Oh no! Where's the JavaScript?
Your Web browser does not have JavaScript enabled or does not support JavaScript. Please enable JavaScript on your Web browser to properly view this Web site, or upgrade to a Web browser that does support JavaScript.
Not a member yet? Click here to register.
Forgot Password?

Anti-Hack?

Asked Modified Viewed 5,311 times
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
asked
Member

What can I do so that my site CANNOT be hacked under any circumstances. if there is no method, to at least make it as secure as possible. please help. my site is polishgoals.com.
0 replies

20 posts

S
Super
S
Super 10
~Samchammy

Find some games below!!!
Gamedna.tk
  • Senior Member, joined since
  • Contributed 248 posts on the community forums.
  • Started 32 threads in the forums
answered
Senior Member

Well, Sooner or Later a website will get hacked, most likely the site cannot be prevented from hackers. The site would have to be in contact and eye-to-eye coordination to work for non hackers, I'm sorry, but hackers are always finding a new a better way to get into a network or even secured they have a way to bypass the network too.
0 replies
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
answered
Member

anything to at least increase security?
0 replies
S
Super
S
Super 10
~Samchammy

Find some games below!!!
Gamedna.tk
  • Senior Member, joined since
  • Contributed 248 posts on the community forums.
  • Started 32 threads in the forums
answered
Senior Member

Quote

jak17 wrote:
anything to at least increase security?


Wat do you mean? It wont increase security
0 replies
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
answered
Member

i said is there anything that i can do to at least increase the security of my site?
0 replies
S
Super
S
Super 10
~Samchammy

Find some games below!!!
Gamedna.tk
  • Senior Member, joined since
  • Contributed 248 posts on the community forums.
  • Started 32 threads in the forums
answered
Senior Member

Umm... PHPFusion has a security filter, but I'm not sure were to look for it at.
0 replies
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
answered
Member

No one is answering my question!!! just give me a link to a mod or infusion or something that would increase the security of my site....! :D
0 replies
M
MrSimple
M
Make it work... keep it simple...
  • Senior Member, joined since
  • Contributed 324 posts on the community forums.
  • Started 7 threads in the forums
answered
Senior Member

Have a look at the Security System infusion from http://www.bs-fusion.de. I'm using it on all my sites and I'm very, very happy with it!
Lots of features, proxy black/white listing, filters, etc.

Free and well supported.
0 replies
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
answered
Member

if only it was written in english...
0 replies
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
answered
Member

i dont know if im missing something but it looks German to me...

Ich habe das aktuelle Paket auch nochmal selbst auf einem Testserver installiert und es wird die Version 1.8.2 angezeigt.
Habe mir die infusion.php angesehen -> Version 1.8.2, in die secsys_settings-Tabelle gegangen unter Version 1.8.2 also alles ok bei mir, daher kann ich es nicht nachvollziehen, das bei dir 1.8.1 erscheint. Dieser Fehler wurde bisher von keinem anderen Benutzer bestätigt. Daher ist es kein Bug, da die Version aus der Settingstabelle ausgelesen wird, auch für das Update.

Könnt auch ein Browsercache-Problem sein.
0 replies
R
Raskolnikov
R
promote.opera.com/small/opera94x15.gif
  • Member, joined since
  • Contributed 71 posts on the community forums.
  • Started 8 threads in the forums
answered
Member

Quote

jak17 wrote:
What can I do so that my site CANNOT be hacked under any circumstances. if there is no method, to at least make it as secure as possible. please help. my site is polishgoals.com.


Firstly, you can start by not promoting your site all over here. If you ask me, that's the #1 way to get hacked. Most hackers who specialize in php-fusion find php-fusion sites like yours simply by looking at this site and finding a nice crop to harvest. I've had a few Turkish hackers visit my site, but since I'm mostly runnning the core version, they couldn't find any exploits, so all they could do was leave a lovely picture of Ataturk in my guestbook. I'm positive that they found my site because I promoted it in the "Post your site" forum. Once the hackers find you, they will check your site every so often until they catch you slipping with an exploitable third-party infusion or something. Once they've found you, you can only hope they give up and forget about you after a while.

