Login Register






How to secure your mybb forum [Full Tutorial] filter_list
Author
Message
How to secure your mybb forum [Full Tutorial] #1
Hello guys and my friends today I'm making a small tutorial about how to secure your forum. after do all the steps, you forum will be secure 90%. I'm not going to tell its 100%, as a hacker you know any website can be get hacked Wink

Original tutorial wrote by CrazyFrog (:mad: don't bitch on me if you see this tutorial on another forum :madSmile

Well lets start, please read everything.

1st Step :
The ./inc/ directory shouldn't be accessible to the public. It's merely a collection of classes and functions. It also houses sensitive information such as database configurations and settings.

its very easy to protecting the directory from public access.
  • Firstly, create a file called htaccess.txt. This will be renamed later but due to files that are prefixed with a period being hidden by default this is the best method.
  • You want to edit this file with a text editor such as Notepad++ and put the following line at the top:
    Code:
    deny from all
  • Now simply save it and upload to the ./inc/ directory on your web-host. You will then need to rename it to .htaccess

You can test it's working by going to http://yoursite.com/inc/
If you receive a 403 error then everything is working perfect and its not public anymore.
If you want to see a demo? See here: http://www.ehackerz.net/inc/

2ndt Step :
NOTE: This works best and most useful if you have a static IP address, otherwise you will be constantly changing the HTAccess file to match your IP!
  • So you want to locate your ACP folder. Default is admin but mine is changed for security purposes. Open up the folder and create a file called ".htaccess" without quotes so now you should have /admin/.htaccess

    Code:
    Options +FollowSymlinks RewriteEngine on RewriteCond %{REQUEST_URI} !/errordocs/error404.htm$ RewriteCond %{REMOTE_HOST} !^IPADDRESS RewriteRule $ /errordocs/error404.htm [R=302,L]

  • here we used an error 404 because this completes hides the panel as if it doesn't exist. You can change yours if you like. So now whoever accesses http://yourdomain.com/forum/admin will appear as if the location doesn't exist. Of course you can change the error to anything you would like by modifying both addresses in the REQUEST and rewriterule

  • But, of course, you need to access it too. So replace IPADDRESS with your IP address and try accessing your panel. You should now have full access to the ACP and any unauthorized people will be redirected to an error of your choice or you can redirect them to the homepage.

  • To add more IP's to the list add the line directly below the previous line that looks like this :
    Code:
    RewriteCond %{REMOTE_HOST} !^IPADDRESS
  • Just like the above steps replace the IPADDRESS except this time put your Admin's IP. Your Admin's should now have access.

3rd Step :

now we are going to add a secret PIN to ACP login.

On ./admin/inc/class_page.php:

Around line 391:
  • Change :
    PHP Code:
    <div class="label"{$login_label_width}><label for="password">{$lang->password}</label></div> <div class="field"><input type="password" name="password" id="password" class="text_input" /></div>

  • To:
    PHP Code:
    <div class="label"{$login_label_width}><label for="password">{$lang->password}</label></div> <div class="field"><input type="password" name="password" id="password" class="text_input" /></div> <div class="label"{$login_label_width}><label for="pin">Secret PIN</label></div> <div class="field"><input type="password" name="pin" id="pin" class="text_input" /></div>


In ./admin/index.php

Around line 136:
  • Change:
    PHP Code:
    if($user['uid']) { $query = $db->simple_select("users", "*", "uid='".$user['uid']."'"); $mybb->user = $db->fetch_array($query); }

  • To:

    PHP Code:
    if($user['uid']) { $query = $db->simple_select("users", "*", "uid='".$user['uid']."'"); $mybb->user = $db->fetch_array($query); } if (isset($config['acp_pin']) && $mybb->input['pin'] != $config['acp_pin']) { $default_page->show_login("Invalid PIN","error"); }
Ok. Then, open ./inc/config.php and add anywhere:

PHP Code:
$config['acp_pin'] = 'yourpin';

Note:
The PIN does not have to be a number, it can be anything.
If the PIN is not set in .inc/config.php, it will not be checked/verified.


To do a different PIN for every admin:

In ./admin/index.php

Around line 136:
  • Change:
    PHP Code:
    if($user['uid']) { $query = $db->simple_select("users", "*", "uid='".$user['uid']."'"); $mybb->user = $db->fetch_array($query); }

  • To:
    PHP Code:
    if($user['uid']) { $query = $db->simple_select("users", "*", "uid='".$user['uid']."'"); $mybb->user = $db->fetch_array($query); } $acpuid = $mybb->user['uid']; if (isset($config['acp_pin'][$acpuid]) && $mybb->input['pin'] != $config['acp_pin'][$acpuid]) { $default_page->show_login("Invalid PIN","error"); }
Open ./inc/config.php and add anywhere:

PHP Code:
$config['acp_pin'][uid of the admin without quotes] = 'yourpin'; $config['acp_pin'][uid of the second admin without quotes] = 'yourpin2';

4th Step :

Renaming the administrator directory
Go To Inc Foder after that open Config.php

Find :
PHP Code:
$config['admin_dir'] = 'admin';

And you can change it as you want
for Example:
PHP Code:
$config['admin_dir'] = 'privet_admin_area';

This is the path for admin panel
PHP Code:
http://example-website.com/privet_admin_area

remember your admin folder name should be the same name as in the config file.

5th Step :

Disable Anonymous Ftp And Use Normal Ftp And Make Sure To Use Strong Password
Check your Cpanel And Make Sure That You password is Strong

How to disable Anonymous FTP

Simply login to cPanel and click the Anonymous FTP icon. Uncheck both boxes ("Allow anonymous access..." and "Allow anonymous upload...") and click the Save Settings button.

