| Author |
Topic Search Topic Options
|
ForumDummy
Groupie
Joined: 04 December 2006
Status: Offline
Points: 58
|
Post Options
Thanks(0)
Quote Reply
Topic: Security Concerns Posted: 07 September 2008 at 4:23pm |
|
I am using v8.05a. I am reluctant to upgrade as I have made so many changes to the code. But I am concerned about security. Are there any dangers by not upgrading? The forum is private and I have had no issues to date. I also keep the forum off the search engines but the main webpages are indexed. Is there anything I should do to keep things safe?
|
 |
123Simples
Senior Member
Joined: 08 July 2007
Location: United Kingdom
Status: Offline
Points: 1192
|
Post Options
Thanks(0)
Quote Reply
Posted: 07 September 2008 at 6:15pm |
|
If you are running an older version such as 8.05, then the dangers are that the software and your forum and your site can be comprimised. Its pretty old now, but it is ones choice to swap or upgrade forum software. I myself am running 9.06, but I will be upgrading to 9.51, or 9.52 if that comes out in a week or so
There are several good reasons why you should upgrade, but you will notice lots of changes, which may not sit well with your current forum
|
|
|
 |
Scotty32
Moderator Group
Joined: 30 November 2002
Location: Manchester, UK
Status: Offline
Points: 1682
|
Post Options
Thanks(0)
Quote Reply
Posted: 07 September 2008 at 6:21pm |
|
Im sure Bruce will post saying how many security fixes their have been...
.. And hes right - At present you are running a forum with known security holes - so it wont take the smartest hacker to get in.
I would highly recommend upgrading - You could create a 2nd test site and apply all your changes to it, and once ready upgrade your main site with it.
|
|
|
 |
123Simples
Senior Member
Joined: 08 July 2007
Location: United Kingdom
Status: Offline
Points: 1192
|
Post Options
Thanks(0)
Quote Reply
Posted: 07 September 2008 at 6:49pm |
Hiya Scotty Your links work out fine by the way  Agree with Scotty on this fact - "so it wont take the smartest hacker to get in"
|
|
|
 |
ForumDummy
Groupie
Joined: 04 December 2006
Status: Offline
Points: 58
|
Post Options
Thanks(0)
Quote Reply
Posted: 08 September 2008 at 2:32am |
Scotty32 wrote:
Im sure Bruce will post saying how many security fixes their have been... |
Is there a way I can get a list of security fixes since 8.05a?
Scotty32 wrote:
At present you are running a forum with known security
holes - so it wont take the smartest hacker to get in. |
1) How do the hackers get in the "known security holes" if my forum is
not on the search engines? How will they find my forum to begin
with?
2) What exactly is it that a hacker can do? Get into my
adminstation login? Or, can they get further into my server
itself?
|
 |
Scotty32
Moderator Group
Joined: 30 November 2002
Location: Manchester, UK
Status: Offline
Points: 1682
|
Post Options
Thanks(0)
Quote Reply
Posted: 08 September 2008 at 9:52am |
|
You can find all the changes in the Version History.
1) the hackers will be able to download the version history and see
what changes have been made, then attack this hole on sites not been
upgraded. They may even find the details on secruity websites.
They can find your site by doing search terms such as "web wiz forum
v8", i usually see "web wiz forums :inurl(uk)" or something like that.
2) there are various things a hacker could do, depending on the exploit.
They could upload malicious files, which could replace your files, read
secure files, etc (there have been improvements on the security of
uploading)
They could use Cross Site Scripting, I believe V9 has improved security on that.
So there is alot of different things they could do.
It would be in your best interest to upgrade.
|
|
|
 |
ForumDummy
Groupie
Joined: 04 December 2006
Status: Offline
Points: 58
|
Post Options
Thanks(0)
Quote Reply
Posted: 08 September 2008 at 10:25am |
Scotty32 wrote:
They can find your site by doing search terms such as
"web wiz forum v8", i usually see "web wiz forums :inurl(uk)" or
something like that. |
By search, I assume you mean via the search engines. But my forum
is not indexed on any search engines. Can they still finding it
by searching?
Scotty32 wrote:
there are various things a hacker could do, depending
on the exploit. They could upload malicious files, which could replace
your files, read secure files, etc (there have been improvements on the
security of uploading) |
Are you talking about uploads within the forum itself, like whena user uploads a file? What if I have uploads turned off?
Scotty32 wrote:
They could use Cross Site Scripting |
Do you mean run a script on one server that would affect the forum on my server?
|
 |
Scotty32
Moderator Group
Joined: 30 November 2002
Location: Manchester, UK
Status: Offline
Points: 1682
|
Post Options
Thanks(0)
Quote Reply
Posted: 08 September 2008 at 11:50am |
Do you block search engines from indexing your site via the robots.txt file? If so then you wont be discovered via search engines. But a hacker can still stumble on your site, as i assume it is live on the net. If you have disabled uploads then you should be relatively safe, but I hacker could turn it on if they got access to your admin area. For info on Cross Site Scripting (XSS) you can view it on wikipedia here
|
|
|
 |