Secondly I would use an image button for your "Powered by" link, rather than searchable text. Thirdly, don't use the same password for your site admin, sql, and ftp accounts. Finally, don't use ANY third-party infusions.

If you run the core version and keep it updated you're pretty secure.
Edited by Raskolnikov on 26-04-2008 08:48,
0 replies
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
answered
Member

interesting post. can you explain why adding an image for the php-fusion link is more secure than searchable text?
0 replies
R
Raskolnikov
R
promote.opera.com/small/opera94x15.gif
  • Member, joined since
  • Contributed 71 posts on the community forums.
  • Started 8 threads in the forums
answered
Member

So they can't google your site using that keyword.
0 replies
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
answered
Member

oh lol my site isnt big enough to come up in a search for php-fusion
0 replies
H
HobbyMan
H
Just some Guy
  • Veteran Member, joined since
  • Contributed 1,486 posts on the community forums.
  • Started 91 threads in the forums
answered
Veteran Member

You should also upgrade to v 6.01.15
0 replies
M
MrSimple
M
Make it work... keep it simple...
  • Senior Member, joined since
  • Contributed 324 posts on the community forums.
  • Started 7 threads in the forums
answered
Senior Member

Quote

jak17 wrote:
if only it was written in english...


The site is in German, so i can understand it's confusing.
The infusion has English, Danish, Dutch and German locale files.
The online documentation is in German and English. link: http://docs.bs-fusion.de
0 replies
K
Ken
K
Ken 10
No Support by PM. Please use the forum.
  • Senior Member, joined since
  • Contributed 713 posts on the community forums.
  • Started 43 threads in the forums
answered
Senior Member

Here are a few things you can maybe consider:

First put on a little .htaccess code that only allows your IP-adress to access the /administration/ folder. If your IP adress is dynamic (changes from time to time) you can add a IP adress range.

Secondly add another .htaccess code adding a username/password on the /administration/ folder.

Keeping hackers out of this folder maybe helps a bit I think.
0 replies
J
jak17
J
jak17 10
  • Member, joined since
  • Contributed 155 posts on the community forums.
  • Started 46 threads in the forums
  • Started this discussions
answered
Member

can you provide me with these codes? if not on here by PM?

also, if i implement these codes will my other admins be able to login?
0 replies
K
Ken
K
Ken 10
No Support by PM. Please use the forum.
  • Senior Member, joined since
  • Contributed 713 posts on the community forums.
  • Started 43 threads in the forums
answered
Senior Member

.htaccess

Quote

order deny,allow
allow from xxx.xxx.xxx.xxx
allow from xxx.
deny from all
AuthName "Restricted Area"
AuthType Basic
AuthUserFile /usr/home/web/your-site-username/administration/.htpasswd
AuthGroupFile /dev/null
require valid-user

/usr/home/web/ = complete path to your site. It might be different from host to host.
xxx.xxx.xxx.xxx = your complete IP-adress (most secure)
xxx. = Allowing all IP-adresses starting with xxx. (but less secure)

.htpasswd

Quote

username:password

Password generator:
http://www.htaccesstools.com/htpasswd...generator/

If your site have several admins you need to give them the extra username/password and add their IP-adresses to the list to make them able to log into "Admin panel" (/administration/ folder).

Edit: Be aware that .htaccess coding might not work on all hosts.
Edited by Ken on 26-04-2008 13:24,
0 replies
H
Heavy mental
H
Hacked by RamiT ...
  • Junior Member, joined since
  • Contributed 13 posts on the community forums.
  • Started 1 thread in the forums
answered
Junior Member

on another website no securiti 100 %

securiti is 10 %

exploit hack 4ever ;)
0 replies

Labels

None yet

Statistics

  • Views 0 views
  • Posts 20 posts
  • Votes 0 votes
  • Topic users 7 members

0 participants

Notifications

Track thread

You are not receiving notifications from this thread.

Related Questions

Not yet