Welcome Guest ( Log In | Register )



2 Pages V   1 2 >  
Closed TopicStart new topic
> Announcement: Importance Of Regular Site Backups !
miCRoSCoPiC^eaRt...
post Jun 3 2006, 04:30 PM
Post #1


PsYcheDeLiC dR3aMeR
Group Icon

Group: Admin
Posts: 2,242
Joined: 29-January 05
From: Nakorn Chaisri, Thailand
Member No.: 2,411



    [/tab]This is to inform all our members that recently we've been facing a lot of hacking attempts from various upcoming groups - whose sole purpose seems to be defacing our members' sites. In most cases it's just a minor botheration though I've no clue what they're gaining out of it.

[tab]Pertaining to this I'd like to mention that we don't employ a server-side backup mechanism anymore. Long time back we used to perform weekly backup of all our members' sites - but this service has been discontinued for a while now owing to some conflict with the quota system.

    [/tab]Recently one of our members lost his site to a defacing attack. The hackers got in and completely trashed his site including his MySQL DBs. Unfortunately he didn't have any backups on his own part and neither did we.. hence the whole site was lost and he'd probably have to start from scratch again. Re-desgning pages are still ok - but what hurts most is all the lost posts/content in case you're running a Forum and/or CMS.

[tab]Thus I'd like to stress on the necessity of maintaining regular backups of your site on your own - in case you come under such an attack. To facilitate your backing up job, the cPanel Site Backup option has been enabled to allow you to perform a single-click backup of your whole site. You should do this as often as possible - and at least once every week. Make this into a habit since it's a job that'll take up just a few minutes of your time once a week - but might save you a lot of tears in the long run.

    Moreover, most such hacking attempts are usually successful if you're using a weak dictionary based cPanel password - which can be easily cracked using some brute-force password generator/cracker. Thus I'd highly recommend you to keep changing your cPanel passwords from time to time apart from making them as cryptic as possible using combinations of both numerals and upper-case, lower-case letters and if possible punctuation marks. If you find it difficult to remember such passwords, there are plenty of Free and Good Password Managers available for download - where you can store such passwords sitewise for future reference.

Best Regards,
miCRoSCoPiC^eaRthLinG
Go to the top of the page
 
+Quote Post
pyost
post Jun 3 2006, 04:40 PM
Post #2


Nenad Bozidarevic
Group Icon

Group: [MODERATOR]
Posts: 998
Joined: 7-November 05
From: Belgrade, Serbia
Member No.: 9,500



If I may add, if you run a forum, CMS, or any other kind of software that uses databases on your web site, try to find a plug-in that sends a database backup to your e-mail every day. It can be very useful in case you lose all your data.
Go to the top of the page
 
+Quote Post
miCRoSCoPiC^eaRt...
post Jun 3 2006, 05:03 PM
Post #3


PsYcheDeLiC dR3aMeR
Group Icon

Group: Admin
Posts: 2,242
Joined: 29-January 05
From: Nakorn Chaisri, Thailand
Member No.: 2,411



QUOTE(pyost @ Jun 3 2006, 11:40 PM) *

If I may add, if you run a forum, CMS, or any other kind of software that uses databases on your web site, try to find a plug-in that sends a database backup to your e-mail every day. It can be very useful in case you lose all your data.


True - that'd help a lot too. In any case it shouldn't be all that difficult. I think if you search around the Database forum I'd posted a script long time back - called autobackupsql or something on those lines.. that generates automated full-backups of your specified MySQL DBs at specified intervals. You can just add in another small script in your crontab to mail gzip this file and mail it out to you at regular (weekly) intervals.

I found the script I'd posted earlier. It's called automysqlbackup and can be found at this thread:
Auto-backup Your MySQL DBs Daily/weekly/monthly
Go to the top of the page
 
+Quote Post
yeh
post Jun 3 2006, 05:14 PM
Post #4


Advanced Member
Group Icon

Group: Members
Posts: 147
Joined: 13-May 06
Member No.: 13,389



Hmm... Is this defacing thing common? Or is it just a handful of individuals that have their websites defaced?


I have a suggestion. I don't think we can change our username. I'm new here so I could be wrong. When we submit our application, we were ask about our username. I think when we actually sign up using the process form, we need to specify our username. There might be a chance that both of the usernames matches. In fact, there is a high chance if users reply to the application form truthfully.

As such, I suggest that approved applications be totally removed from view after maybe, let's say, 2 weeks? Then whoever that tries to use a password generator would have a tough time becoz he/she needs to guess the username as well.
Go to the top of the page
 
+Quote Post
nightfox
post Jun 3 2006, 09:49 PM
Post #5


NiGHTFoX - Hiding in the dark
Group Icon

Group: Members
Posts: 680
Joined: 3-April 05
Member No.: 3,584



QUOTE(yeh @ Jun 3 2006, 01:14 PM) *

Hmm... Is this defacing thing common? Or is it just a handful of individuals that have their websites defaced?

All web hosts usually have this problem. Sometimes it is more than defacing but a hacker gets into the server and just creates or deletes some accounts.
QUOTE
I have a suggestion. I don't think we can change our username. I'm new here so I could be wrong.

