletin | 2 | 03-20-2006 09:36 PM |
| Malicious Hackers Exploit Windows Flaw | shellspeare | Off Topic | 0 | 12-30-2005 11:07 AM |
