How to secure your mybb forum [Full Tutorial] 07-11-2013, 08:37 AM
#1
Hello guys and my friends today I'm making a small tutorial about how to secure your forum. after do all the steps, you forum will be secure 90%. I'm not going to tell its 100%, as a hacker you know any website can be get hacked 
Original tutorial wrote by CrazyFrog (:mad: don't bitch on me if you see this tutorial on another forum :mad
Well lets start, please read everything.
1st Step :
The ./inc/ directory shouldn't be accessible to the public. It's merely a collection of classes and functions. It also houses sensitive information such as database configurations and settings.
its very easy to protecting the directory from public access.
You can test it's working by going to http://yoursite.com/inc/
If you receive a 403 error then everything is working perfect and its not public anymore.
If you want to see a demo? See here: http://www.ehackerz.net/inc/
2ndt Step :
NOTE: This works best and most useful if you have a static IP address, otherwise you will be constantly changing the HTAccess file to match your IP!
3rd Step :
now we are going to add a secret PIN to ACP login.
On ./admin/inc/class_page.php:
Around line 391:
In ./admin/index.php
Around line 136:
Note:
The PIN does not have to be a number, it can be anything.
If the PIN is not set in .inc/config.php, it will not be checked/verified.
To do a different PIN for every admin:
In ./admin/index.php
Around line 136:
4th Step :
Renaming the administrator directory
Go To Inc Foder after that open Config.php
Find :
And you can change it as you want
for Example:
This is the path for admin panel
remember your admin folder name should be the same name as in the config file.
5th Step :
Disable Anonymous Ftp And Use Normal Ftp And Make Sure To Use Strong Password
Check your Cpanel And Make Sure That You password is Strong
How to disable Anonymous FTP
Simply login to cPanel and click the Anonymous FTP icon. Uncheck both boxes ("Allow anonymous access..." and "Allow anonymous upload...") and click the Save Settings button.
You will see anonymous@Domain.com and ftp@Domain.com in your cPanel, but they are not enabled if both boxes under Anonymous FTP are unchecked.
If you are connecting and see a public folder, then anonymous FTP is not enabled. (That folder is not on your account; it is on the server.)
I forgot to put some other things to the tutorial really sorry for it but here you go.
normally all database detail in inc/config.php so we should secure inc folder and config.php file. follow my this small steps to secure your inc folder and config.php file.
Look at step 1 on the tutorial. Edit that .htaccess file again put this code in to that .htaccess file
after that now change your inc folder CHMOD to :
and
config.php CHMOD to :
here is one other thing you can save your forum from hackers if you have an .htaccess file you can use mod_rewrite to block hackers from scanning your site with various security scanners.
paste this in your htaccess file and you shouldn't be scanned by anyone. Will update this as i find out about more scanners.
Well i hope this tutorial help full for you. if you have any problem or if you want me to secure your website post here. i'll try to do my best for you
Have a nice day and Thanks for reading
Special Thanks to Nathan Malcolm

Original tutorial wrote by CrazyFrog (:mad: don't bitch on me if you see this tutorial on another forum :mad

Well lets start, please read everything.
1st Step :
The ./inc/ directory shouldn't be accessible to the public. It's merely a collection of classes and functions. It also houses sensitive information such as database configurations and settings.
its very easy to protecting the directory from public access.
- Firstly, create a file called htaccess.txt. This will be renamed later but due to files that are prefixed with a period being hidden by default this is the best method.
- You want to edit this file with a text editor such as Notepad++ and put the following line at the top:
Code:deny from all - Now simply save it and upload to the ./inc/ directory on your web-host. You will then need to rename it to .htaccess
You can test it's working by going to http://yoursite.com/inc/
If you receive a 403 error then everything is working perfect and its not public anymore.
If you want to see a demo? See here: http://www.ehackerz.net/inc/
2ndt Step :
NOTE: This works best and most useful if you have a static IP address, otherwise you will be constantly changing the HTAccess file to match your IP!
