StarTrekGuide Downtime... hacked?

Latest News and Announcements.
Board Rules <-- Read here before posting.

Re: StarTrekGuide Downtime... hacked?

Postby Highway of Life » 13 Jan 2011, 20:18

King Rhyono wrote:
Obsidian wrote:Well, that kind of security (or rather, insecurity) is what you get when you buy shared hosting.


I agree. STG should pay $100/month for a dedicated server. :good:
You’re correct. We should.
We actually had a colocation server which was fantastic, but we had to give up the server due to the company we were leasing the server from. We are still at the same colo facility on another server, but unfortunately we are hosted with 190 other websites. This presents an obvious security vulnerability if one of the sites is compromised and the server does not have strong enough local directory protection. We are working with the host to improve their security as well as working on getting STG back onto it's own server.
Watch out! I might do a code wheelie!

User avatar
Highway of Life    
STG Jedi Master
STG Jedi Master
 
Posts: 10458
Joined: 08 May 2006, 05:23
Location: Beware of Programmers carrying screwdrivers
Gender: Male
phpBB Knowledge: 10




phpBB Academy at StarTrekGuide
Support STG
Using PayPal Donate

Re: StarTrekGuide Downtime... hacked?

Postby Obsidian » 13 Jan 2011, 22:02

Highway of Life wrote:
wired076 wrote:
Jaymie1989 wrote:Any chance the captcha could be changed? Its so hard to read.


I agree! It makes me feel like I am blind. :(

I have changed the CAPTCHA now to use reCAPTCHA. :)

Be warned, crack rate for recaptcha is getting mighty high for the latest xrumer release from what I've been seeing around the net.
うるさいうるさいうるさい!

StopForumSpam Spam Reporting Database
Giving xrumer and friends a great big "screw you" since 2007.
User avatar
Obsidian    
Supporter
Supporter
 
Posts: 2250
Joined: 04 Mar 2008, 23:35
Gender: Male
phpBB Knowledge: 10

Re: StarTrekGuide Downtime... hacked?

Postby Honor » 13 Jan 2011, 22:33

Sortables! I love mine!
BluePlanet RP
my own creation.

Host: Host Monster
Version: 3.0.9
Honor    
STG Moderator
STG Moderator
 
Posts: 328
Joined: 23 Dec 2010, 10:53
Gender: Female
phpBB Knowledge: 2

Re: StarTrekGuide Downtime... hacked?

Postby Highway of Life » 14 Jan 2011, 11:48

Obsidian wrote:Be warned, crack rate for recaptcha is getting mighty high for the latest xrumer release from what I've been seeing around the net.
I'd rather have no CAPTCHA than potentially lose users because they can't read it. At some point, it may become equal for CAPTCHAs. But I am NOT going to make it so difficult for people to crack CAPTCHAs that they can't login or register. I'd rather risk the bots. If CAPTCHA's become too difficult for humans to read, they become completely pointless.
We'll end up shifting to other ways of blocking bots, such as using StopForumSpam and catching spam posts.
Watch out! I might do a code wheelie!

User avatar
Highway of Life    
STG Jedi Master
STG Jedi Master
 
Posts: 10458
Joined: 08 May 2006, 05:23
Location: Beware of Programmers carrying screwdrivers
Gender: Male
phpBB Knowledge: 10

Re: StarTrekGuide Downtime... hacked?

Postby Unknown Bliss » 14 Jan 2011, 14:56

reCAPTCHA and Q&A CAPTCHA seem to have been failing alot more recently. Most people using CAPTCHA Plugins/Anti-Spam Modifications such as ACP Anti-Spam, Derky's Sortables Plugin, Peoplesign CAPTCHA Plugin are working well though.
Unknown Bliss    
Crewman
Crewman
 
Posts: 2
Joined: 13 Oct 2010, 16:04
Gender: Male
phpBB Knowledge: 9

Re: StarTrekGuide Downtime... hacked?

Postby Obsidian » 15 Jan 2011, 08:40

Yeah, Q&A is flawed from the beginning though. As soon as the answer can be googled, it's an open door.

@HoL: Same -- however I have been finding some success on my own server, by redirecting useragents with MSIE 6 or under in them to a subdomain.
http://ie6.ichimonai.com/

We gave up supporting IE6 and earlier (theme issues) -- so we blocked it. And with the faux-useragents that spambots like to run around under, the server ends up denying spam access to the bots quite often.
We've got ReCAPTCHA and post approval in place on top of that as well, and haven't gotten one to slip in spam publicly in months. They do register, but end up being silently banned in the end.
うるさいうるさいうるさい!

StopForumSpam Spam Reporting Database
Giving xrumer and friends a great big "screw you" since 2007.
User avatar
Obsidian    
Supporter
Supporter
 
Posts: 2250
Joined: 04 Mar 2008, 23:35
Gender: Male
phpBB Knowledge: 10

Re: StarTrekGuide Downtime... hacked?

Postby iKeirNez » 23 Jan 2011, 12:26

I am glad it is working now! At least it was just the index files! Why do people waste there time hacking? It will just be sorted withing a day! I am on a shared server too and never had this problem!
iKeirNez    
Cadet IV
Cadet IV
 
Posts: 43
Joined: 23 Jan 2011, 11:52
Gender: Male
phpBB Knowledge: 7

Re: StarTrekGuide Downtime... hacked?

Postby wadie » 04 Feb 2011, 07:15

Obsidian wrote:Well, that kind of security (or rather, insecurity) is what you get when you buy shared hosting.

There are actually many awesome companies that take security very seriously. If shared hosting was that easy breakable then I assume we wouldn't see many sites online.

You just get what you pay for!
PM me for private support or installing MODs/styles.
User avatar
wadie    
Lieutenant
Lieutenant
 
Posts: 329
Joined: 11 Mar 2010, 10:14
Gender: Male
phpBB Knowledge: 5

Re: StarTrekGuide Downtime... hacked?

Postby Obsidian » 05 Feb 2011, 10:32

wadie wrote:
Obsidian wrote:Well, that kind of security (or rather, insecurity) is what you get when you buy shared hosting.

There are actually many awesome companies that take security very seriously. If shared hosting was that easy breakable then I assume we wouldn't see many sites online.


I say this because shared hosting has inherent security risks that aren't present in other hosting methods (VPS, dedicated server, colocation).
Any large host running a shared hosting business is going to have more problems than any other method available, simply because there's many, many more things to keep track of when trying to maintain a secure environment; all it takes is one vulnerable application to expose an entire server (reference: PHPlist zero-day LFI exploit being used to break into the server for phpBB.com a few years ago).

You just see more sites online using shared hosting because it's much more affordable than the other methods.
うるさいうるさいうるさい!

StopForumSpam Spam Reporting Database
Giving xrumer and friends a great big "screw you" since 2007.
User avatar
Obsidian    
Supporter
Supporter
 
Posts: 2250
Joined: 04 Mar 2008, 23:35
Gender: Male
phpBB Knowledge: 10

Re: StarTrekGuide Downtime... hacked?

Postby wadie » 05 Feb 2011, 12:07

Affordable or not,if it was too easy to hack through any hosting company a lot of sites wouldn't be using it even if you pay as little as 1$ per year. lol
PM me for private support or installing MODs/styles.
User avatar
wadie    
Lieutenant
Lieutenant
 
Posts: 329
Joined: 11 Mar 2010, 10:14
Gender: Male
phpBB Knowledge: 5

PreviousNext

Return to News / Announcements

Who is online

Users browsing this forum: No registered users and 2 guests