You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 57 guest(s) and 2 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - This might seem kind of silly, but... [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
Thalgor
Nuke Soldier
Nuke Soldier


Joined: Feb 16, 2004
Posts: 10


PostPosted: Sun Sep 12, 2004 12:55 pm Reply with quoteBack to top

...I had a VERY hard time FINDING Admin Secure. Don't know if I completely overlooked something blaringly obvious or not Embarassed

First thing I did was search the downloads section and came up with nothing. Trolling every post I could for an hour in THIS forum turned up nothing. I finally searched the news and found an obscured link to version 1.3, then had to 'back up' the tree on that site to get any response Smile

Would it not be nice to post a sticky in this forum that has a link to the current version, or at least the downloads section of that board?
Find all posts by ThalgorView user's profileSend private message
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Sun Sep 12, 2004 2:22 pm Reply with quoteBack to top

Thalgor wrote:
Would it not be nice to post a sticky in this forum that has a link to the current version, or at least the downloads section of that board?

Well, thank you Thalgor for the idea. But I though the link was available in forum sub-title. Smile

Or click on my sig pic to go to AS project page at SourceForge.

_________________
I'm Image
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
JesseJames01
Lieutenant
Lieutenant


Joined: Jan 15, 2004
Posts: 164

Location: U.S.A

PostPosted: Sun Sep 12, 2004 3:37 pm Reply with quoteBack to top

What's he looking for , i'm confused...

_________________

http://flashlevel.com | http://ultrashock.com | http://billybussey.com
Find all posts by JesseJames01View user's profileSend private messageSend e-mailVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
Thalgor
Nuke Soldier
Nuke Soldier


Joined: Feb 16, 2004
Posts: 10


PostPosted: Sun Sep 12, 2004 4:52 pm Reply with quoteBack to top

Ah, okay...I see...

Usually when I see a link on a nickname, I always assume it's an email link. Wink

Guess what I'm saying is, for those of us not l33t enough or simply don't have the time to dig for the unobvious to search for links want something blaringly obvious like:

"Get the latest version of Admin Secure here."

Just a suggestion Smile
Find all posts by ThalgorView user's profileSend private message
JesseJames01
Lieutenant
Lieutenant


Joined: Jan 15, 2004
Posts: 164

Location: U.S.A

PostPosted: Mon Sep 13, 2004 1:52 pm Reply with quoteBack to top

Thalgor wrote:
Ah, okay...I see...

Usually when I see a link on a nickname, I always assume it's an email link. Wink

Guess what I'm saying is, for those of us not l33t enough or simply don't have the time to dig for the unobvious to search for links want something blaringly obvious like:

"Get the latest version of Admin Secure here."

Just a suggestion Smile
Good idea i just deleted my admin.php and links.editadmins.php files to prevent access for the hackers totally , this should work though right instead?

_________________

http://flashlevel.com | http://ultrashock.com | http://billybussey.com
Find all posts by JesseJames01View user's profileSend private messageSend e-mailVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Mon Sep 13, 2004 2:09 pm Reply with quoteBack to top

JesseJames01 wrote:
Good idea i just deleted my admin.php and links.editadmins.php files to prevent access for the hackers totally , this should work though right instead?

Not totally, if that was you though. Cookie stealing and XSS can do the job even if you delete admin.php and all contents on "admin/" directory. Oh man, c'mon this is something like destroying your own house to stay away from thiefs. Smile

btw; I think you're little bit misunderstood with all we have discussed here. Smile
"Admin Secure" forum does not meant to be discussing about "Securing PHP-Nuke Administration", but more about a security add-on for PHP-Nuke that called "Admin Secure". Very Happy

Admins already secured, 'coz they've equipped with nukes! Very Happy Mr. Green
Just kidding... Wink

_________________
I'm Image
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
JesseJames01
Lieutenant
Lieutenant


Joined: Jan 15, 2004
Posts: 164

Location: U.S.A

PostPosted: Tue Sep 14, 2004 4:25 am Reply with quoteBack to top

madman wrote:
JesseJames01 wrote:
Good idea i just deleted my admin.php and links.editadmins.php files to prevent access for the hackers totally , this should work though right instead?

