Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-01-2008, 11:40 PM   #1
eMonk
Confirmed User
 
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
install mod_security on web server?

anyone recommend installing this module to increase server security? more info at http://www.modsecurity.org/projects/...che/index.html.

i'm just wondering if current scripts will still operate normally.
eMonk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-01-2008, 11:42 PM   #2
rhcp011235
Confirmed User
 
rhcp011235's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: North Carolina
Posts: 538
There's been multiple remote bugs in that module in the past as well as exploits in the wild. Its up to you if you want to try it I'd personally never run it.

Get your servers running some non-exec stack/heap patch. you should be good. And set basedir restrictions in php.
__________________
Skype rhcp011235 | Cell Phone 212.812.9043 | Email [email protected]
rhcp011235 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-01-2008, 11:43 PM   #3
yahoo-xxx-girls.com
Confirmed User
 
yahoo-xxx-girls.com's Avatar
 
Join Date: Jul 2006
Location: Canada
Posts: 3,143
If I were you I would contact that company directly.
__________________
sig too big
yahoo-xxx-girls.com is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 12:04 AM   #4
eMonk
Confirmed User
 
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
what about getting my host to upgrade the apache & php to the lastest versions on my box?

i've been attacked with some nasty trojans lately where the hacker uploads infected .php files on my box & alters my main index file + template files. right now the template files are chmodded to 444.
eMonk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 12:08 AM   #5
rhcp011235
Confirmed User
 
rhcp011235's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: North Carolina
Posts: 538
Yea, make sure to run apache 1.X not 2.X and upgrade to latest versions of all. Also, chances are the attacker is attacking 'your' scripts themselves not the server. Like the software you are running. no php/apache.
__________________
Skype rhcp011235 | Cell Phone 212.812.9043 | Email [email protected]
rhcp011235 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 12:13 AM   #6
eMonk
Confirmed User
 
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
yeah, there seems to be a hole in arrow traders traffic trading scripts, at3/atx, and they told me to hire a server security tech guy to inspect my box. this guy is infecting 100's of sites.

im just wondering what the server tech would do to increase security.
eMonk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 12:14 AM   #7
rhcp011235
Confirmed User
 
rhcp011235's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: North Carolina
Posts: 538
lol. You need someone to audit the traffic trading script. Many of them have holes. Such as UCJ ;) Most of them are encoded with zend or something. Some people know how to defeat this ;)
__________________
Skype rhcp011235 | Cell Phone 212.812.9043 | Email [email protected]
rhcp011235 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 12:18 AM   #8
eMonk
Confirmed User
 
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
that sucks man!

i even ip restricted all my scripts + ftp + ssh BUT this mofo can walk through walls, lol!
eMonk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 12:22 AM   #9
BigBen
Confirmed User
 
Join Date: Nov 2004
Location: scv
Posts: 2,299
Do you have Smart Thumbs installed?
BigBen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 12:27 AM   #10
eMonk
Confirmed User
 
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
Quote:
Originally Posted by BigBen View Post
Do you have Smart Thumbs installed?
no, tgpx but sites running st are also being infected with the same trojan.
eMonk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 05:17 AM   #11
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Quote:
Originally Posted by eMonk View Post
i even ip restricted all my scripts + ftp + ssh BUT this mofo can walk through walls, lol!
a) You haven't cleaned the box, he's got shells on it.
b) Scripts he's getting through are public reachable, they're most likelly not in your admin folder.

a) most likelly, as it's usually the case.

Mod security is nothing if you dont know how to configure it.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 05:28 AM   #12
HomerSimpson
Too lazy to set a custom title
 
HomerSimpson's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
It's piece of cake to install.
If you need this done hit me up.

here's a good tutorial on how to install it...
http://www.eth0.us/mod_security
__________________
Make a bank with Chaturbate - the best selling webcam program
Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!!

PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email:
HomerSimpson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 07:07 AM   #13
cem
Confirmed User
 
cem's Avatar
 
Join Date: Sep 2002
Posts: 415
Did you check your logs?
cem is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 11:22 AM   #14
2012
So Fucking What
 
2012's Avatar
 
Industry Role:
Join Date: Jul 2006
Posts: 17,189
:tongue

Quote:
Originally Posted by eMonk View Post
i'm just wondering if current scripts will still operate normally.
you have to test them based on the rules you have.

update everything to current versions. Use modsecurity 2

to start get some rules from here ... http://www.gotroot.com/tiki-index.ph...security+rules

.... other things that help out ...
Make sure your /usr/tmp directory isn't executable

set this to off in your php.ini ... you probably don't need it
allow_url_fopen = Off

ive been having some adventures lately with modsec if you want to hit me up I might be able to shed some light on something ..

goodluck
__________________
best host: Webair | best sponsor: Kink | best coder: 688218966 | Go Fuck Yourself
2012 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-02-2008, 11:39 AM   #15
2012
So Fucking What
 
2012's Avatar
 
Industry Role:
Join Date: Jul 2006
Posts: 17,189
Quote:
Originally Posted by fartfly View Post
.... other things that help out ...
Make sure your /usr/tmp directory isn't executable
or just the "tmp" dir ... /usr/tmp probably a simlink ti /var/tmp
__________________
best host: Webair | best sponsor: Kink | best coder: 688218966 | Go Fuck Yourself
2012 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.