Register for your free account! | Forgot your password?

You last visited: Today at 19:30

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



about website security

Discussion on about website security within the SRO Private Server forum part of the Silkroad Online category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Sep 2012
Posts: 116
Received Thanks: 64
about website security

hello guys, i'm here to talk about websites security you know there is kids have a small hack program can close / open the website and really i got bored from this, but i dun know how to security the website well so i just requesting from any pro coder or anyone who can help me in this and sorry for this strange thread thank you.
Spider* is offline  
Old 09/17/2012, 15:58   #2

 
鳳凰城's Avatar
 
elite*gold: 273
Join Date: Aug 2012
Posts: 4,451
Received Thanks: 2,428
IIS

鳳凰城 is offline  
Old 09/17/2012, 16:42   #3
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,310
Received Thanks: 6,470
Quote:
Originally Posted by Spider* View Post
hello guys, i'm here to talk about websites security you know there is kids have a small hack program can close / open the website and really i got bored from this, but i dun know how to security the website well so i just requesting from any pro coder or anyone who can help me in this and sorry for this strange thread thank you.
cherno's exploit pack(look on release section) f*** up if IIS is open(ports)
as for a website, is just matter of injections
PortalDark is offline  
Old 09/17/2012, 16:45   #4
 
LastThief*'s Avatar
 
elite*gold: 60
Join Date: Feb 2012
Posts: 3,942
Received Thanks: 6,475
@Portal

Who have told you those things ?

Overlimit is hosted on iis port 80 and no one can harm it the only thing could get you ****** is opening billing port
LastThief* is offline  
Old 09/17/2012, 16:54   #5
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,310
Received Thanks: 6,470
Quote:
Originally Posted by LastThief* View Post
@Portal

Who have told you those things ?

Overlimit is hosted on iis port 80 and no one can harm it the only thing could get you ****** is opening billing port
i meant without any kind of security
if you get the default IIS files and not protecting it(75% of noob servers)
but is an example as he asked about a website security
since all websites are made on php, i can only think on injections(maybe some engine flaws but not sure about his one)
PortalDark is offline  
Old 09/17/2012, 16:59   #6
 
LastThief*'s Avatar
 
elite*gold: 60
Join Date: Feb 2012
Posts: 3,942
Received Thanks: 6,475
Quote:
Originally Posted by PortalDark View Post
i meant without any kind of security
if you get the default IIS files and not protecting it(75% of noob servers)
but is an example as he asked about a website security
since all websites are made on php, i can only think on injections(maybe some engine flaws but not sure about his one)
There are scripts which can crash appserv in less than second not only injections
LastThief* is offline  
Thanks
2 Users
Old 09/17/2012, 17:01   #7

 
鳳凰城's Avatar
 
elite*gold: 273
Join Date: Aug 2012
Posts: 4,451
Received Thanks: 2,428
Quote:
Originally Posted by PortalDark View Post
cherno's exploit pack(look on release section) f*** up if IIS is open(ports)
as for a website, is just matter of injections
Portal , You're my friend but , check your words before saying. SPRUT could make the job done.
Quote:
Originally Posted by LastThief* View Post
There are scripts which can crash appserv in less than second not only injections
鳳凰城 is offline  
Old 09/17/2012, 17:06   #8
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,310
Received Thanks: 6,470
im not that "skilled" on any kind of hacking ways(only windows password hack XD) so i dont really know much on how the IIS exploit works
PortalDark is offline  
Old 09/17/2012, 17:10   #9

 
鳳凰城's Avatar
 
elite*gold: 273
Join Date: Aug 2012
Posts: 4,451
Received Thanks: 2,428
Quote:
Originally Posted by PortalDark View Post
im not that "skilled" on any kind of hacking ways(only windows password hack XD) so i dont really know much on how the IIS exploit works
Let me explain it to you

You run your website (HTML-PHP-****)
Appserver host it after you set the settings as should be
OMQ YOUR WEBSITE IS WORKING W-O PROBLEM
I(Hacker) Wanna down your website ,
I get your website IP by using ping yourwebsitedomain.com -t
I run the script , Write your IP
1 missing part , check your website port.
Portchecker ftw
I now get your port which you've hosted the website on.
I write the port and running the threads (200~5m thread)
Start it
less than min. your website is down
You:Omg what should I do
You:Let me run appserver again
You:You run , get instant crash =))
Even you have firewall , not all firewalls are good.
The script crashes appserver due the too-much load on it
Solution: IIS. (Wont explain because idiots will fix their websites)

Any missing part you didnt got it?
鳳凰城 is offline  
Thanks
2 Users
Old 09/20/2012, 21:01   #10
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,310
Received Thanks: 6,470
#cleaned
if you are gonna give suggestions, do it, this is not a "I'm better than you" threads
PortalDark is offline  
Thanks
1 User
Old 09/20/2012, 21:32   #11
 
Mykha*'s Avatar
 
elite*gold: 275
Join Date: May 2008
Posts: 300
Received Thanks: 215
Quote:
Originally Posted by Spider* View Post
hello guys, i'm here to talk about websites security you know there is kids have a small hack program can close / open the website and really i got bored from this, but i dun know how to security the website well so i just requesting from any pro coder or anyone who can help me in this and sorry for this strange thread thank you.
Your post doesn't specify any specific problem but in general.
Specify whether you want to protect your sites against flood attacks and such...
Either against vulnerabilities/SQLi and all other attacks that could lead to several things ranging from stealing users data and such to injecting shells.

So that i could help you further.
Mykha* is offline  
Reply


Similar Threads Similar Threads
[Help] SQL security & website php scripts
08/30/2013 - Shaiya Private Server - 8 Replies
Hello all, i've run into a bit of a snag and was hoping the good people here on epvp could give me a clue... I've searched for this but unable to find anything clear. For security in my SQL Server Configuration Manager under TCP/IP I've disabled external IP's from accessing the database, (Listen all = no, All IPs other than 127.0.0.1 switched to no) Problem is, the scripts on my website such as registration, online players etc can't communicate with the DB either, which some are prudent to...
[Website] PHP Ideas: Javascript and Security (XSS Attacks)
07/04/2012 - Web Development - 5 Replies
Hello again, E*PVP! Here's my second PHP (hopefully helpful) post. This one is around the concept of an XSS attack. Let me define it first: An XSS attack is when a user is capable of entering html code and then whatever webpage it is on will then process the code. Example of a normal user: > Register Form > User enters information
[Website] PHP Ideas: Cookies and Security Checks
07/04/2012 - Web Development - 3 Replies
Hello, E*PVP community! I hopefully have a relatively useful PHP guide/release for you here today. After all the PHP I've done with websites over the last couple of years, I've never really learned more than I have on the last project I had begun working on, which was a PHP, tick-based MMORPG (a tick-based MMORPG is a MMORPG that allows the user do do RPGish actions, but the server part of it is refreshed every time the user either loads the page, or every set time or so. For instance, the...



All times are GMT +2. The time now is 19:30.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.