Well, that would be correct, 2 and 3 seem like the only completely valid measures. Although, you probably only need to password protect the directory Admincp and ModCP. You should keep HTML code disabled. DO NOT ENABLE IT UNDER ANY CIRCUMSTANCE.
Also, logging into the admin and mod cp as little as possible helps as far as cross site scripting goes. In answer to your direct questions-
1- Vbulletin is fairly secure as it is, but it can't hurt.
2- In reality, even with them your forum COULD get hacked, but don't count on it.
3- Same concept as 2, but you still shouldn't have to worry about it too much.
4- Same as 2,3
5- Explained at the top of the post
6- Whatever you think nescassary, just watch out for DDOS, that is a hassle.
|