Yep, you can't change your server username. The only way to change it is to delete your account and create it again.
QUOTE

As such, I suggest that approved applications be totally removed from view after maybe, let's say, 2 weeks? Then whoever that tries to use a password generator would have a tough time becoz he/she needs to guess the username as well.

Usernames need to be 6 characters. So you can still use a brute force tool to associate a username with a password.

There really isn't anything that can be done to prevent a hacking attempt. Just save your data.

btw, I'm probably going after a degree in network security. I've read the books.

[N]F
Go to the top of the page
 
+Quote Post
Sarah81
post Jun 4 2006, 12:32 AM
Post #6


That really was a Hattori Honzo sword.
Group Icon

Group: Members
Posts: 473
Joined: 27-August 05
From: Texas, USA
Member No.: 8,126



Thanks for the heads-up, m^e. I keep copies of my files both on my hard drive and on a USB flash drive already. But man I would hate to have to re-create all my junk just because some punks thought that trashing Web sites was fun.

I'd like to add one more piece of advice on passwords: don't use the same password for all of your sites. Even just using a variation from one site to the next is better than having the exact same thing everywhere you go on the Internet.
Go to the top of the page
 
+Quote Post
lonebyrd
post Jun 4 2006, 03:13 AM
Post #7


Premium Member
Group Icon

Group: Members
Posts: 302
Joined: 23-February 06
From: Northeastern Connecticut USA
Member No.: 11,487



I just started changing up passwords for things on the internet and on my website stuff. Not that I've been hacked (yet), but, more and more by reading this forum and the like I've come to the conclusion that people as a whole cannot be trusted on the net. And when my site is more developed, I'm definitly gonna need to make sure I know how to back it up. Especially that database thing. And I'll also have to look up that cron job thing about the site back-up too. Thanks for the heads up M^E. I mean, I always knew it was a possibility, but now I know some ways to protect myself.
Go to the top of the page
 
+Quote Post
miCRoSCoPiC^eaRt...
post Jun 4 2006, 11:16 AM
Post #8


PsYcheDeLiC dR3aMeR
Group Icon

Group: Admin
Posts: 2,242
Joined: 29-January 05
From: Nakorn Chaisri, Thailand
Member No.: 2,411



I posted the link to that MySQL Automated Backup Script - check it out guys.. it surely is helpful. I'll see if I can come up with some small shellscripts that'll mail out the backed-up data to you at pre-specified intervals..

Any other bright suggestions about protecting your data, most welcome smile.gif

Regards,
m^e
Go to the top of the page
 
+Quote Post
cyborgxxi
post Jun 5 2006, 11:05 AM
Post #9


Premium Member
Group Icon

Group: Members
Posts: 342
Joined: 31-July 05
Member No.: 7,540



Alright, Joe! Thanks for the warning. Man, I feel so bad for that guy who lost his site! I think some government officials should do something about this... or you guys should report this at least. Do you guys have logs and stuff? There should be like a way to track where the attacks came from... it's so not fair for us - just random attacks. I mean, this is just like property assault/damage!!
Go to the top of the page
 
+Quote Post
abhiram
post Jun 5 2006, 12:35 PM
Post #10


Hedonist at large
Group Icon

Group: Members
Posts: 610
Joined: 30-July 05
From: another realm
Member No.: 7,524



Hey, I've got a problem! My campus server doesn't allow me to connect to port 2083 anymore. Does anyone know of a method to bypass this thing or any other way to backup data? I've tried tunneling using your-freedom but it isn't working.
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. A Site I Put Together Over The Last 3 Days(0)
  2. Www.modthesims2.com - Sims 2 Mods Site(8)
  3. How To Create Your Own Proxy Site (free And Easy)(13)
  4. Free Site(2)
  5. Regular Expressions(6)
  6. Airtel GPRS(22)
  7. Youtube Videos(4)
  8. Request Form Site Suspended(4)
  9. Create A Site Without Cms But Just Dreamweaver?(6)
  10. Time Travel?(1)
  11. Main Trap17 Site Is Down?(0)
  12. Site Down Again, Help Or Suggestions?(6)
  13. My Site Got Hacked!(9)
  14. Please Hack My Site(23)
  15. Love Calculator(1)
  1. Does This Site Mean Anything To Us…i Don’t Know U Tell Me?(3)
  2. Site Link Analyzer Tool(1)
  3. Web Host Review Site(0)
  4. Visit My Site, Internet Stops For A While(8)
  5. Add A Search Box To My Web Site(10)
  6. Hack This Site(28)
  7. Integrate Access Database Onto Intranet Site(5)
  8. Add A Forum To Your Site(20)
  9. Website Navigation Hover Buttons Stick So Made Css Today(7)
  10. Sparkx Website(3)
  11. Using Regular Expressions To Parse Functions(5)
  12. Flash Site Software(10)
  13. Site Will Not Load, I Can Not Get To The Cpanel(6)
  14. Can't Access Any Site Hosted On The Server(4)
  15. Php Script To Download File From Another Site(9)


 



- Lo-Fi Version Time is now: 22nd August 2008 - 05:25 AM