Trying to understand security. Help...

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Sal Collaziano
    Senior Member
    • May 2000
    • 922

    Trying to understand security. Help...

    Alright. My sites are being clobbered by hackers and whatnot.. I'm not saying they're getting in through vBulletin - but probably some other script. Still, I just can't be sure.. I'm weary of any world-writable directories (chmod 777). If I'm not mistaken, the "attachments" folder and "customavatars" folder needs to be set this way. Isn't it possible for anyone to come along and upload malicious scripts or rootkits to those folders? If not, how? How are they blocked from doing so?

    For now, I've turned off all attachment and avatar uploads on my forums. Is there any way around this besides storing everything in my database - which is already too large as it is? I want to be proactive rather than be reactive.. It seems the only way to be secure is to not allow any way for people to upload to my server...
    My vBulletin Forums:
    cadillac, buick, pontiac, oldsmobile, automotive, freestyle, 80s, lexus, bmw, mercedes, audi, toyota, honda, acura, nissan, infiniti, hyundai genesis, chevy

    ...can't fit any more...
  • eschaum
    Member
    • Apr 2003
    • 46

    #2
    Hey Sal, fancy meeting you here!

    Try putting those directories above your web root so that they can't be accessed by the public.

    Ed

    Comment

    • Sal Collaziano
      Senior Member
      • May 2000
      • 922

      #3
      Hi Eschaum! Is THAT it? That's the solution? So placing these directories before "public_html" would do the trick?
      My vBulletin Forums:
      cadillac, buick, pontiac, oldsmobile, automotive, freestyle, 80s, lexus, bmw, mercedes, audi, toyota, honda, acura, nissan, infiniti, hyundai genesis, chevy

      ...can't fit any more...

      Comment

      • eschaum
        Member
        • Apr 2003
        • 46

        #4
        That should do it. But before taking advice from someone like me, be sure to back everything up

        Comment

        widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
        Working...
        😀
        😂
        🥰
        😘
        🤢
        😎
        😞
        😡
        👍
        👎