PDA

View Full Version : Security Exploit Blocker


Mythotical
04-27-2005, 01:14 AM
I'm looking to see if something like this: http://phpbb-amod.com/ has been created which blocks exploit attempts, blocks bots from trying to commit bandwidth theft, and so on. If so could someone direct me to the thread, if not, is there anyone willing to make this hack or take PHPBB's and rework it so it will work with vbulletin 3.0.X?

Thanks in advance
Steve

twoseven
04-27-2005, 01:26 AM
depending on permissions with vB you could not hotlink to files. also there are no known exploits to stock vB right now. if you dont want the bots you can disable them by blocking the ip addy(dont know why you would want to do this but to each his own)

Reeve of shinra
04-27-2005, 01:35 AM
Do you have a direct link to the page with the mod? I dont feel like looking.

Tekton
04-27-2005, 04:14 AM
Do you have a direct link to the page with the mod? I dont feel like looking.
Doesn't sound like you're too concerned about it then~ :P

Reeve of shinra
04-27-2005, 02:34 PM
heh, as far as I know the latest versions of vb are secure but I am always interested in looking at other security measures.

Mythotical
04-30-2005, 05:00 AM
Yes vb has a very good security stable forum but I believe in alot of security now a days. I will get a direct link to the mod so everyone can see it.

Ok got it, here is the link for a bit of a description and download the file:
http://phpbb-tweaks.com/downloads.php?mode=sub&cid=916

Here is a link of what it blocks so you can see its not the bots it blocks but DDos Attempts that can slow down a server or even shut it down.
http://phpbb-tweaks.com/security.html-phpBBSecurity-caught

Zachery
04-30-2005, 01:38 PM
Yes vb has a very good security stable forum but I believe in alot of security now a days. I will get a direct link to the mod so everyone can see it.

Ok got it, here is the link for a bit of a description and download the file:
http://phpbb-tweaks.com/downloads.php?mode=sub&cid=916

Here is a link of what it blocks so you can see its not the bots it blocks but DDos Attempts that can slow down a server or even shut it down.
http://phpbb-tweaks.com/security.html-phpBBSecurity-caught
If you are under a DDOS you call your host a pray, not install a hack..

Mythotical
05-05-2005, 09:58 PM
Zachery, HUH?!? LOL, I do not understand the language the you speak. Lamen's terms if you would please.

Zachery
05-05-2005, 10:24 PM
If you are under a DDOS you call your host a pray, not install a hack..
If you are under a Distribtued Denial of Service attack, you call your host, and you pray

Mythotical
05-09-2005, 12:19 AM
LOL, see thats the thing, I have my own server so he doesn't watch that stuff I have to. So this type of hack would be good for me. But if it doesn't exist or is not possible, I'll live.

Brandon Sheley
05-09-2005, 12:41 AM
i know austins phpbb mod very well, vB isn't anything like phpbb on how its one of the boards you can search google for known exploits... any vb exploits are usually found by the developers b4 the latest vB is even released ;)

Hellspire
05-09-2005, 03:57 AM
Mythotical, simply look up an apache module called 'mod_dosevasive' or something to that name. My host uses it, and a bunch of other modules that basically absorb, redirect or shunt DDOS attacks without any effect. That is an apache thing and is not the province of vbulletin.

In terms of blocking bots from your script, then that is something that you can do with apache htaccess files by either denying access to them, or redirecting them to a certain location.

Both of those are things you should look up on your own as they are not vbulletin. In terms of a vbulletin hack for this, I simply don't see the point? However, for security exploits, I'll let you know if I find one ;D

Zach... pray? My host contacts me and we have a nice laugh at idiots.

Zachery
05-09-2005, 11:05 AM
Mythotical, simply look up an apache module called 'mod_dosevasive' or something to that name. My host uses it, and a bunch of other modules that basically absorb, redirect or shunt DDOS attacks without any effect. That is an apache thing and is not the province of vbulletin.

In terms of blocking bots from your script, then that is something that you can do with apache htaccess files by either denying access to them, or redirecting them to a certain location.

Both of those are things you should look up on your own as they are not vbulletin. In terms of a vbulletin hack for this, I simply don't see the point? However, for security exploits, I'll let you know if I find one ;D

Zach... pray? My host contacts me and we have a nice laugh at idiots.
Guess you've never been under a real DDOS. probally just one or two kids with 100 bots.