Go to Post In theory, this should work... Oops. - Eldarion [more]
Home
Go Back   Chief Delphi > Technical > IT / Communications > Website Design/Showcase
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
 
 
Thread Tools Rate Thread Display Modes
Prev Previous Post   Next Post Next
  #10   Spotlight this post!  
Unread 14-06-2007, 01:58
artdutra04's Avatar
artdutra04 artdutra04 is offline
VEX Robotics Engineer
AKA: Arthur Dutra IV; NERD #18
FRC #0148 (Robowranglers)
Team Role: Engineer
 
Join Date: Mar 2005
Rookie Year: 2002
Location: Greenville, TX
Posts: 3,078
artdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond repute
Re: Website Hacking Problems

Quote:
Originally Posted by yodameister View Post
For now we are disabling all forums, blogs, picture uploading capacity, etc. We hope that this will clear up the problem (for now).
That won't totally solve the problem, as disabling the photo galleries and forums will only continue to hide the underlying security loophole.

Check your access logs, and see if you can find anything there.

Check the file/folder permissions of the root directory. If it's are listed as 777, this is a security problem. Change (chmod) them to 770 or 755. You can create subfolders with a chmod setting of 777, but only do so where your scripts actually need file creation/deletion/alteration permissions. If all you have in a directory is static HTML files that you alter via FTP, lock down the file permissions for that directory.

If users can upload files through a script, make sure the script is doing proper checks of the file to verify the contents. Check PHPbb or your photo gallery websites for any plug-ins that provide extra security in this department.

Check to make sure there aren't any additional user accounts with administrator privileges. If the hacker found his way into your website, he could have also gained access to your Control Panel, where he could have created a back-door FTP user account with a separate username and password.

I'd suspect that there is some sort of backdoor entrance somewhere (perhaps one exploited by a security loophole in your scripts), especially since you said changing passwords didn't solve the problem. Check everything. FTP. Forums. etc.

And last, but not least, make sure your passwords are secure. Don't pick obvious things. Use lots of 'weird' things like l0w3rcaS3 & uPpeRca5e letters, along with 5pEC!aL cHaR|\CT3r5. Make long passwords. Don't ever store your password anywhere except your head.
__________________
Art Dutra IV
Robotics Engineer, VEX Robotics, Inc., a subsidiary of Innovation First International (IFI)
Robowranglers Team 148 | GUS Robotics Team 228 (Alumni) | Rho Beta Epsilon (Alumni) | @arthurdutra

世上无难事,只怕有心人.
 


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HELP! Website hosting problems. Tottanka Website Design/Showcase 27 04-02-2007 22:28
263's Computer Hacking Competition SeanCassidy Chit-Chat 31 29-09-2005 15:11
Using non joystick controls with Operator Interface (Hacking Various Controllers) Astronouth7303 Control System 58 02-02-2005 15:56
Talk about the 'hacking' here. Brandon Martus Chit-Chat 12 08-07-2003 15:53
Hacking The Segway MattK Dean Kamen's Inventions 16 31-07-2002 20:51


All times are GMT -5. The time now is 16:11.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi