Welcome Guest ( Log In | Register )



2 Pages V  < 1 2  
Reply to this topicStart new topic
> How To Prevent Your Site From Hacking?
Cassandra
post Oct 8 2005, 08:58 PM
Post #11


Advanced Member
Group Icon

Group: Members
Posts: 110
Joined: 6-April 05
Member No.: 3,673



How about using a script which can only be run by "nobody"?
Go to the top of the page
 
+Quote Post
Fate
post Oct 8 2005, 09:04 PM
Post #12


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 13
Joined: 8-October 05
Member No.: 8,988



hmmm...
what exactly do you mean? cant be run by anyone?
with what are you going to limit this? .htaccess? or chmod?
and if no one can access it why does it exist?
it seems odd to me, or i didnt quite understand what you ment?
Go to the top of the page
 
+Quote Post
Cassandra
post Oct 8 2005, 09:29 PM
Post #13


Advanced Member
Group Icon

Group: Members
Posts: 110
Joined: 6-April 05
Member No.: 3,673



QUOTE(Fate @ Oct 8 2005, 09:04 PM)
hmmm...
what exactly do you mean? cant be run by anyone?

I may be crazy, but I'm not that crazy. If I had meant that the script can't be run by anyone, I would have written nobody, without the quotes. When I wrote "nobody', with quotes, I was referring to the special user called "nobody" on many UNIX-type systems. If I'm not mistaken, the user "nobody" is the server itself, and if one sets the owner of a script to "nobody", and then has it writable, executable, whatever, only by the owner, it can't be run except by a process on the server itself, not by an ordinary user. Of course, I may be wrong.


QUOTE
with what are you going to limit this? .htaccess? or chmod?

CHMOD, as above.


QUOTE
and if no one can access it why does it exist?

To preserve the spiritual balance of the Universe.

QUOTE
it seems odd to me, or i didnt quite understand what you ment?
You obviously didn't understand what I meant, but it could be that what I was suggesting is impossible. Somehow, though, I seem to remember seeing scripts which were really written that way.
Go to the top of the page
 
+Quote Post
Fate
post Oct 8 2005, 10:14 PM
Post #14


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 13
Joined: 8-October 05
Member No.: 8,988



you are suggesting a good idea...
though it will require some kind of gateway script that will make the request on the other script so it will originate from the server itself...
otherwise the origin even on regular surfing is always from the user.
what you are suggesting can be done, and ive seen it, its quite good protection...
Go to the top of the page
 
+Quote Post
Cassandra
post Oct 9 2005, 10:35 AM
Post #15


Advanced Member
Group Icon

Group: Members
Posts: 110
Joined: 6-April 05
Member No.: 3,673



I suspect that there's something very simple which would be pretty effective in practice, if not in theory: Just have the script check the referrer. It's true that the referrer can be spoofed very easily, but whoever hacks the site isn't going to know immediately why he got a 403, or whatever, and he often won't have any overwhelming interest in hacking a particular site, unless it's a professional hacking a bank site, or whatever. I suspect that most of the vermin who hack other people's Web sites are script kiddies trying to feel important: if they (or their robots) can't get in immediately, they'll just go elsewhere.

Like the lock on a door, Web security doesn't have to be perfect, and never will be. It just has to be good enough to make hacking that site a waste of the guy's time.

I have two desktop machines always online protected only by minimal and very standard security, and I've never been hacked (yet).
Go to the top of the page
 
+Quote Post
Fate
post Oct 12 2005, 09:50 AM
Post #16


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 13
Joined: 8-October 05
Member No.: 8,988



true enough, personal computers dont usually get hacked by people,
but by worms or other automatic tools, but i think we are going off the subject here.

the subject was site protecting.. smile.gif
and sites, depending on thier content can attract more serious and more skilled poeple to try and brake it.

and i agree that security cant be perfect...
Go to the top of the page
 
+Quote Post
Cassandra
post Oct 12 2005, 10:45 AM
Post #17


Advanced Member
Group Icon

Group: Members
Posts: 110
Joined: 6-April 05
Member No.: 3,673



QUOTE(Fate @ Oct 12 2005, 09:50 AM)
the subject was site protecting.. smile.gif

Well, I was really referring to my Web sites as well, but I decided to phrase it as if I were talking only about my desktop machines because I believe in keeping a low profile, also for security reasons.

Of course, thousands of people per week do find my sites, and I wouldn't want them to stop, but as the lady said, why look for trouble? On the other hand, it could really be that the bad guys don't find my sites "serious" enough. So much the better.
Go to the top of the page
 
+Quote Post
TarzanTerry
post Oct 24 2005, 03:23 AM
Post #18


Newbie [ Level 1 ]
Group Icon

Group: Members
Posts: 8
Joined: 23-October 05
Member No.: 9,252



Make sure all of your moderators and administrators use non-dictionary-word, 'strong' passwords, consisting of 8 or more letters and numbers.

You can add .htaccess protection to your Admin and Mod CP directories, although if you guard your passwords and stay up to date with vBulletin releases, this is somewhat overkill. Although I guess it can't hurt.
Go to the top of the page
 
+Quote Post

2 Pages V  < 1 2
Fast ReplyReply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Hacking That Firmware(2)
  2. Good Places To Advertise Your Site(20)
  3. Flash Site Software(13)
  4. Www.modthesims2.com - Sims 2 Mods Site(9)
  5. Hack This Site(30)
  6. Create A Site Without Cms But Just Dreamweaver?(6)
  7. Add A Forum To Your Site(23)
  8. Please Hack My Site(23)
  9. What Is The Best Photo Sharing Site?(20)
  10. Skemb -- Site Preview(5)
  11. "hacking" The Bios Password(12)
  12. How To Create Your Own Proxy Site (free And Easy)(14)
  13. Youtube Videos(4)
  14. Web Host Review Site(1)
  15. Does This Site Mean Anything To Us…i Don’t Know U Tell Me?(4)
  1. My Site Got Hacked!(10)
  2. Site Down Again, Help Or Suggestions?(6)
  3. Time Travel?(1)
  4. Main Trap17 Site Is Down?(0)
  5. Request Form Site Suspended(4)
  6. Free Site(15)
  7. A Site I Put Together Over The Last 3 Days(7)
  8. Help Me Host My Site On My Pc(4)
  9. Nice Models And Free Models, New Site!(6)
  10. Free Fast Web Submission(2)
  11. Need To Copy An Entire Site..(10)
  12. Site Language(9)
  13. Advertisingknowhow(1)


 



- Lo-Fi Version Time is now: 22nd November 2008 - 09:59 PM