The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
![]()
Hi there. I run a small vB with only 385 members, and 2 are wanting to try and take it over. I intercepted a message about my site not being secure. I have .htaccess on the admin folder, but appearently it is not enough. Is there anything else I can do? I have 2.3.0 uploaded, and such. But I am totally clueless what to do.
If they do it or not, I am thinking what if someone just does it without discussing it. I have passwords that are constantly changing which I think is a big help, and such. Anyone had to deal with this? |
#2
|
||||
|
||||
![]()
Here's some things you can do to increase the level of security for your forums:
1. Upgrade to the latest version (you've done this) 2. Do not install any hacks 3. Password protect your Admin and Mod CPs: http://www.javascriptkit.com/howto/htaccess.shtml 4. Make sure the getadmin.php file is NOWHERE on your website 5. If you have phpMyAdmin make sure it's password protected. 6. Also ask your host to change the login password for your account. |
#3
|
||||
|
||||
![]()
Great tips, Steve.
Regarding (2) - it is crucial that people who do install hacks that they review the code to ensure there are no backdoors put in. I've never seen one, but it's best to do so. ![]() |
#4
|
||||
|
||||
![]()
Even without an obvious backdoor it's possible that a hack will change the code in such a way to inadvertantly create a security hole or impair one of the security fixes in the default files.
While this isn't likely, it's nonetheless possible. |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|