Go Back   Webmaster Forums UK SEO SEM Webmaster Community Forum - UKWW > General > General Webmaster Talk > Running a forum
Register FAQ Members List Downloads Calendar Today's Posts Webmaster Resources Webmaster Blogs
 
 

Running a forum Information and resources for running a successful forum.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-02-2008, 04:53 AM
Meti's Avatar
Senior Member
 
Join Date: Mar 2007
Location: Sweden
Posts: 467
Default Securing a forum

Hey there,

Lets make this one of those long threads with useful information, shall we? Please share your security tips'n tricks below and I am sure that many forum owners will appreciate your tips.

Here are mine;

- You may wish to modify the adminCP/moderatorCP folders (this may require some modifications on the configuration settings)

- I often password protect directories that control the web site, for example the adminCP & moderatorCP are being password protected, and I provide each member a private user and password.

- Make sure your file permissions are set as low as possible, try to avoid having files CHMODDED at 777, doublecheck your configuration file so it has READ permissions only.

- Use a unique password for both your administrator user and don't ever use the same password for your webhost control panel as you do for your site.

- Change your password once in a while, and never assign a user full administration permissions (be careful with who you choose as staff).

- Make sure the forum platform is fully up to date, if there are any new versions the best way would be to upgrade asap, as there may be security fixes and further bug fixes released.

Share your own tips and tricks, and I am sure this will come to good use for all of us, remember, these are good tips although a very important factor is your web host, you should pick a reliable webhost.

- Meti
__________________
Computer Blogging - Gago Games
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 01-02-2008, 06:33 AM
temi's Avatar
Facilitator
 
Join Date: Jun 2003
Location: London, England.
Posts: 12,528
Send a message via ICQ to temi
Default

Meti,
Excellent tips, are you talking about all forums generally or one forum software specifically, some of your suggestion goes with any forum thanks that is good, here are a few tips from me.
- Do not give a member of your backroom staff more permission than they need.
- Always remove or down grade the account of a staff that left very very quickly
- Make your forum software force you and other important member of your staff to change their password regularly and they should not use the same password twice in a year.
- Backup your forum after making any important changes or hitting a posting landmark.
__________________

* Build a shopping cart for your business with eCommerce software UK
* BossCart.com can build you a.
Register your domain names at Velnet
::
Add Eco sites to The Green Directory free of charge.
Use LBS Free PHP Directory Script . Web Hosting Blog
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 01-02-2008, 06:36 PM
Meti's Avatar
Senior Member
 
Join Date: Mar 2007
Location: Sweden
Posts: 467
Default

Thanks for those excellent tips Temi, I am speaking of general security for any forum platform. You hit a very good point, make sure you do at least weekly backups in order to avoid any complications. Ask your web host regarding backups, most of them do daily/weekly backups.

Meti
__________________
Computer Blogging - Gago Games
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #4 (permalink)  
Old 01-02-2008, 08:58 PM
temi's Avatar
Facilitator
 
Join Date: Jun 2003
Location: London, England.
Posts: 12,528
Send a message via ICQ to temi
Default

Meti,
I think in addition to you hosts backup, its better if you do a database dump of your site. Hosts are usually not very fast when it comes to helping restore a site but if you have a backup on your PC you can have your forum back online within a few minutes of disaster happening of you have you own db dump on your PC
__________________

* Build a shopping cart for your business with eCommerce software UK
* BossCart.com can build you a.
Register your domain names at Velnet
::
Add Eco sites to The Green Directory free of charge.
Use LBS Free PHP Directory Script . Web Hosting Blog
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 01-03-2008, 05:04 AM
Meti's Avatar
Senior Member
 
Join Date: Mar 2007
Location: Sweden
Posts: 467
Default

Quote:
Originally Posted by temi View Post
Meti,
I think in addition to you hosts backup, its better if you do a database dump of your site. Hosts are usually not very fast when it comes to helping restore a site but if you have a backup on your PC you can have your forum back online within a few minutes of disaster happening of you have you own db dump on your PC
Agreed. I used to have an application that automatically connected with my mySQL server and backed up my databases, stored them at my own PC. However, I had that software on my previous machine, cannot seem to find it any more.

Meti
__________________
Computer Blogging - Gago Games
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 02-17-2008, 09:28 AM
Shadab's Avatar
Member
 
Join Date: Dec 2007
Location: Bhopal (India)
Posts: 80
Send a message via MSN to Shadab Send a message via Yahoo to Shadab
Default

Some more tips :

1. IP Protect your AdminCP directory.

Find out your IP address (or IP range, if you have a dynamic ip address), and then restrict access to your AdminCP directory for all IPs, except your own IP address; using an .htaccess file placed in your adminCP directory.

Example : If your IP range is 122.154.*.*
Then you can use this .htaccess code to restrict the access :
Code:
order deny,allow
deny from all
allow from 122.154.
2. IP Protect your hosting control panel

If your webhost allows it, you can also request your webhost to restrict cPanel access to everybody, except from your own IP address/range. This will make it even harder to break into your control panel. This way, even if somebody knows your pass, he won't be able to login as the IP won't match.
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #7 (permalink)  
Old 02-17-2008, 09:35 AM
temi's Avatar
Facilitator
 
Join Date: Jun 2003
Location: London, England.
Posts: 12,528
Send a message via ICQ to temi
Default

Nice tip shadab, rep added
__________________

* Build a shopping cart for your business with eCommerce software UK
* BossCart.com can build you a.
Register your domain names at Velnet
::
Add Eco sites to The Green Directory free of charge.
Use LBS Free PHP Directory Script . Web Hosting Blog
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 09-29-2008, 09:07 AM
GrAveTzT's Avatar
Junior Member
 
Join Date: Apr 2008
Posts: 13
Default

Excellent, I was messing around with this and couldn't believe how un-secure my forum actually was.

Great article.
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #9 (permalink)  
Old 11-07-2008, 10:31 AM
Member
 
Join Date: Nov 2008
Posts: 41
Default

Thank you for the nice tips.
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
  #10 (permalink)  
Old 11-13-2008, 04:43 AM
Junior Member
 
Join Date: Nov 2008
Location: Canada
Posts: 24
Default

I have noticed that in order to avoid unwanted posters posting bad things on your forums best to have your settings set so that any new members have to be approved by either the webmaster or the global moderator and this should discourage any trouble maker from trying to register only to do harm to your site!
Digg this Post!Add Post to del.icio.usStumble this Post!Wong this Post!
Reply With Quote
Reply

Bookmarks



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Webmaster Resources
 
The Forum Rules
Forum Rules - MUST READ
 
Site Of the Month
BizzFace
Nominate site of the month
 
Tag Cloud
affiliates b2b directory blogging money blogs business directory categories menu directories directory directory script e4 media group e4mediagroup.com ecommerce forum free submit godaddy godaddy codes godaddy coupon godaddy promo home user iphone 3gs justdial clone link pages menu paid directories right sidebar search engine script sell link sequence hosting submit site free web hosting website website hosting yellow

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 07:02 AM.

UK Webmaster World Forums - Internet marketing, web development, domain names, SEO contest and discussuons.
Subscribe to our feeds   Subscribe to our feeds

Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0