Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - wwforum.mdb
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

wwforum.mdb

 Post Reply Post Reply Page  12>
Author
stormshadow View Drop Down
Newbie
Newbie


Joined: 17 June 2003
Status: Offline
Points: 1
Post Options Post Options   Thanks (0) Thanks(0)   Quote stormshadow Quote  Post ReplyReply Direct Link To This Post Topic: wwforum.mdb
    Posted: 17 June 2003 at 3:31pm

I have a question about the security issue involving the wwforum.mdb database. is this still a potential threat to my forum? i read somewhere on the net that hackers use this file to get people's passwords. i opened it in microsoft access and it looks like the passwords are encrypted. are they encrypted and how? should i still move this file or change the name? i'm the administrator and i can't even read my member's passwords. how could a hacker figure it out? it doesn't look like much of a threat to me, but i could be wrong.

Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 17 June 2003 at 4:32pm

passwords are encrypted yes, however you should still move and rename the database.  detailed instructions on how to do this are included in the documentation

Back to Top
hockenpj View Drop Down
Groupie
Groupie
Avatar

Joined: 10 February 2003
Location: Belgium
Status: Offline
Points: 149
Post Options Post Options   Thanks (0) Thanks(0)   Quote hockenpj Quote  Post ReplyReply Direct Link To This Post Posted: 17 June 2003 at 4:34pm

It is still best to move the forum and place it in a private folder if possible. All the passwords are encrypted, however, if the hacker gets hold of the ASP files and the database he will have a better chance of hacking your forum.

Another factor is that if your database can be downloaded it invites people to do so and may use up your bandwidth if you have a large database.

There are a few other reasons well, but considering how easy it is to move or rename the database, I think the above reasons make it worth it!

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 18 June 2003 at 1:38am

Read the following page on how to move the database:-

http://www.webwiz.net/web_wiz_forums/docs_access_move_db.asp

Back to Top
Fitzkah View Drop Down
Newbie
Newbie


Joined: 24 June 2003
Status: Offline
Points: 10
Post Options Post Options   Thanks (0) Thanks(0)   Quote Fitzkah Quote  Post ReplyReply Direct Link To This Post Posted: 24 June 2003 at 10:39am

Yes this is a serious threat, and it is a very good idea to rename and move your database, heres what happened to a site that didn't.
http://www.netherworldusa.com/forum/forum/default.asp
They were hacked immediately because a quick search on google of:
allinurl: wwFoum.mdb
Its the only site that comes up, and I was looking for one to see how easy it is to hack it, to prevent this from happening to my own forum.

Back to Top
pmormr View Drop Down
Senior Member
Senior Member


Joined: 06 January 2003
Location: United States
Status: Offline
Points: 1479
Post Options Post Options   Thanks (0) Thanks(0)   Quote pmormr Quote  Post ReplyReply Direct Link To This Post Posted: 24 June 2003 at 6:52pm

i always put my sensitive data in folders outside of my shared area (i.e. not avaliable from the internet) then in your scripts you access the database using a dsn-less connection. That way noone can download your database.

Back to Top
keeguy View Drop Down
Newbie
Newbie


Joined: 15 November 2003
Location: Canada
Status: Offline
Points: 5
Post Options Post Options   Thanks (0) Thanks(0)   Quote keeguy Quote  Post ReplyReply Direct Link To This Post Posted: 22 November 2003 at 5:16am

if your on a fronpage web can you move the database to the ../_private folder and have it secure? that folder does require the person to know the frontpage username and password to gain access to files in there.

In theory this should work should it not?

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 22 November 2003 at 8:58am
Yes you can do if the permisisons are correctly set in Frontpage.

Don't ask me how to do permissions in Frontpage I don't use the product.
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.