'Copyright'

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • derfy
    Senior Member
    • Jul 2005
    • 244
    • 3.8.x

    #16
    Originally posted by Cromulent
    Have an .htaccess file password protect the AdminCP and ModCP. That sorts that problem out.
    Rename them, also. I think that's the best you can do.

    Comment

    • Floris
      Senior Member
      • Dec 2001
      • 37767

      #17
      Yep, I don't mind the copyright at all, but I do like to keep things clean and I also remove the <br /> so everything is on one line.

      Comment

      • JakeS
        Senior Member
        • Jul 2005
        • 1975

        #18
        Originally posted by Cromulent
        The point is if you remove the version number you also remove a (very small) security risk that someone will visit your forum and see that you are running an out of date version and then decide on the off chance to hack you.

        It still requires you to keep up to date, but makes it that little bit harder to find what version you are running. Whether or not it makes much of a difference is not really the point. Why have a sign on your front door saying your out for the day when you could just leave the house without anything on it at all.
        removing version number just makes us wonder what version your using say like one of us couldn't hack 'the latest' and you have an older version, we would be able to say look at that i can hack that version so removing version number can help slightly.

        Comment

        • Floris
          Senior Member
          • Dec 2001
          • 37767

          #19
          And hackers can still go to modcp/ to find the version number or open one of the .js files.

          Comment

          • JakeS
            Senior Member
            • Jul 2005
            • 1975

            #20
            also gives makes them wonder what version your using so they hack you to find out, but you could go to modcp etc but, if you .htaccess protect it its still easy because then they just find the .htpsswd file and decript the password .

            Comment

            • Floris
              Senior Member
              • Dec 2001
              • 37767

              #21
              I highly doubt they can just download the .htaccess and .htpasswd file. Especially the latter is a file you don't have to save in the same dir but somewhere outside the public html directory.

              Adding .htaccess to your modcp/ and admincp/ and removing the install/ directory is a good additional security layer.

              Comment

              • JakeS
                Senior Member
                • Jul 2005
                • 1975

                #22
                Indeed, but being a white hat hacker (dont do any damage) its still pretty easy to get to those files.

                Comment

                • Icheb
                  Senior Member
                  • Nov 2002
                  • 1291

                  #23
                  Originally posted by ~Biker~
                  also gives makes them wonder what version your using so they hack you to find out, but you could go to modcp etc but, if you .htaccess protect it its still easy because then they just find the .htpsswd file and decript the password .
                  You can't download .ht* files in the first place. And even if you could, you can't "decode" password hashes. But please, go ahead and hack those sites if it's so easy.

                  Comment

                  • JakeS
                    Senior Member
                    • Jul 2005
                    • 1975

                    #24
                    Originally posted by Icheb
                    You can't download .ht* files in the first place. And even if you could, you can't "decode" password hashes. But please, go ahead and hack those sites if it's so easy.
                    don't ask me to hack sites because when people ask me to hack something i hack them instead.

                    Comment

                    • Icheb
                      Senior Member
                      • Nov 2002
                      • 1291

                      #25
                      First of all, it was sarcasm. And if you are such a great hacker that you hack sites all the time, you should know that you can't download .ht* files.
                      Btw, you should do something about your ego problems.

                      Comment

                      • JakeS
                        Senior Member
                        • Jul 2005
                        • 1975

                        #26
                        I Never said download them.

                        i said view them.

                        ie in there cpanel etc.

                        and i never said i hack all the time.

                        Comment

                        • Icheb
                          Senior Member
                          • Nov 2002
                          • 1291

                          #27
                          Why do you need to view the .htaccess file and "decode" the passwords to that account if you already have access to cpanel?

                          Comment

                          • melefire
                            New Member
                            • Jan 2006
                            • 17

                            #28
                            Originally posted by Icheb
                            Why do you need to view the .htaccess file and "decode" the passwords to that account if you already have access to cpanel?
                            Agree, if you want to destroy there site and you have accses to there cPanel why not just delete there database?

                            And ~Biker~, hacking is not nice!!
                            http://www.vbulletin.com/forum/custo...ic109960_1.gif
                            An awsome internet/computers community!

                            Comment

                            • JakeS
                              Senior Member
                              • Jul 2005
                              • 1975

                              #29
                              When you go to cpanel you click cancel on the .htaccess one, and then takes you to the login error page which has a login part so you just crack that haha

                              you view htaccess to find out where .htpsswd is ie it would be like this most of the time

                              AuthGroupFile /dev/null
                              AuthName "Admin's Only"
                              AuthType Basic
                              AuthUserFile /home/*****/*******/*******/.htpasswd/******/******/.htpasswd
                              require valid-user

                              Comment

                              • JakeS
                                Senior Member
                                • Jul 2005
                                • 1975

                                #30
                                Originally posted by melefire
                                Agree, if you want to destroy there site and you have accses to there cPanel why not just delete there database?

                                And ~Biker~, hacking is not nice!!
                                Because A , thats not my catagory, and B its to easy that way.

                                Comment

                                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                                Working...