Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - My forum got hacked
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

My forum got hacked

 Post Reply Post Reply
Author
Andreas.E View Drop Down
Newbie
Newbie


Joined: 12 October 2006
Location: Norway
Status: Offline
Points: 19
Post Options Post Options   Thanks (0) Thanks(0)   Quote Andreas.E Quote  Post ReplyReply Direct Link To This Post Topic: My forum got hacked
    Posted: 16 May 2008 at 12:30pm
I all

Recently i installed my forum on a subdomain.. and upgraded to the 9.50 version for MSSQL. Five min ago the site, where the forum is located got hacked. The persons behind the attack only replaced the default file for the forum, and im running daily backups so its no problem.

But what I start to wonder, is it an easy way in to my folders via the structure and design of the forum, or how its coded?

Any advise regarding improving the security on a general basis is highly appreciated. Note.. that this is not criticism against  Bruce or the team behind the software. Its just a curious question? Wink

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 16 May 2008 at 12:43pm
We are very particular about ensuring the software is secure and check security sites almost daily and if any secure hole, no matter how small, is found we generally have a fix out for it with 2 hours of being made aware of the issue.

At the present time we are not aware of any vulnerabilities in the present version and the only way to be sure of how this was done is to look at your website log files.

You have not mentioned what version you upgraded from, it could be that you were running an old version 7 before which did have a number of security vulnerabilities and the hacker may have used this older version to upload a file that gives him/her a back door to your site to change files.

What you should do is:-

1. Make sure that you ONLY have read, write and modify permissions on the 'upload' directory. The rest of your site should have 'read' only permissions, this prevents hackers from defacing your web site.

2. Check that there is not an unsafe file and image upload type in your forums upload settings (things like .asp, .php, .aspx, etc. should not be permitted as upload types). Towards the end of version 7 this was changed so that the admin can only permit 'safe' upload file types when configuring upload settings.

3. Check your entire site for any files that shouldn't be there. The hacker may have placed a file on your site that allows then access to your web sites files.

4. Make sure that you always keep up-to-date and running the latest versions of any software, like Web Wiz Forums, that you have running on your web site.


Edited by WebWiz-Bruce - 16 May 2008 at 12:46pm
Back to Top
Andreas.E View Drop Down
Newbie
Newbie


Joined: 12 October 2006
Location: Norway
Status: Offline
Points: 19
Post Options Post Options   Thanks (0) Thanks(0)   Quote Andreas.E Quote  Post ReplyReply Direct Link To This Post Posted: 20 May 2008 at 7:28am
Originally posted by WebWiz-Bruce WebWiz-Bruce wrote:


1. Make sure that you ONLY have read, write and modify permissions on the 'upload' directory. The rest of your site should have 'read' only permissions, this prevents hackers from defacing your web site.


This was the way in… And thank you Bruce for clarifying the topic Thumbs%20Up


Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.