Quote:Cpanel WHM > FTP Configuration > Disable Anonymous FTP
Cpanel > FTP Manager > Disable Anonymous FTP

You will see anonymous@Domain.com and ftp@Domain.com in your cPanel, but they are not enabled if both boxes under Anonymous FTP are unchecked.

If you are connecting and see a public folder, then anonymous FTP is not enabled. (That folder is not on your account; it is on the server.)



Update : 2013 - 04 - 06

I forgot to put some other things to the tutorial really sorry for it but here you go.

normally all database detail in inc/config.php so we should secure inc folder and config.php file. follow my this small steps to secure your inc folder and config.php file.

Look at step 1 on the tutorial. Edit that .htaccess file again put this code in to that .htaccess file

PHP Code:
# eHackerz.net Mybb config.php secure <Files config.php> order allow,deny deny from all </Files>

after that now change your inc folder CHMOD to :
Code:
400


and

config.php CHMOD to :

Code:
100

here is one other thing you can save your forum from hackers if you have an .htaccess file you can use mod_rewrite to block hackers from scanning your site with various security scanners.

PHP Code:
RewriteEngine On <IfModule mod_rewrite.c> RewriteCond %{HTTP_USER_AGENT} ^w3af.sourceforge.net [NC,OR] RewriteCond %{HTTP_USER_AGENT} dirbuster [NC,OR] RewriteCond %{HTTP_USER_AGENT} nikto [NC,OR] RewriteCond %{HTTP_USER_AGENT} SF [OR] RewriteCond %{HTTP_USER_AGENT} sqlmap [NC,OR] RewriteCond %{HTTP_USER_AGENT} fimap [NC,OR] RewriteCond %{HTTP_USER_AGENT} nessus [NC,OR] RewriteCond %{HTTP_USER_AGENT} whatweb [NC,OR] RewriteCond %{HTTP_USER_AGENT} Openvas [NC,OR] RewriteCond %{HTTP_USER_AGENT} jbrofuzz [NC,OR] RewriteCond %{HTTP_USER_AGENT} libwhisker [NC,OR] RewriteCond %{HTTP_USER_AGENT} webshag [NC,OR] RewriteCond %{HTTP:Acunetix-Product} ^WVS RewriteRule ^.* http://127.0.0.1/ [R=301,L] </IfModule>

paste this in your htaccess file and you shouldn't be scanned by anyone. Will update this as i find out about more scanners.

Well i hope this tutorial help full for you. if you have any problem or if you want me to secure your website post here. i'll try to do my best for you Smile

Have a nice day and Thanks for reading
Special Thanks to Nathan Malcolm

Reply

RE: How to secure your mybb forum [Full Tutorial] #2
This is a great tutorial and covers some good features of security! Good job!
(I see you're RaZoR on eHackerz.net hihi)

Reply

RE: How to secure your mybb forum [Full Tutorial] #3
(07-11-2013, 10:03 AM)Platinum Wrote: This is a great tutorial and covers some good features of security! Good job!
(I see you're RaZoR on eHackerz.net hihi)

hehe yeah its me Tongue Thank you, hope you learn something with the tutorial

Reply

RE: How to secure your mybb forum [Full Tutorial] #4
Good job, looks like an easy to do tutorial!
[Image: OkXCq.gif]

Reply

RE: How to secure your mybb forum [Full Tutorial] #5
(07-11-2013, 10:06 AM)Hexology Wrote: Good job, looks like an easy to do tutorial!

Thanks man, i'll update the thread with some new methods soon Wink

Reply

RE: How to secure your mybb forum [Full Tutorial] #6
(07-11-2013, 10:08 AM)CrazyFrog Wrote:
(07-11-2013, 10:06 AM)Hexology Wrote: Good job, looks like an easy to do tutorial!

Thanks man, i'll update the thread with some new methods soon Wink

You don't have to make it harder ;-)

Reply

RE: How to secure your mybb forum [Full Tutorial] #7
(07-11-2013, 10:17 AM)Platinum Wrote:
(07-11-2013, 10:08 AM)CrazyFrog Wrote:
(07-11-2013, 10:06 AM)Hexology Wrote: Good job, looks like an easy to do tutorial!

Thanks man, i'll update the thread with some new methods soon Wink

You don't have to make it harder ;-)

I'm not going to make it harder, just add some new secure place :huh:
Follow Code Community Rules and Keep The Board Clean
If you You break any rule of Code Community, Just keep in mind that CrazyFrog has an eye on You

Reply

RE: How to secure your mybb forum [Full Tutorial] #8
(07-11-2013, 10:20 AM)CrazyFrog Wrote:
(07-11-2013, 10:17 AM)Platinum Wrote:
(07-11-2013, 10:08 AM)CrazyFrog Wrote:
(07-11-2013, 10:06 AM)Hexology Wrote: Good job, looks like an easy to do tutorial!

Thanks man, i'll update the thread with some new methods soon Wink

You don't have to make it harder ;-)

I'm not going to make it harder, just add some new secure place :huh:

Sarcasm xD But bro do as you want Wink

Reply

RE: How to secure your mybb forum [Full Tutorial] #9
Wow! This is a HQ tutorial. Amazing work, thank you!

Reply

RE: How to secure your mybb forum [Full Tutorial] #10
(07-13-2013, 08:31 PM)Wet Wrote: Wow! This is a HQ tutorial. Amazing work, thank you!

Thank you, hope you could understand about mybb secure a bit :embarrased:
Follow Code Community Rules and Keep The Board Clean
If you You break any rule of Code Community, Just keep in mind that CrazyFrog has an eye on You

Reply