The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Security Through Limiting Apache Access to PHP Question
I am trying to harden my servers security (co-location techs actually doing work, out of my league) as I got a new server installed fresh systems (Joomla and vBulletin sites) and imported databases and already got malicious code injected that sends out SPAM email, gets my server black listed and is hard to track down. I have been hacked so many times in over a dozen years and I am really fed up with it. One of the items that was suggested to me for Joomla involves limiting Apache access to Index.php files only:
"The only entry point to Joomla is index.php and administrator/index.php. Older versions of Joomla also use index2.php. They are the only PHP files that need to be served by Apache for Joomla. All other PHP files are loaded by the PHP code, not by Apache. The PHP code is not affected by restrictions in the Apache configuration. The technique may not be applicable to vBulletin, although it may be possible to make some restrictions." My question is whether there are only a few files in vBulletin (forum.php for example) that need outside Apache access so that I could limit what files could be executed? I spend a small fortune on free communities and really starting to regret doing it as I spend more time repairing damage than I do improving or participating at them. One of the sites is a free repository (over 100,000 registered users) and I have had it shut down for months do to the hacking and malicious code. That site doesn't have vBulletin, but my other big one does and it has been hit through vBulletin plenty in the past and I am just trying to figure out how to make it tougher to get in. I believe my techs are good, but I think they are generalist and so I am trying to find info specific to vBulletin and Joomla. Thanks in advance for your time and have a great weekend! Cheers! Russell |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|