Not totally, if that was you though. Cookie stealing and XSS can do the job even if you delete admin.php and all contents on "admin/" directory. Oh man, c'mon this is something like destroying your own house to stay away from thiefs. Smile

btw; I think you're little bit misunderstood with all we have discussed here. Smile
"Admin Secure" forum does not meant to be discussing about "Securing PHP-Nuke Administration", but more about a security add-on for PHP-Nuke that called "Admin Secure". Very Happy

Admins already secured, 'coz they've equipped with nukes! Very Happy Mr. Green
Just kidding... Wink
LOL , ok what should i do to prevent them from hitting my admin and gaining access to our admin panels and reaking havok on our sites and knocking them down , somehow also they've accessed our ftp's and deleting Rainbow Brite in them , and only way i can think of that is by getting access to our private messages we've sent our admins back and forth in our sites. I want this fixed , whats the best way to go about doing it , I'm at my wits end and deleting those files is the only way i stopped them. I mean look at this link from the hackers site for cripes sake:

http://www.majalehhack.com/modules.php?name=Forums&file=viewtopic&t=10&sid=6789c993b897fa4a92f1639c1


And thats hardly any of the sites that were hit , that's only the top 8 they wanted to hit first.

_________________

http://flashlevel.com | http://ultrashock.com | http://billybussey.com
Find all posts by JesseJames01View user's profileSend private messageSend e-mailVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Tue Sep 14, 2004 2:46 pm Reply with quoteBack to top

JesseJames01 wrote:
ok what should i do to prevent them from hitting my admin and gaining access to our admin panels and reaking havok on our sites and knocking them down ,

For the precaution, it advisable to applying security patches. These patches will close sanitize known insecure variables used on script files comes with PHP-Nuke standard packages. You can find these patches on most PHP-Nuke support sites, or visit the ChatServ's website ( http://nukeresources.com ). Nuke Security website ( http://nukesecurity.com ) also provides latest patches for various PHP-Nuke version. Hacker Assasins ( http://www.hackerassassins.com ) also provide pre-compiled PHP-Nuke that already modified with latest patches and some security addons included.

JesseJames01 wrote:
somehow also they've accessed our ftp's and deleting Rainbow Brite in them , and only way i can think of that is by getting access to our private messages we've sent our admins back and forth in our sites. I want this fixed , whats the best way to go about doing it , I'm at my wits end and deleting those files is the only way i stopped them. I mean look at this link from the hackers site for cripes sake

If someone can get your FTP account, it's serious. Consider to transfer your files using secure protocol (SFTP). FTP not quite secure because the password isn't encrypted whatsoever. Someone can also gather your FTP account by doing some XSS and trojan techniques. If your site allowing people to upload some kind of files, your site being vulnerable to such attacks.

_________________
I'm Image
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
JesseJames01
Lieutenant
Lieutenant


Joined: Jan 15, 2004
Posts: 164

Location: U.S.A

PostPosted: Tue Sep 14, 2004 3:36 pm Reply with quoteBack to top

madman wrote:
JesseJames01 wrote:
ok what should i do to prevent them from hitting my admin and gaining access to our admin panels and reaking havok on our sites and knocking them down ,

For the precaution, it advisable to applying security patches. These patches will close sanitize known insecure variables used on script files comes with PHP-Nuke standard packages. You can find these patches on most PHP-Nuke support sites, or visit the ChatServ's website ( http://nukeresources.com ). Nuke Security website ( http://nukesecurity.com ) also provides latest patches for various PHP-Nuke version. Hacker Assasins ( http://www.hackerassassins.com ) also provide pre-compiled PHP-Nuke that already modified with latest patches and some security addons included.

JesseJames01 wrote:
somehow also they've accessed our ftp's and deleting Rainbow Brite in them , and only way i can think of that is by getting access to our private messages we've sent our admins back and forth in our sites. I want this fixed , whats the best way to go about doing it , I'm at my wits end and deleting those files is the only way i stopped them. I mean look at this link from the hackers site for cripes sake

If someone can get your FTP account, it's serious. Consider to transfer your files using secure protocol (SFTP). FTP not quite secure because the password isn't encrypted whatsoever. Someone can also gather your FTP account by doing some XSS and trojan techniques. If your site allowing people to upload some kind of files, your site being vulnerable to such attacks.
Thank you very much madman , that was useful information , oh and i was looking through that site because i seen a new http referer from it and i guess they got a new list to hack today:

http://www.majalehhack.com/modules.php?name=Forums&file=viewtopic&p=56&sid=13bcdaf2f3741dbca71605737 and i guess they already hit some i see and took a couple down also if you go through the links.

dang bastards....

Again , Thanks a bunch MadMan , your the man!

Regards,

Travis Mattern

_________________

http://flashlevel.com | http://ultrashock.com | http://billybussey.com
Find all posts by JesseJames01View user's profileSend private messageSend e-mailVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.862 Seconds - 217 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::