Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Snitz Forums 2000 DEV-Group
 DEV Internationalization (v4)
 How To Secure my (Hacked) v4b Forum?
 Forum Locked  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

tomasalsbro
Average Member

Sweden
818 Posts

Posted - 09 May 2002 :  11:49:02  Show Profile  Visit tomasalsbro's Homepage
Hi,

Whiplash Info has been hacked!

Are their any security patches that works with sf2k_v40_b03?

Any suggestions of what to do?

Cheers / Tomas

!-Keep distance in traffic-!
www.whiplash.pp.se

[edit] The original topic title was Security patches?[/edit]


Edited by - bozden on 10 May 2002 19:38:34<

Deleted
deleted

4116 Posts

Posted - 09 May 2002 :  11:56:14  Show Profile
Tomas, please e-mail me your FTP info ASAP, or meet me on MSN messenger with ID deleted by bozden if you have it installed. It will take time here.

Man, you were checking the Internationalization forum... Didn't you see the bug fix?



Think Pink
==> Start Internationalization Here

Edited by - bozden on 11 May 2002 00:34:15<
Go to Top of Page

Deleted
deleted

4116 Posts

Posted - 09 May 2002 :  12:13:32  Show Profile
So didn't get any connection till now. Here we go (I'll post and keep editing this for you to follow):

  1. Download the latest patch004 (link can be reached from my signature)

  2. Make a backup from your two files which are to be changed (members.asp, pop_printer_friendly.asp)

  3. Upload the patch files (2 of them) to the server

  4. Immediately change your admin passwords, also passwords of any other admins, do not forget to inform them (you've got one more admin today, didn't you?)

  5. Inform your users about the fact and ask them to change their passwords. You may like to put that info into your forum and/or to your main page. It is also a good idea to e-mail your moderators about the issue (or also cange their passwords).

  6. Go to admin options and reset any changed value to the status before the hack

  7. Never strugle with those bad behaving (this time Turkish) kids



More general security/safety recommendations.

  1. Make sure you put the database to a secure folder outside your www directory. If your host does not provide such an opportunity, the next item is more important.

  2. Make sure you have a hard to remind filename for your database lie forum785473_jhgy.mdb (also correct your DB path in config.asp)

  3. Make sure you have a good admin password (not easy to guess, use alpha + numeric + spcial character that has no meaning)

  4. Make sure you backup your database as often as possible. It can be a life saver.

  5. Encrypt the database and protect it with a password

  6. Before making changes (upgrade, MOD addition, adding fixes etc), make sure you backup your database and your forum files.

  7. Are you sure that your favorite MOD does not have any security holes? Do not apply them to critical sites until they get mature.

  8. Do not play with some admin options (allow HTML, allow images, cookies, etc) until you know what you are doing. Same applies to "admin db setup": You can delete whole tables if you do it wrong...

  9. Use a good host which keeps their servers with latest fixes. Make sure that they do not use software (including OS) which can be hacked

  10. If you think somebody hacked/is trying to hack your site, check you logs, download them and keep them. You may need them when you contact your ISP, hackers host or court/FBI (or their analogs)

  11. Keep visiting this site, check the security forum, make sure you also join the list server (info)



Think Pink
==> Start Internationalization Here


Edited by - bozden on 11 May 2002 11:33:47<
Go to Top of Page

Deleted
deleted

4116 Posts

Posted - 09 May 2002 :  17:28:49  Show Profile
Solved with coordination...

Think Pink
==> Start Internationalization Here<
Go to Top of Page
  Previous Topic Topic Next Topic  
 Forum Locked  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.12 seconds. Powered By: Snitz Forums 2000 Version 3.4.07