![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#51 |
Old broad
Join Date: Oct 2002
Location: Away
Posts: 13,933
|
Hacker's fault.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#52 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
mount -o loop,noexec,nosuid,rw /dev/tmpMnt /tmp or something similar and have it constantly mounted with noexec from fstab.
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#53 | |
Confirmed User
Industry Role:
Join Date: Dec 2004
Location: Montreal, Canada
Posts: 3,271
|
Quote:
__________________
264 349 400 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#54 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
Like scannerX said - there is not a single server out there that is unhackable. The only ones which are unhackable afrom external sources re the ones unplugged from the internet.
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#55 | |
Marketing & Strategy
Industry Role:
Join Date: Jun 2001
Location: Former nomad
Posts: 14,293
|
Quote:
__________________
Whitehat is for chumps If you don't do it, somebody else will - true story!
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#56 |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
I've written a few HOWTOs over at SplitInfinity on a few "absolute musts" to securing your server....
nothing there on firewalls, since everyone has their own flavour (you are running a firewall aren't you?) http://forums.splitinfinity.com/forumdisplay.php?f=7 Even if your server is managed, have a looksie at the HowTo's and if there something in them that isn't implemented, ask your managed provider to get it sorted. This list is non-exhaustive and I'll be adding to the HowTo's, esp for security as and when, so check there regularly. Any questions, post in the forum, or hit me up on ICQ. I also do one-off hardening configs for $100 -if interested hit me up (this includes much more extensive hardening than those HowTo's, but over time, I'll be posting pretty much all the HowTo's so you can do it yourself if you're savvy enough!)
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#57 | |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
There's so much more then what you wrote there.
Quote:
That's all? I can think of at least 5 more commands that would upload things, plus some 10 more ways to add it without uploading...
__________________
agentGFY *at* gmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#58 | |
Too lazy to set a custom title
Industry Role:
Join Date: May 2003
Location: icq: 71462500 Skype: Jupzchris
Posts: 27,880
|
Quote:
thanks for bumping this now i am going to get 100 more icq from hosting companys wanting to sell me shit fuck.
__________________
[email protected] |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#59 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
![]()
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#60 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
Adult websites are the most targetted sector. This was just a start to get a comprehensive security list together to help others. So, hey, do us all a favour and add things to the threads I created ![]()
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#61 |
Confirmed User
Industry Role:
Join Date: Jul 2006
Location: los angeles
Posts: 825
|
i'm actually responsible, i'll try not to let it happen again.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#62 |
Now choke yourself!
Industry Role:
Join Date: Apr 2006
Posts: 12,085
|
It depends to your level of management, but really, it's usually not directly applicable to the host.
For instance, if you are paying for a colocated server - most sites will install the basic OS, give you your IP list, and your root password. From there, it's all yours. However, if you are paying for a managed host, you really need to see what their level of support is. Most 'managed' will monitor HTTP and do basic support, but not that many offer upgrades or updates beyond your initial install - some of them aren't even aware that they should update the OS, being that DirectAdmin/CPanel have the ability to update their specific Apache 1.3/PHP/etc support tools. The closest experience to a fully managed system I've actually had was through a non-adult service, ICDSoft. They actually scanned all clients, and alerted those with phpBB2 to ensure they ran updates. It was surprising, being how cheap their services were. However, they DO NOT do adult, and I don't believe that they offer anything other than shared accounts at this time. Sorry to hear you got hacked. It'd be interesting to know how they got in.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#63 | |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Quote:
__________________
agentGFY *at* gmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#64 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
rcp, lynx, links, scp, nc, elinks, proxy, vbox, lwp, GET will all be added to the HowTO in due time. It's not a half-assed job. It's work in progress, fuckwit. Now, if you want to help others to help themsleves, add to the thread goddammit. 99% of the peopel who have servers here wouldn't know what to do. It's not easy putting up easy-to-follow instructions. So I did the basics and will update as and when I have the time.
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#65 |
Registered User
Join Date: Jan 2006
Posts: 44
|
it s the scripts fault
|
![]() |
![]() ![]() ![]() ![]() ![]() |