The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#21
|
||||
|
||||
![]()
Ideally, a user just dedicated to PHP (with locked down permissions). Also have a look at upload_tmp_dir (you may want to change this as well, although it is not necessary).
|
#22
|
|||
|
|||
![]()
Sorry for reviving this old thread but how can I know if my site is compromised?
|
#23
|
||||
|
||||
![]()
usually if you keep your bulletin board up to date, your pretty safe
|
#24
|
||||
|
||||
![]()
You don't really know until its too late. However, as mentioned above, keeping your software as up to day as possible will reduce this risk.
|
#25
|
|||
|
|||
![]()
What about the tmp folder?
|
#26
|
||||
|
||||
![]()
What about it? As long as you keep PHP's temp directory secured, you should be fine.
|
#27
|
|||
|
|||
![]()
What I meant was how do I know if the /tmp/ folder is not secured?
|
#28
|
||||
|
||||
![]()
The hacker does not use a /tmp dir, to hack your forum. He takes advantage of your 0777 chmoded dirs in vB to screw you nice.
I posted this issue long time ago but people thought I'm crazy. I even wrote a tutorial on this site how to secure vB... Put it this way: You have a 0777 dir into your /var/www/html (or whatever is the web root)? You can be hacked, very easy. Read this article I wrote long time ago... probably nobody read it. Then secure the same way the curent 0777 dirs, not just the config file. Chmod them to 0750 and own them by nologinuser:root. |
#29
|
|||
|
|||
![]() Quote:
|
#30
|
|||
|
|||
![]()
Teck-
Just to make sure I understand, moving the config.php to another directory out of the public html will not affect vb operation? I was just hacked yesterday and confirmed that it was some sort of database insertion, based on that when I restored a backup database, the hack was cleared. I wasn't able to find any files with changed dates. Is there some other way, other that the hacker breaking the config.php that they could manipulate the database? Note that I also have htaccess on all pertinent directories. Thanks! |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|