A good way to keep PHPBB3 boards safe from hackers?

Make sure other forums are hacked. I understand that if a hacker is detected, they will find a way, but what actions can you take to try to ensure, where possible, that this will not happen?

+3
source share
2 answers

There will be another vulnerability in PHPBB3 and you will be hacked. Try updating PHPBB3. I know that Simple Machines Forums is much safer because I manually checked both of them.

1) Undoubtedly, the most important thing you can do to make any web application more secure is to use a web application firewall, such as Mod_Security .

2) Make sure you are using a modern Linux distribution that uses simple SELinux or AppArmor, SELinux is more secure. DO NOT USE WINDOWS.

3) , mysql PHPBB3 NOTHING ELSE. , PHPBB3 mysql.user! " " - , -. , "grant", sql : ' union select '<?php eval($_GET[e])?>' into outfile "/var/www/backdoor.php"--, , "grant" , "" mysql_query() SQL-.

4) Firewall off port 3306 mysql. , , .

5) PHPSecInfo , "" .

6) OpenVAS , , , , .

+5

, 100% , , , , .

  • root,
  • ,
  • captcha ,
  • ,
  • HTML .
+2

Source: https://habr.com/ru/post/1737998/


All Articles