I am a vBulletin forum owner, running on the 3.6.5 version..
I have read in many websites about some steps that you have to do
to protect your forum from getting hacked,
below are some of the mentioned steps:
1. Change the name of the "admincp" and "modcp" folders.
2. Give a username/password protection from the websites main cpanel
to the following folders "admincp - modcp - includes - install - archive"
3.Change the prefix in the config.php file to another new number/word.
example: $config['Misc']['cookieprefix'] = 'jydh23';
4. Bann the use of the following words in the forum from the forum cpanel:
"cook cooki cookie cookies COOK COOKI COOKIE COOKIES META meta SCRIPT script"
5. Change the content of the following files " showgroups.php - memberlist.php - online.php"
with the contents of the "index.php"
6. If possible do not display your forums version in the forums footer.
7. Disabling the forums archive.
My questions are:
- Is it necessary for me to do these steps?
- Will they really protect my forum from being hacked?
- Is it possible that my forum gets hacked if i don't do them?
- Is it possible that my forum gets hacked if i do them?
- Some of the steps are clearly stupid like step 1, 4, 5, 7 while some others seem to be important like 2 and 3, what do vBulletin moderators think of them?
- what's the best way to protect my forum?
Thank you,
Nizar Selander.