Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Security
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Security

 Post Reply Post Reply
Author
glumbert View Drop Down
Newbie
Newbie
Avatar

Joined: 20 February 2003
Location: United States
Status: Offline
Points: 1
Post Options Post Options   Thanks (0) Thanks(0)   Quote glumbert Quote  Post ReplyReply Direct Link To This Post Topic: Security
    Posted: 20 February 2003 at 2:09am

I would just like to warn everyone that if you are using a DSN-less connection, your forum can easily be hacked. If the database is stored in a folder accessible to the web, then the database can be downloaded, and your passwords etc. changed. It happened to my site today. If you can, use a DSN connection with the database stored in a folder which cannot be accessed from the web. Also, the hacker found my forum via google using the search phrase 'web wiz forum' and I noticed that a number of other people were hacked as well.

Back to Top
trendecide View Drop Down
Groupie
Groupie


Joined: 26 May 2002
Location: United States
Status: Offline
Points: 54
Post Options Post Options   Thanks (0) Thanks(0)   Quote trendecide Quote  Post ReplyReply Direct Link To This Post Posted: 20 February 2003 at 5:09am

This isn't good.  Thanks for the warning.  Good thing I'm on SQL server 2000 instead of Access.  DSN isn't much slower than DSN-less unless you have lots of simultaneous users... which you should move to a SQL database if that's the case.  Glumbert is right.

Wear a condom... USE DSN!!  Safety First!

Love, Peace and Chicken Grease!
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 20 February 2003 at 6:50am

You don't need to use a DSN connection.

If you had read the documentation that came with the forum you will have found that this issue is covered.

It is strongly suggestested that you rename the database and move it to a folder that is not accessible through a web browser. For this you don't need to use a DSN connection, a DSN-less connection can be used and all you have to do is change the path in the common.asp files to where the database is located.

If people where to read the documentation then these things wouldn't happen!!!!

Also as many of you don't, version 7 addresses this issue by one-way encrypting all passwords, so it doesn't matter if someone downloads the database, they can't get the passwords.

Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.