We hope you enjoy your visit.

You're currently viewing our forum as a guest. This means you are limited to certain areas of the board and there are some features you can't use. If you join our community, you'll be able to access member-only sections, and use many member-only features such as customizing your profile, sending personal messages, and voting in polls. Registration is simple, fast, and completely free.


Join our community!


If you're already a member please log in to your account to access all of our features:

Username:   Password:
Add Reply
Just a couple of things that need to be known...
Topic Started: Mar 29 2005, 10:34 AM (546 Views)
Sipefree
Moved to paid hosting.
[ *  *  * ]
People's boards being 'hacked' seems to be on the rise.

Therefore I've compiled a list of what can happen and when can't, for people who don't know.


"[they] has a virus that will attack anyone who enters the ACP"

As Seth said, anyone who believes this does deserve their board to be shut down.
#1: Nobody. Nobody. Can get into your AdminCP without the password, or FTP access to the server. PHP scripts that are accessed from a server can only be done so if someone has uploaded the file to the server via FTP. Javascripts require access to the HTML content of the AdminCP, which again requires FTP access.


"The attackers probably have ended your textarea and put in a script."

And they do this how?
#2: You can't edit (or save, of you use an HTML editor) the page without FTP access or the password (to close the <textarea>).


"...script kiddies..."

Once again, nobody is using any scripts to gain access to your board.
#3: Unless you are stupid enough to let normal users post HTML content, then you are free from all scripts


Then how do they gain access?

Very simply. You can't keep your password private! Always use a strong password (one for only your board!), and keep your email private. In rare circumstances, crackers can get the password for your email address due to security problems with your ESP (Email Service Provider).

Good ways to keep your email private:
Enter in a bunk email address for the Board Emails. The system uses PHP mail() to send emails. It doesn't need a real one. Use something like forums@thegamerzones.tk if you use a .tk.

Use one email for contact and another for your account (use Hotmail or Yahoo! for disposable ones). Give out the contact one to your friends and keep the account one private (by using the option in the UserCP).

The 'Forgot My Password' option is where most things fail. If you keep your email private then you've nothing to worry about.


Anyway, never give out your password to anyone and never fall for tricks like Board Security sites (where you give your password or an admin account and they rid your board of spammers), or 'people to trust access to your AdminCP to install CSS, skins etc.'. 99% of people will find installing skins as easy as copy-and-paste. If you have trouble, ask at a support forum, but never give your password out to anyone who claims to be trustworthy.

Also, Staff Members of IF will always contact you and confirm their identity via Support Ticket before joining your board. If someone contacts you claiming to be a staff member, most of the time they will be an imposter, but to be sure, open a Support Ticket and post up the PM they sent you. You will find out soon enough if it is really a staff member or not.

As for Duffy, he doesn't need your password or an admin account to access your board. I'm sure he has his own admin system where he can control most anything. In any case, he will always contact you.


Be safe,
Sipefree.
Offline Profile Quote Post Goto Top
 
maxxillian
Member Avatar
Member
[ *  *  *  * ]
what can html do wrong ? :unsure:

*maxxillian changes emoticon
Offline Profile Quote Post Goto Top
 
Sipefree
Moved to paid hosting.
[ *  *  * ]
With HTML you can add Javascripts.
Offline Profile Quote Post Goto Top
 
maxxillian
Member Avatar
Member
[ *  *  *  * ]
I see, and other then modify the forum's looks or making it redirect. is there any other threat to it?
Offline Profile Quote Post Goto Top
 
Sipefree
Moved to paid hosting.
[ *  *  * ]
There's always potential.

The point is to only give HTML posting ability to member groups that you trust not to deface your board.
Offline Profile Quote Post Goto Top
 
scizor-ZNS
Member
[ * ]
people joined my friends forum Called foolishly Duff Man and Seth.Very Obvious cause DuffMan Does anot spell his name Duff Man.And they pmed my friend about the virus.and he foolishly gave them hiis pass
Offline Profile Quote Post Goto Top
 
maxxillian
Member Avatar
Member
[ *  *  *  * ]
lmao, some people are verry stupid.

there should be a guillability test on registration medunkt
Offline Profile Quote Post Goto Top
 
Shivan Fire
Support before Beer
[ *  *  * ]
< agrees If you an admin somewhere make sure you password is different than anywhere else never register anywhere else espescially ipb1.3 because md5 hash is easily decoded NEVER give your password to anyone. Security boards or Support forums. ost problems can be solved step by step espescially with IF I know the Admin CP by heart and can tell you how to do most anything from memory so will any good support staff So there is never any need of giving anyone acp access you dont trust. This includes duff dont't trust anyone claiming to be duffy and even if it is duffy he doesn't need your password. Also what he said about e-mail use use hot mail for chatting use a more secure thing like MSN/Yahoo/gmail/Aol/Angelfire for registration and keep it secret from everyone.

Other general security there are programms that keylog passwords and encryptions keepy your Anti virus/spyware service up to date and scan every once and a while. I the end being cracked is easily avoided if you use common sense.

:)
Offline Profile Quote Post Goto Top
 
Stephen
Member Avatar
Twilight is upon me, and soon night must fall.

I saw the increase in crackings also and updated the FAQ with a hacking one. If you'd like, I can add your information in also. :)
Offline Profile Quote Post Goto Top
 
1 user reading this topic (1 Guest and 0 Anonymous)
« Previous Topic · zIFBoards Discussion · Next Topic »
Add Reply