Go Back   HYIPs Talk - Your HYIP Investment Forum > -->Hyips Talk Forum (NO Advertising or Ref Links) > Computer Safety and Security and Technical Support

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-16-2007, 04:52 PM
Senior Investor
 

Join Date: Jan 2007
Location: Nomaden..
Posts: 862
Rep Power: 4
umat_gila is on a distinguished road
Points: 78
Red face Your Community's Security

have a nice post in some forum, hopefully its helpful for you..


When "internet security" is mentioned, most of you probably think of hackers, virii, worms, and Trojan horses, all of which hardly apply to you. But the truth is, internet security is an important issue for anyone online, and is especially significant for anyone running a web site. Forums are big targets for hackers and crackers, due to the fact that bulletin boards members may become argumentative and passionate about their differing opinions. If angered by a banning, a user might try to find nefarious means of rejoining or harming your forum!

What can you do to protect yourself? First, let me cover some background information and basics you should know about security. There are many different kinds of attacks that your forums may be susceptible to. The most common attacks you will encounter are Cross-Site Scripting (XSS) exploits, SQL injections, and password cracking/abusing.

Cross-Site Scripting (XSS) exploits
XSS exploits usually depend on a malicious, specially crafted URL to execute arbitrary code (HTML, JavaScript, etc) in a user's browser, which undermines the user's trust in your site. In layman's terms, it allows someone to embed HTML on your site. For example, an attacker could create a page that impersonates your forum's login screen, but actually just steals a user's password when he or she enters it. Or, using JavaScript, an attacker could intercept information stored in a user's browser (cookies) and use that information to hijack and post under the user's account. NOT something that will add to your forum's popularity, that's for sure!

SQL injections
SQL injections can provide database access to any attacker. SQL injections happen when unchecked variables used in a SQL statement can be modified (generally by the end user with a malformed URL). What does that mean? Basically, SQL exploits extend to the point where the attacker can run any SQL query, thus gaining the power to do almost anything an administrator could do. Obviously, this is a serious threat you want to protect against, as you don't want an attacker to gain complete control over your forum!

Password cracking/abusing
Password cracking is when attackers try to force their way into an account, using a password list or creating random strings. These attempts are generally very weak, as most bulletin board systems will lock an account out after a few (generally, 5) unsuccessful login attempts. Password abusing is simply compromising the proper use of an account, such as a friend logging into his friend's account with a known password, or someone using a known password you use for your admin account. They could obtain this password from any other site you use it on (for example, a forum which does not encrypt passwords).



Why does all of this matter? As I have touched upon, these types of attacks can have huge effects on your community. A hacker could delete users, read/modify any thread, and even delete your forum. As I alluded to above, a hacker could modify posts or custom titles to include malicious HTML which could steal cookies (and allow them to log in under any user), or even utilize the newest Internet Explorer exploit. All of a sudden, it is not just your forum that could be in danger. Are you prepared? In this day and age, attacks are becoming more and more frequent.
Protect your members with these following tips:

* Use strong passwords, and change your password frequantly. This should be obvious, but people neglect password security all the time. Use a strong password, which generally is a password 7 characters or longer with letters and numbers. The more complex your password is, the harder it is to crack, but do not make it so you cannot easily remember it. Leaving a sticky note on your computer with the password can ruin any benefit from a strong password. Remind your members to keep their passwords private.
* Keep yourself informed of exploits that may affect you. At the bottom of this article are links that show all the public current exploits out. Searching for "vBulletin", "phpBB", etc will show you exploits your forums may be susceptible to.
* Keep your bulletin board upgraded to the newest version.
* Add an additional password layer to your mod or admin control panels ( more information here )
* Do not give FTP access to anyone else, even if it's in a subdirectory. If someone can run PHP, they could easily steal your database login information and even set up phpMyAdmin (a popular database managment tool). If you have to give FTP access out (for example, to moderators), use a different domain.
* Only install hacks from a trusted source. If you know PHP, examine all hacks you install. A malicious hack could gain complete control over your forum. Be very wary of hacks that use encrypted code.
* Do not use your forum to give private imformation to anyone (including PMs). In a recent security audit, I found cPanel login information in private messages after I gained database access. Be careful.


Is your security helpless? Hardly. By being smart about your forum's security, you can easily help protect the boards, you, and your members. If you ever see any suspicious activity, change your password and do not be afraid to ask for help.

Resources
The following links can be very helpful in securing your forum:

* SecurityFocus
* Packet Storm
* vBulletin Bug Tracker
* milw0rm
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Paid Advertisement
  #2 (permalink)  
Old 01-16-2007, 06:44 PM
Investor
 

Join Date: Jan 2007
Posts: 211
Rep Power: 2
emmet is on a distinguished road
Points: 15
Default

YEAP, thanks very mutch for the information, it's very good to know.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 01-17-2007, 01:12 AM
Investor
 

Join Date: Jan 2007
Posts: 141
Rep Power: 3
caro is on a distinguished road
Points: 0
Default

yeah, just say thank very much, it is very helfull information, great job
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 01-17-2007, 08:22 AM
Senior Investor
 

Join Date: Jan 2007
Location: Nomaden..
Posts: 862
Rep Power: 4
umat_gila is on a distinguished road
Points: 78
Default

Quote:
Originally Posted by emmet View Post
YEAP, thanks very mutch for the information, it's very good to know.
Quote:
Originally Posted by caro View Post
yeah, just say thank very much, it is very helfull information, great job
Im so very happy if its realy useful for u..Later i have made some thread with elese info again...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 01-27-2007, 05:21 AM
Senior Member
 

Join Date: Jan 2007
Posts: 109
Rep Power: 2
earn_hyip is on a distinguished road
Points: 0
Default

that was a good and useful information.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 01-27-2007, 03:54 PM
Investor
 

Join Date: Jan 2007
Location: Indonesia
Posts: 235
Rep Power: 2
khiang is on a distinguished road
Send a message via Yahoo to khiang
Points: 0
Default

Thanks for the information, its very usefull for me, as i,m work in computer shop
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 01-28-2007, 05:46 PM
Investor
 

Join Date: Jan 2007
Posts: 234
Rep Power: 2
Santerus is on a distinguished road
Points: 0
Default

Very helpful info. As I can see this forum is very useful for me.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 01-29-2007, 12:44 AM
Investor
 

Join Date: Jan 2007
Posts: 279
Rep Power: 2
gianbryant is on a distinguished road
Points: 0
Default

thanks for sharing this information.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 02-06-2007, 02:51 AM
Senior Investor
 

Join Date: Jan 2007
Location: Nomaden..
Posts: 862
Rep Power: 4
umat_gila is on a distinguished road
Points: 78
Default

ur always wellcome brother...
later i will give u another tutorial...

regards,
me
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 02-06-2007, 02:23 PM
Senior Member
 

Join Date: Jan 2007
Posts: 124
Rep Power: 2
VM Guardian is on a distinguished road
Points: 0
Default

I guess this thread is the most important in this forum, as here you can find really useful info as the above is said. I think every internaut should know it
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 01:54 PM.


Advertising
$150/week or $580/month!
$60/week or $220/month!
$40/week or $140/month!
$30/week or $100/month!
click to view LargeSUM.com details on Investdad.com
$25/week or $80/month!
Get the HYIPsTalk.com Buttons :
Add these buttons to your site by copying the code below:







Link Partners
HYIP Surf Talk | Partners | HYIPS Tracker

MoneyTalkPro.com - Get Paid to Post Forum

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Copyright © 2007 HYIPs Talk All rights reserved