Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-21-2007, 02:50 AM   #1
Naughty
Confirmed User
 
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,482
Is your site/server hackersafe?

We certainly hope so.

Is there a tool that you can scan your servers with and see if you have holes in your security?
__________________
seks.ai for sale - ping me
Naughty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 03:05 AM   #2
TidalWave
Confirmed User
 
Industry Role:
Join Date: Sep 2007
Location: Los Angeles
Posts: 2,706
LOL... the only way to guarantee you wont be hacked is to pull your power cord from the wall. this has been proven many times.

apart from that, make sure you have recent offsite backups to restore from.
__________________
www.SwiftNode.com

Last edited by TidalWave; 10-21-2007 at 03:06 AM..
TidalWave is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 03:20 AM   #3
Naughty
Confirmed User
 
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,482
I agree. And how about checking admin sections? Forgotten closures in htaccess files etc.. Any way to test those?
__________________
seks.ai for sale - ping me
Naughty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 03:21 AM   #4
Naughty
Confirmed User
 
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,482
I'm thinking it should be easy to create though. Just a script that will scan all serverfiles/directories for easy access and print results.
__________________
seks.ai for sale - ping me
Naughty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 03:23 AM   #5
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
You can hire someone like me to make suggestions, which are ignored or overruled, and when someone gets through by some script written in New Delhi that uses unsanitized requests to include functions or unescaped SQL... well..

No, there is no tool; there was one 12 years ago, and it's been outdated since it's release. There's far too many things that can be done, can go wrong, or can be fucked with.
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 03:24 AM   #6
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
Quote:
Originally Posted by Naughty View Post
I'm thinking it should be easy to create though. Just a script that will scan all serverfiles/directories for easy access and print results.
Code:
find / -type f -exec echo {} "is probably not safe." \;
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 03:34 AM   #7
tomud
Confirmed User
 
Join Date: Jun 2002
Location: $$$
Posts: 7,993
Online port scanner :

http://www.t1shopper.com/tools/port-scanner/

Tomud
__________________


AFF – up to $1.50 per free join, $130 per order ! NASTYDOLLARS - 35$ PPS ! Free hosted galleries !
ADULTDATELINK$42 PPS, 50% REV ! DATINGGOLD - 100% !!! REV, $4 per email !
Adult Sponsors Reviews – take a look at the best adult programs !
Epassporte Sponsors

ICQ: 160168237
tomud is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 03:46 AM   #8
Naughty
Confirmed User
 
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,482
Quote:
Originally Posted by tomud View Post
This is just to see how you're doing on your own pc, right?
I'm talking about something that GrouchyAdmin is talking about.
__________________
seks.ai for sale - ping me
Naughty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 04:00 AM   #9
cem
Confirmed User
 
cem's Avatar
 
Join Date: Sep 2002
Posts: 415
Try checking your /tmp folder or you could scan your /cgi-bin/ folders for unknown files (e.g. shell.cgi or 101image.cgi) MANUALLY.

Here are a few points to consider for server security;

- Make sure you have the most recent software (e.g. web script software, apache, php, ftp etc. etc.)
- Use mod_security (apache mod) (it's actually more effective then you'd think)
- Use .htaccess IP restriction in admin folders (If you have a static IP)
- in php.ini = safe_mode on / register_globals off
- enable open_basedir (you know why)

None of my sites have been hacked (i have some since early 2000) and never seen ANY of my site passwords floating around, BECAUSE i am also managing my own servers and don't let any fool touch my servers.

If you need any help let me know.

Last edited by cem; 10-21-2007 at 04:02 AM..
cem is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 04:25 AM   #10
thonglife
So Fucking Banned
 
Join Date: Oct 2004
Location: Midwest, US
Posts: 1,566
You can use GFI's Languard to scan your server for common vulnerabilities and run Chkrootkit to scan your files to check CRC's. Anything is possible these days.. like someone else said.. the only safe server is one that's unplugged. I've had my server rooted only once.. but that was enough.. have had game servers installed, httpds compromised and a phishing site setup... sendmail hacked.. etc.. if these fucking people want to get in your machine and they are good they will.

Last edited by thonglife; 10-21-2007 at 04:27 AM..
thonglife is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 06:04 AM   #11
PussyTeenies
Confirmed User
 
Join Date: Feb 2005
Location: Haarlem and Amsterdam, capital of the porn world ;-)
Posts: 6,496
try

chkrootkit
and
rkhunter

those are fast server scanners to see if something is wrong

also learn to use lsof
__________________
Need adult hosting?

Contact us!
WARM Hosting

Need an IT solution? or someone to check your site and security? Nossie - IT Professional
PussyTeenies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 06:11 AM   #12
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Quote:
Originally Posted by cem View Post
None of my sites have been hacked (i have some since early 2000) and never seen ANY of my site passwords floating around, BECAUSE i am also managing my own servers and don't let any fool touch my servers.
The reason for that is because your sites are unpopular, not because you manage your servers.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 07:03 AM   #13
cem
Confirmed User
 
cem's Avatar
 
Join Date: Sep 2002
Posts: 415
Quote:
Originally Posted by ladida View Post
The reason for that is because your sites are unpopular, not because you manage your servers.
You dont even know which adult sites i own. I've been in the scene for a while, maybe even too long Don't let my sig fool you, this is just my latest attempt to try to get into the softcore scene.
cem is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2007, 07:09 AM   #14
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Then name them, but i'm 100% sure that if you were popular enough you'd be hacked several times by now, especially if you are that long on the scene since problems with security "back then" have been so abundant it's ridiculous.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.