Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - How to prevent your forum being hacked
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

How to prevent your forum being hacked

 Post Reply Post Reply Page  123 10>
Author
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Topic: How to prevent your forum being hacked
    Posted: 31 December 2005 at 12:18pm
Web Wiz Forums is one of the most secure forum packages around, and this can be seen by the very few vulnerabilities that have been found in the software and the 24 hour patch turn around for any that are found (this is why allot of large hacking sites use Web Wiz Forums).

However, your forum is only as safe as you make it, and often people don't follow the install instructions on securing their forum, then blame it on the software when their forum is hacked.

The Turkish hacker, is just one hacker, who constantly hacks unsecured Web Wiz Forums installations on a daily basis.

Like all hackers he is using a number of exploits to get in and delete or deface forums, on sites that have; insecurely setup servers, running old versions or incorrectly patched Web Wiz Forums, or those who simply have not followed the install instructions to secure their forums Access database.

Please read the following on how forums and web sites are hacked and ways to prevent it:-
  1. Hackers download Access database's and get details to use so they can login as the forum admin from that they can not only mess up your forum, but your entire web site!!. Make sure you place the database out side of your web sites root folder where it can be downloaded see, http://www.webwiz.net/web_wiz_forums/docs_access_move_db.asp

  2. Hackers look for older versions of Web Wiz Forums, or ones that have not been updated correctly and then uses old, mainly XSS hacks, to deface forums. To prevent this make sure you are running the latest version.

  3. Hackers also looks for holes in the servers own security, for sites that have not setup permissions securely and have write and modify permissions enabled on public files and folder, this allows a hacker who has compromised the admin account of your forum to upload his/her own files to the server to deface or hack entire sites. Permissions need to be set by your web host, contact them to setup secure permissions for your site (disable Write and Modify permissions).

  4. Do not enable upload features in the forum. For uploading to work you need to make your server insecure by enabling write permissions on the upload directory, these can be used by a hacker to hack your site (as in point 3).



Edited by -boRg- - 19 January 2006 at 10:52am
Back to Top
dfrancis View Drop Down
Senior Member
Senior Member


Joined: 16 March 2005
Location: United States
Status: Offline
Points: 442
Post Options Post Options   Thanks (0) Thanks(0)   Quote dfrancis Quote  Post ReplyReply Direct Link To This Post Posted: 31 December 2005 at 4:43pm
BoRg, can you explain number 3? (Privately if you think better.) I'm not familiar with this exploit.
Back to Top
Amateur View Drop Down
Senior Member
Senior Member
Avatar

Joined: 22 July 2004
Location: Ireland
Status: Offline
Points: 210
Post Options Post Options   Thanks (0) Thanks(0)   Quote Amateur Quote  Post ReplyReply Direct Link To This Post Posted: 01 January 2006 at 2:36am
Cheers BoRg, thanks for the pointers.

Now people, wake up and obey them and dont be complaining in time when you have been hacked.
Back to Top
megetron View Drop Down
Groupie
Groupie


Joined: 20 September 2004
Status: Offline
Points: 147
Post Options Post Options   Thanks (0) Thanks(0)   Quote megetron Quote  Post ReplyReply Direct Link To This Post Posted: 01 January 2006 at 9:22am
I didnt know that option 4 is unsecured..Confused
good to know. thanks.
Back to Top
megetron View Drop Down
Groupie
Groupie


Joined: 20 September 2004
Status: Offline
Points: 147
Post Options Post Options   Thanks (0) Thanks(0)   Quote megetron Quote  Post ReplyReply Direct Link To This Post Posted: 01 January 2006 at 9:25am

Jus one question about 1...

How can they know what is the file name if U have changed it? hackers can only guess..am I write?
Back to Top
Lynford View Drop Down
Groupie
Groupie


Joined: 14 December 2004
Status: Offline
Points: 171
Post Options Post Options   Thanks (0) Thanks(0)   Quote Lynford Quote  Post ReplyReply Direct Link To This Post Posted: 01 January 2006 at 7:40pm
Originally posted by Amateur Amateur wrote:

Cheers BoRg, thanks for the pointers.

Now people, wake up and obey them and dont be complaining in time when you have been hacked.


I left it and left it (cos I couldn't understand what to do Embarrassed) and surprisingly enough - I got doneAngry

I'm not very experienced but it really is pretty easy to do once you concentrate Thumbs Up
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 03 January 2006 at 2:01pm
Originally posted by dfrancis dfrancis wrote:

BoRg, can you explain number 3? (Privately if you think better.) I'm not familiar with this exploit.

Yes, it quite easy, you should always secure your server by disabling write and modify permissions on public folders.

If you don't any hacker armed with simple hacking tools is able to place files onto the server through HTTP and deface web sites. This is how web sites are usally defaced.

I was tought how to do this as a security part of a network unit at University and it is so simple 12 year old hackers often just download simple tools to do this. This is why most sites are hacked around the school holidays.

I haven't used it for a long time but as far as I remember the IIS lockdown tool from MS disables write and modify permissions for public folders (I could be wrong about this tool).

For this site the only permissions I allow for the IUSR account on public folders is read.


Edited by -boRg- - 03 January 2006 at 2:01pm
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 03 January 2006 at 2:04pm
Originally posted by megetron megetron wrote:

Jus one question about 1...

How can they know what is the file name if U have changed it? hackers can only guess..am I write?

Another simple thing to do, if your server is setup to send detailed ASP debugging errors to the client (most are) then it is quite simple to course an ASP error that can give details of the database name and location.

This is why all Access databases need to be placed in secure folders.
Back to Top
 Post Reply Post Reply Page  123 10>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.