yup, this is an ad!
Napalm Riot Forums > Tech Talk > Help for my site

Help for my site

    Avatar
    Rank
    Recruit
    Creed
    Action
    Joined
    06.20.08

ɤSYST3M4T1C

Headshot Hero

Chillinvillain informed me that his old clan's site was hacked three times. I am making a clan site and want to prevent this from happening. Can anybody help me out?
06.20.08 2:21 am
    • Avatar
      Rank
      Sergeant
      Creed
      MMO
      Uber Subscriber Joined
      10.18.07

    ʊchillinvillain (#22521)

    Is In Your Base, Killing Your Pokemans

    It is indeed true, back in the day my clans site was hacked 3x and fully wiped 1x. Luckily we did have HD backups on a computer and were able to restore the frontpage, but our forums were lost as were all the pearl databases.

    It's a very taxing process having to deal with, and i was telling ɤsyst3m4t1c that we finally did get a guy who locked it down pretty tight, but i couldn't tell you for the life of me what exactly he was doing, so i thought someone might be able to help him out...


    (by the way, The Illuminati [Gaming Society], or tI/tIGS (we switched names on our 2nd year) was the clan, we started in Game: The Matrix Online so getting hacked was almost expected, it was like RP IRL lol.)
    ---
    "We aren't allowed to say brainstorm where I work because it's apparently offensive to people with cerebal palsy (bullshit)." --Chalkley3
    06.20.08 2:26 am
    • Avatar
      Rank
      Corporal
      Creed
      Action
      Uber Subscriber Joined
      11.07.07

    ʊchalkley3 (#22671)

    I go where I please, and I please where I go

    Erm... not use vulnerable board software etc. Be on the lookout for recent exploits, and do a little research into some of the hacking methods, as I doubt any of the "real" hackers could be bothered breaking into small clansites. They're most likely script kiddies, in which case the solutions are easy to put in practice. Password everything, make sure the power tools are available to the least amount and most trusted of people, and for gods sake, don't choose retarded mods or anyone likely to get phished.

    The only other things I can thing of are specific vulnerability like MySQL injection and XSS attacks, but I don't know anything about those.
    06.22.08 2:41 pm
    • Avatar
      Rank
      Recruit
      Creed
      Action
      Joined
      09.11.08

    ɤsofag (#24783)

    Stole Your Kill

    Was he using his own server or relying on another host?
    09.13.08 9:22 pm
    • Avatar
      Rank
      Specialist
      Creed
      Platformer
      Joined
      05.11.08

    ӝMiksago (#24829)

    I'm not a Geek, I'm a Computerist.

    basic rule I've always heard about this sorta stuff is:

    NEVER TRUST YOUR USERS.

    Simple as that. Strip the content of html tags, parse it, make it so it corrupt the database, etc.
    Link: http://www.addedbytes.com/php/writing-secure-php/
    ---
    Code is Art, I am a Code Monkey, therefore an Art-Monkey, but not an Artic Monkey.
    09.17.08 10:04 am