[Article] Top tips for protecting your forum

spyka

Paragon
Joined
Sep 3, 2007
Messages
1,870
Reaction score
1
FP$
2,521
Top tips for protecting your forum
Creating and maintaining a community can be a full time job – and there is nothing worse to see it all go down the toilet because of poor security. There are a number of things you can do to protect your forum and improve security on your forum.

These tips apply to all forums regardless of the software you’re using. Do remember that although these tips will improve the security of your forum and stop some attacks they do not guarantee your forum is 100% safe and nothing will ever be able to do that. However following these tips will help you deal with attacks and make sure you lose as little as possible.


Keep your software up to date
This one is really a no brainer – when the software you’re running requires an update – update it! If you’re running your own forum software then be sure to block any security holes you find as soon as you can. No one is a perfect programmer and software will have holes. The good thing is that any good company will release a fix to them as soon as possible so be sure to make best use of their quick response and update as soon as you can.

It may also be a good idea to remove the version of the software you are running. When software exploits are published hackers can search for vulnerable forums by searching for the version number in a search engine. Learn how to remove the version number in vBulletin.
Mailing lists

Be sure to sign up to a mailing list which will provide you with updates and notices as soon as they are released, a few helpful links:

* MyBB Mailing list
* SMF forum – from here you can sign up and request important announcements be sent by email.
* vBulletin and Invision Power Board users should be sent email updates automatically to the email associated with your license.

Continue reading
 
Cheers for posting this, its a really good write up and i didnt give it much thought about security but i certianly will do so know.
 
Security should be important to every forum or website owner although alot of people don't care and think "It will never happen to me". But it does happen.
 
Re:

Fowler said:
Security should be important to every forum or website owner although alot of people don't care and think "It will never happen to me". But it does happen.
I'll second that. I know first hand how easy it is to use Google Dorks to find exploitable scripts. Removing version numbers is a must.
 
People believe that security through obscurity isn't security at all. I believe it is... Anything that might help, does help. There's also no harm in trying.
 
Back
Top Bottom