SWF Forum Security

I think Edd can pre-approve new members so that may be the way forward if he has time, if not then a new Admin user might be the best way forward if Edd agrees.

It would be worth everyone updating their password details to make them more secure, i.e. by including numbers in various combinations etc.
 
I doubt very much he decided to do a scripted attack, but if he did he could have found out ALL users password from the database, but that depends on how the database is stored, encrypted ect.

Its more likely he just tried all mods accounts with simple passwords or tried a password attack on an account.

All IP addresses change unless you specify you want a static address from you IP provider, and until the new octets come out they wont do it as there is due to be a shortage.

Best way is to verify new members to the forum, maybe gather ebay ID, a photo (with them showing forum name on paper ect)

I thought the below was best

only allow new members to be added by invite only....so only current members can request new members to be added.
 
Finally made it in this morning and glad to see the forum hasn't been taken over again. :)

Here is my take on the security. I am by no means an expert, but have had to research this a bit as I mange a couple of servers with my job and also have my own personal server I take care of.

It sounds like he most likely got in with the weak password, however, I wouldn't rule out an exploit either. As far as passwords go the worst thing you can do is use a word on its own. It is very easy to do what is called a dictionary attack on a users password. This involves a program that will go through every word in the dictionary and attempt to login with all of those words. One way that you can get around this and still use a word would be to substitute numbers for letters, so if my password was starwars :) I could change it to 5tar5war5, but many know that users do that, so a better way would be to make it a little more random and use different cases throughout, so 5TaRwarS would be an even better substitute. Another good idea would be to add some other numbers or characters to the end, so 5TaRwarS-4826 or something along those lines. That way it is still a word or something that can be remembered, but requires a lot more work to figure out. Another way to go would be to use the first letters of a phrase mixed with numbers and letters, so say you want to use "May The Force Be With You", you could do MtFbwY and then mix in some numbers or characters, so M4t8F2b6wY! These obviously aren't as easy to type, but hopefully make it somewhat easier to remember. I hope someone at least finds this useful. :)

As far as the forum software goes it is always good to keep up to date. The software is free and open source which has advantages and disadvantages. The advantage is that if an exploit is found then anyone with some php knowledge can figure out a patch and submit the fix to the group that makes it. The fix would then come out very quickly. The disadvantage is that anyone can look at the source to find new exploits, so it is always a cat and mouse game. I learned this the hard way with some software I was using for a family site a few years ago. Now I always stay on top of the latest patches and haven't had any problems. I still have problems with spammers registering, so I made it that I had to approve them before they could do anything. Unfortunately, I now have to approve anyone that registers on my site, but in the long run it is worth it. If the forum goes this route then hopefully some of the other mods would be able to approve instead of just Edd. I have no idea what version of phpbb we are using. I found a few thing yesterday to try and find out, but luckily those didn't work. The only thing that makes me think it could be an older version is the 2007 copyright date at the bottom of the page and I know phpbb3 came out in 2009.

These exploits get out there and pretty much anyone that can figure out how to run a script can take advantage of it, so that is why it is important to stay up to date on the patches and such.

I hope this helps a bit. I know there are some other IT people who use the board, so any additions are welcome.
 
Hi guys,

apologies for what's happened. The fact is it's virtually impossible to ban somebody - most UK ISP's use dynamic IP addresses meaning that banning IPs is almost a waste of time, and if people are banned by email address they can simply use another. I cannot physically stop people that are banned signing up again.

My advice to everybody - change your password to something more secure, and ignore his trolling. He will go away if nobody responds.

I update the software regularly, as said if he has "hacked" anyone it's because he's guessed your password.

Cheers,
Edd
 
Dont forget you can complain to his ISP about his actions, they wont be happy knowing hes doing this kind of thing and may boot him off.

I would also suggest a private forum for members for conversations like this so.
 
Glad we have some knowledge on board with Shawn + Andy !

Can we at least force people into registering an account before reading the forum? At least then you can do as others have suggested and screen the people who try to register, might be a lot of work but its better than having it happen again.

Anyone who types this url in can read pretty much all of the forum :(

Perhaps create an actual front page, intro page with the forum being a link that then asks you to login or sign up to enter?
 
There's various reasons I don't want to "hide" the forum - mainly because if you have to register to read it, that means Google can't index it, so no new people will be able to find it.

I also don't want to add extra admins as that means they can do literally anything - delete the forum, delete me, change it to a star trek forum :lol: and that would be much more dangerous if somebody hacked into the account.
 
My bad I always say "Admin" when I should use the word "Mod"

A bigger Mod team then?
 
I'm happy to add any regular, well known members as mods if the other mods approve of them :)
 
edd_jedi said:
There's various reasons I don't want to "hide" the forum - mainly because if you have to register to read it, that means Google can't index it, so no new people will be able to find it.

I also don't want to add extra admins as that means they can do literally anything - delete the forum, delete me, change it to a star trek forum :lol: and that would be much more dangerous if somebody hacked into the account.

I understand exactly where your coming from there Edd i think Joe meant more MOD's ideally people who are trusted by the community, are actively collecting and who post / visit daily.

EDIT - i saw Joe had responded

Dam that Tri Luke Bespin MOC in your Avatar looks minty!
 
jaymassive619 said:
Dam that Tri Luke Bespin MOC in your Avatar looks minty!

I do miss my Luke Bespin focus, that's pretty much why I stopped collecting :(
 
We could do with another more active mod as a couple of us aren't here as much as we used to be (although I'll try and make an effort). Joe or Jay have been here a fair time now and are obvious candidates (if they want to do it). Anyone else?
 
Darth Wensleydale said:
We could do with another more active mod as a couple of us aren't here as much as we used to be (although I'll try and make an effort). Joe or Jay have been here a fair time now and are obvious candidates (if they want to do it). Anyone else?

Im happy to do it if its ok with the rest of the MOD's i wont speak for Joe apart from saying he is a sound guy who would be another good choice as well.

Jay
 
edd_jedi said:
jaymassive619 said:
Dam that Tri Luke Bespin MOC in your Avatar looks minty!

I do miss my Luke Bespin focus, that's pretty much why I stopped collecting :(

I can imagine Edd.

I just picked up the Meccano ROTJ Luke Bespin cardback off Uli (now my avatar)i would love to find it MOC someday and im still trying to find a Tri Logo Luke Bespin in decent condition.
 
Old Thread: Hello . There have been no replies in this thread for 365 days.
Content in this thread may no longer be relevant.
Perhaps it would be better to start a new thread instead.
Back
Top Bottom