vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin.org Site Feedback (https://vborg.vbsupport.ru/forumdisplay.php?f=7)
-   -   New 'Security Section' Proposal (https://vborg.vbsupport.ru/showthread.php?t=171853)

Boofo 03-04-2008 08:42 PM

Quote:

Originally Posted by magnus (Post 1457012)
To what degree? Have I suffered data loss due to an exploit? No, never.

Regardless, what does this have to do with the issue at hand? The current state of security of my own personal sites has nothing to do with a public discussion/repository for security related topics. If any of my sites are compromised, I can immediately reference my logs, find out what happened, and either patch the exploit or take it offline for further review.

Could you say the same?

My point being, a vBulletin-focused security discussion isn't inherently a bad thing -- but it's not going to accomplish what many think it will. If you want to keep up to date on security issues, subscribe to Bugtraq. Consider getting a basic grasp of PHP, so you can skim through the multitude of hacks before installing to look for basic security risks -- such as unsanitized inputs. Be proactive.

I think you're missing the point of this whole debate. First, you as an experienced Admin could obviously take care of it if it happened to you. But there are those out there that have no clue what to look for or how to fix it if it does happen to them. Have you noticed how many "I've been hacked! Help!" threads have been popping up lately? And all from Admins that are either new to the being-hacked arena or inexperienced in the process of running a vb site. That doesn't make them any less deserving than you or I, and yes, even iogames (although, that is debatable). I get fed up hearing "then you shouldn't be running a site if you don't know who to fix it" statements. How many of us were born with the knowledge to run a site? I sure as hell wasn't. And neither was anyone else. It is a learning process and vbulletin.org is the school.

An area like we are discussing it a great idea for reference if nothing else. If gives a user a place to go to hear others stories about how they were hacked and what it took to fix it or stop it, or whatever. Something like this would be invaluable to a new Admin. I wish they had had something like this around when I was first starting out.

iogames 03-04-2008 08:48 PM

Quote:

Originally Posted by Boofo (Post 1457039)
I think you're missing the point of this whole debate. First, you as an experienced Admin could obviously take care of it if it happened to you. But there are those out there that have no clue what to look for or how to fix it if it does happen to them. Have you noticed how many "I've been hacked! Help!" threads have been popping up lately? And all from Admins that are either new to the being-hacked arena or inexperienced in the process of running a vb site. That doesn't make them any less deserving than you or I, and yes, even iogames (although, that is debatable). I get fed up hearing "then you shouldn't be running a site if you don't know who to fix it" statements. How many of us were born with the knowledge to run a site? I sure as hell wasn't. And neither was anyone else. It is a learning process and vbulletin.org is the school.

An area like we are discussing it a great idea for reference if nothing else. If gives a user a place to go to hear others stories about how they were hacked and what it took to fix it or stop it, or whatever. Something like this would be invaluable to a new Admin. I wish they had had something like this around when I was first starting out.

I'm glad to have you back! [sob,sob,sniff]

Boofo 03-04-2008 09:06 PM

I guess I just snapped there for a second with all the "why don't the newbies know as much as I do" stuff. That is a very sore point with me. We all were newbies at one time or another and didn't know squat about vb. We can learn here but not pass on what we have learned along the way? Sounds like crap to me.

tazzarkin 03-04-2008 09:14 PM

On the 1st page, some guy mentioned that the more you bring attention to it, the more it encourages hackers.

Maybe someone should make a Security Mod that will trace will mods are most likely to be hacked or what parts of the site have open ports, what files have recently been changed, etc. Sort of like a spysweeper/virus checker.

Then instead of talking about hacking, you focus on the security more.

Boofo 03-04-2008 09:57 PM

Quote:

Originally Posted by tazzarkin (Post 1457058)
On the 1st page, some guy mentioned that the more you bring attention to it, the more it encourages hackers.

Maybe someone should make a Security Mod that will trace will mods are most likely to be hacked or what parts of the site have open ports, what files have recently been changed, etc. Sort of like a spysweeper/virus checker.

Then instead of talking about hacking, you focus on the security more.

I agree with the use of the word Security over hacking. Security can cover a lot of areas, including being hacked.

DrewM 03-04-2008 10:05 PM

Just a side note in hope of getting this thread to "calm" a little bit I have posted an idea here: https://vborg.vbsupport.ru/showthread.php?t=172019

Boofo 03-04-2008 10:12 PM

Quote:

Originally Posted by Larrysw (Post 1457098)
Just a side note in hope of getting this thread to "calm" a little bit I have posted an idea here: https://vborg.vbsupport.ru/showthread.php?t=172019

When you start mentioning paid hacks in the same breath as a free security area, looks like a bait-and-switch to me. I want no part of it.

SEOvB 03-05-2008 01:53 AM

Me either, and on a side note, i'm amazed this has made 4 pages, of well...really not much of anything. And this post isn't helping anything!

nexialys 03-05-2008 02:14 AM

Quote:

Originally Posted by tazzarkin (Post 1457058)
On the 1st page, some guy mentioned that the more you bring attention to it, the more it encourages hackers.

thanks to not mention my name... lol

actually, the goal to have a "Quarantine" place where to put the mods with inserts or security issues is one of the reasons why hacking mods may not be discussed here... when you announce that the hack XYZ have an exploit ABC, that is the way to break all the securities... you just need one moron to ask "hey, i have that hack and that version on my site, what can i do to secure my site"... 30 seconds after that post, someone would exploit his site...

that's why the guys on vb.org are NEVER discussing exploits of any hack here... neither would Jelsoft on vb.com ... so why start a place for the opposite means ?!

iogames 03-05-2008 02:47 AM

Quote:

Originally Posted by nexialys (Post 1457208)
thanks to not mention my name... lol

actually, the goal to have a "Quarantine" place where to put the mods with inserts or security issues is one of the reasons why hacking mods may not be discussed here... when you announce that the hack XYZ have an exploit ABC, that is the way to break all the securities... you just need one moron to ask "hey, i have that hack and that version on my site, what can i do to secure my site"... 30 seconds after that post, someone would exploit his site...

that's why the guys on vb.org are NEVER discussing exploits of any hack here... neither would Jelsoft on vb.com ... so why start a place for the opposite means ?!

'Theorically' [sighs]

Is like NOT TEACHING Cops how to evaluate a crime, is like NOT TEACHING Doctors how to prevent diseases...

When an exploit is announced 95% of users will run to solve the problem, reducing the risk, just a few will commit the mistake that you mentioned above...


All times are GMT. The time now is 01:16 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01147 seconds
  • Memory Usage 1,752KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (6)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete