Title: SECURITY- READ NOW!
Frontier Lord Liam - September 13, 2005 09:17 AM (GMT)
OK, this board has been hacked twice now. We can't let this happen again. My suggestions are
1) Staff and above are required to have paaswords being words that contain more than just letters. I remember, when I was first an admin, the passwords for the staff forums were "onlymods" and "onlyadmins." Passwords like that can't be accepted for anyone who has access to the ACP.
2) Merge Co-Owner and Owner. Of course, ~FL~ will still be top dog, but this gives us Co-Owners the ability to view over Admin Logs, to help prevent hackers slowly aining entry. I think it would also stop us from being deleted.
3) Require Email Validation, for membership. This will ensure that we have their email address.
4) Take any threat to anyone here seriously with an IP, email and name ban. (Especially Staff and higher)
5) Make sure nobody uses chatspeak or 1337speak. Both of these can hide the writing style of a hacker.
6) Investigate if you have suspision that ANYONE might hack the board.
These are my ideas. What do you guys think?
Firebird306 - September 13, 2005 09:23 AM (GMT)
If we have Email Validation, then...
Frontier Lord Liam - September 13, 2005 09:23 AM (GMT)
Firebird306 - September 13, 2005 09:31 AM (GMT)
Think about it. Email, Check, Disapprove?
mewlover - September 13, 2005 05:44 PM (GMT)
have one that is 20 charceters that may help or make a comusing 1 example:a66f9nnna2
Frontier Lord Liam - September 14, 2005 03:55 AM (GMT)
FB, they validate their own email. Currently IF doesn't offer double validation.
Also, make sure you have a secure Email account. That's like your life online.
Firebird306 - September 14, 2005 06:12 AM (GMT)
Oh, nevermind about that theory. And yes, if your Email Address is messed with your entire online life and possibly your computer will be screwed.
Frontier Lord Liam - September 15, 2005 03:48 AM (GMT)
I suppose Admin Validation may be better than Email validation in tis case.
Firebird306 - September 15, 2005 06:05 AM (GMT)
Bulbasaur - September 15, 2005 08:13 PM (GMT)
| QUOTE (Frontier Lord Liam @ Sep 13 2005, 04:17 AM) |
OK, this board has been hacked twice now. We can't let this happen again. My suggestions are
1) Staff and above are required to have paaswords being words that contain more than just letters. I remember, when I was first an admin, the passwords for the staff forums were "onlymods" and "onlyadmins." Passwords like that can't be accepted for anyone who has access to the ACP.
2) Merge Co-Owner and Owner. Of course, ~FL~ will still be top dog, but this gives us Co-Owners the ability to view over Admin Logs, to help prevent hackers slowly aining entry. I think it would also stop us from being deleted.
3) Require Email Validation, for membership. This will ensure that we have their email address.
4) Take any threat to anyone here seriously with an IP, email and name ban. (Especially Staff and higher)
5) Make sure nobody uses chatspeak or 1337speak. Both of these can hide the writing style of a hacker.
6) Investigate if you have suspision that ANYONE might hack the board.
These are my ideas. What do you guys think? |
IP Bans don't work at all.As long as you have firefox, you can always change. And the Admin log thing is good (merge of two groups).
Admin Validation > E-Mail Validation
Also allow only one E-Mail so double accounts don't work.
I'll be learning how to hack soon, so I might be able to revenge-hack soon.
Firebird306 - September 15, 2005 08:17 PM (GMT)
Frontier Lord Liam - September 17, 2005 12:12 AM (GMT)
@Bulbasaur:
I did say admin validation would be better a few posts ago. Also, are
you cracking them back is legal? XD! Also, waita tell the novice crackers who
don't know that about IP Bans ;/ And wasn't the multiple email rule
already in place? o_O Or is there a way to change that in the ACP?
Bulbasaur - September 22, 2005 12:41 AM (GMT)
The novice hackers are only trolls or n00bs.They don't even klnow how to change it.There is a way to ban that though.
AcCiDeNT - September 26, 2005 05:07 AM (GMT)
First, you can't say that you're going to learn to hack soon... It may never happen it takes time to learn to hack, and as for the writing, it doesn't matter how they write they can write like this "7h1$ pl@c3 1$ l33t!" and it not be a hacker... For the email think, yeah that'd be good... Also merging the groups, the hackers that hacked were n00bs they didn't know what they were doing... And we can't find them by IP, they probably used an Proxy server or some other cover for their I.P. so I wouldn't count on that...