Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
Who's Online
2 registered (Thelockman, 1 invisible), 22 Guests and 21 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 06/07/06
Posts: 728
Top Posters (30 Days)
Ruben Rocha 177
Gizmo 110
Rick 109
Thelockman 80
driv 48
AllenAyres 35
Ian 33
ntdoc 27
Sirdude 23
Mark S 21
Latest Photos
My Home System
test photo gallery
Bernese Mountain Dogs
My Daimler
Dorado and shark
Topic Options
Rate This Topic
#216620 - 08/27/08 04:48 AM Protecting Board from hackers
duquesne Offline
stranger

Registered: 09/06/06
Posts: 12
I have a 7.3 board up and running for testing. There are no links to it on any web page yet someone was able to upload a bank phishing page to one of the board sub-directories. The installation specifies that some directories be writable to the world (777). Can I change these without compromising the function of the boards? How else can I protect myself?

Top
#216621 - 08/27/08 05:07 AM Re: Protecting Board from hackers [Re: duquesne]
Thelockman Online   crying
addict
****

Registered: 02/10/07
Posts: 438
Loc: Pennsylvania
The only way I know that someone can do that with the permissions set to 777 is that the server it self allows Anonymous log in to the server to the web site. If you have Anonymous users accessing your folders via FTP or Windows Explorer then you need to change your sites FTP settings to not allow any Anonymous logins to the server.
_________________________
Beagle World - A forum for those who are owned by beagles.
Track Thunder - The Unofficial Racing Forum

Top
#216622 - 08/27/08 05:34 AM Re: Protecting Board from hackers [Re: Thelockman]
Gizmo Moderator Offline

***

Registered: 06/04/06
Posts: 12002
Loc: Portland, OR; USA
Yeh, just because a FOLDER is chmodded 777 doesn't mean people can just randomy upload to it...

Likely, some script has been comprimised on your system and they just uploaded their stuff to that directory through the script that they exploited.
_________________________
UGN Security, Elite Web Gamers & VNC Web Design Owner
Longtime UBB Supporter, UBB7 Beta Tester & Resident Post-A-Holic

Top
#216627 - 08/27/08 05:50 PM Re: Protecting Board from hackers [Re: Gizmo]
duquesne Offline
stranger

Registered: 09/06/06
Posts: 12
Anonymous FTP is not enabled. Ubbthreads 6.5 is installed on the same system. Is there a script in 6.5 that can be compromised to upload stuff. I've found four directories with these phishing pages - two in the 6.5 directory hierarchy, one under the 7.3 directory and one outside these directories but in another directory with 777 permissions. All are owned by user apache. The only scripts are in the 6.5 and 7.3 directories, everything else is static HTML files.

Top
#216628 - 08/27/08 07:16 PM Re: Protecting Board from hackers [Re: duquesne]
Gizmo Moderator Offline

***

Registered: 06/04/06
Posts: 12002
Loc: Portland, OR; USA
I believe that an early 6.5 build had some security issues; so it could be that; you should at least upgrade to the latest 6.5 build (if not upgrade to UBB.T7)
_________________________
UGN Security, Elite Web Gamers & VNC Web Design Owner
Longtime UBB Supporter, UBB7 Beta Tester & Resident Post-A-Holic

Top


Moderator:  Gizmo 
Shout Box

Today's Birthdays
brushie, cass, Monte G., twebman, White Gold Wielder
Recent Topics
Font and column shifts occuring
by Bill B
Yesterday at 06:21 PM
changing colors in quoted thread box
by sbserves
Yesterday at 07:08 AM
[7.3.1] Image Not Found
by BellaOnline
11/29/08 09:48 PM
Private topic (PM) to a user that doesn't exist...
by bakerzdosen
11/29/08 10:56 AM
Forum Permissions - Can see forum
by Geoff
11/29/08 08:55 AM
Forum Stats
4261 Members
33 Forums
30528 Topics
154942 Posts

Max Online: 978 @ 06/24/07 08:19 PM