You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 69 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Nuke Sentinel for PHPNuke 6.5 [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
joannal
Nuke Cadet
Nuke Cadet


Joined: Sep 08, 2008
Posts: 4


PostPosted: Mon Sep 08, 2008 9:01 am Reply with quoteBack to top

Hello!

I have gotten hacked about 2 times in the past year and thought I should do some security things to help. First of all I was wondering if anyone felt as though still having PHPNuke was OK security wise. For some reason my boss wants to stay on 6.5 because someone had told her that it wouldn't drastically change anything as far as looks. As far as security goes, I already altered my .htaccess file to prevent certain IPs but was looking to put Sentinel on. Does anyone know if there is a sentinel version for PHPnuke 6.5?

Many thanks!
Find all posts by joannalView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12397


PostPosted: Mon Sep 08, 2008 9:23 am Reply with quoteBack to top

By sticking with 6.5, you're pretty much opening yourself to every security vulnerable over the last several years. 6.5 was release more than 5 years ago. While she's right that the looks haven't changed, the code has changed quite a bit in order to make it more secure.

There isn't even a updated Patched release for 6.5, which Nuke Sentinel requires.

You should really get up to at least phpNuke 7.6 + Patched files + Nuke Sentinel. Or for a more integrated solution, I recommend RavenNuke from http://ravenphpscripts.com

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
joannal
Nuke Cadet
Nuke Cadet


Joined: Sep 08, 2008
Posts: 4


PostPosted: Mon Sep 08, 2008 1:45 pm Reply with quoteBack to top

Thanks for getting back to me Evaders99. I was looking at this website that compares the different types security: http://freesoftwarereviews.org/modules.php?name=News&file=article&sid=2

And it says that Nuke Sentinel can be used with 6.5 - I'm not sure what to believe. Do you know for sure that it doesn't work?

Thanks again Smile
Find all posts by joannalView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12397


PostPosted: Mon Sep 08, 2008 5:11 pm Reply with quoteBack to top

You "could" hack it up to work in 6.5, but even then, it wouldn't be the most secure version. Nuke Sentinel is not a complete solution in itself. It is a police officer - it can stop suspicious activity it knows about. But it doesn't mean you should leave your doors open: by not using patched, secure code!

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
joannal
Nuke Cadet
Nuke Cadet


Joined: Sep 08, 2008
Posts: 4


PostPosted: Mon Sep 08, 2008 6:29 pm Reply with quoteBack to top

Do you think that it's also the responsibility of the company that owns the server space to help with security avoid these hacks? What's your opinion on this?

Thanks again Smile
Find all posts by joannalView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12397


PostPosted: Mon Sep 08, 2008 7:22 pm Reply with quoteBack to top

Up to a certain point, yes. They can install some firewalls and lock down your account so that malicious scripts cannot get outside your server. But that's mostly to protect other users of their services.

To continue the analogy, the government provides deeds that says you control your own property. They have firefighters to stop the spread of fires to the community. It doesn't mean they can or should stop you from lighting a fire in your house: for a cookout or even a cigarette. However, you should have common sense to not leave lite candles around the house around flamable substances.

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
joannal
Nuke Cadet
Nuke Cadet


Joined: Sep 08, 2008
Posts: 4


PostPosted: Tue Sep 09, 2008 9:50 am Reply with quoteBack to top

Ok, I've finally been able to convince my boss to update to 8.1, but I see that 9.0 is supposed to be available soon. Do you have any idea how "soon" this will be? Maybe I should just stick to 8.1 considering there are probably many patches for that to help me out....

Thanks for your analogy on that Smile Those damn fires are so pesky.
Find all posts by joannalView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12397


PostPosted: Tue Sep 09, 2008 1:54 pm Reply with quoteBack to top

Really that's how all webhosts view it. If your site gets infected, its your job to remove it. All that is done with the software is your responsibility. Many hosts will terminate your account if it compromises their server.

There is no date on 9.0. Given that phpnuke.org is under new ownership and hasn't revealed themselves, I figure 9.0 is a bunch of talk. There is no release plan.

Use 8.1 (with the Patched files and Nuke Sentinel) and you'll be fine for a while.

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.206 Seconds - 283 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::