- So you want to locate your ACP folder. Default is admin but mine is changed for security purposes. Open up the folder and create a file called ".htaccess" without quotes so now you should have /admin/.htaccess
Code:Options +FollowSymlinks RewriteEngine on RewriteCond %{REQUEST_URI} !/errordocs/error404.htm$ RewriteCond %{REMOTE_HOST} !^IPADDRESS RewriteRule $ /errordocs/error404.htm [R=302,L]
- here we used an error 404 because this completes hides the panel as if it doesn't exist. You can change yours if you like. So now whoever accesses http://yourdomain.com/forum/admin will appear as if the location doesn't exist. Of course you can change the error to anything you would like by modifying both addresses in the REQUEST and rewriterule
- But, of course, you need to access it too. So replace IPADDRESS with your IP address and try accessing your panel. You should now have full access to the ACP and any unauthorized people will be redirected to an error of your choice or you can redirect them to the homepage.
- To add more IP's to the list add the line directly below the previous line that looks like this :
Code:RewriteCond %{REMOTE_HOST} !^IPADDRESS - Just like the above steps replace the IPADDRESS except this time put your Admin's IP. Your Admin's should now have access.
3rd Step :
now we are going to add a secret PIN to ACP login.
On ./admin/inc/class_page.php:
Around line 391:
- Change :
PHP Code:<div class="label"{$login_label_width}><label for="password">{$lang->password}</label></div> <div class="field"><input type="password" name="password" id="password" class="text_input" /></div>
- To:
PHP Code:<div class="label"{$login_label_width}><label for="password">{$lang->password}</label></div> <div class="field"><input type="password" name="password" id="password" class="text_input" /></div> <div class="label"{$login_label_width}><label for="pin">Secret PIN</label></div> <div class="field"><input type="password" name="pin" id="pin" class="text_input" /></div>
In ./admin/index.php
Around line 136:
- Change:
PHP Code:if($user['uid']) { $query = $db->simple_select("users", "*", "uid='".$user['uid']."'"); $mybb->user = $db->fetch_array($query); }
- To:
PHP Code:if($user['uid']) { $query = $db->simple_select("users", "*", "uid='".$user['uid']."'"); $mybb->user = $db->fetch_array($query); } if (isset($config['acp_pin']) && $mybb->input['pin'] != $config['acp_pin']) { $default_page->show_login("Invalid PIN","error"); }
PHP Code:
$config['acp_pin'] = 'yourpin';
Note:
The PIN does not have to be a number, it can be anything.
If the PIN is not set in .inc/config.php, it will not be checked/verified.
To do a different PIN for every admin:
In ./admin/index.php
Around line 136:
- Change:
PHP Code:if($user['uid']) { $query = $db->simple_select("users", "*", "uid='".$user['uid']."'"); $mybb->user = $db->fetch_array($query); }
- To:
PHP Code:if($user['uid']) { $query = $db->simple_select("users", "*", "uid='".$user['uid']."'"); $mybb->user = $db->fetch_array($query); } $acpuid = $mybb->user['uid']; if (isset($config['acp_pin'][$acpuid]) && $mybb->input['pin'] != $config['acp_pin'][$acpuid]) { $default_page->show_login("Invalid PIN","error"); }
PHP Code:
$config['acp_pin'][uid of the admin without quotes] = 'yourpin';
$config['acp_pin'][uid of the second admin without quotes] = 'yourpin2';
4th Step :
Renaming the administrator directory
Go To Inc Foder after that open Config.php
Find :
PHP Code:
$config['admin_dir'] = 'admin';
And you can change it as you want
for Example:
PHP Code:
$config['admin_dir'] = 'privet_admin_area';
This is the path for admin panel
PHP Code:
http://example-website.com/privet_admin_area
remember your admin folder name should be the same name as in the config file.
5th Step :
Disable Anonymous Ftp And Use Normal Ftp And Make Sure To Use Strong Password
Check your Cpanel And Make Sure That You password is Strong
How to disable Anonymous FTP
Simply login to cPanel and click the Anonymous FTP icon. Uncheck both boxes ("Allow anonymous access..." and "Allow anonymous upload...") and click the Save Settings button.
Quote:Cpanel WHM > FTP Configuration > Disable Anonymous FTP
Cpanel > FTP Manager > Disable Anonymous FTP
You will see anonymous@Domain.com and ftp@Domain.com in your cPanel, but they are not enabled if both boxes under Anonymous FTP are unchecked.
If you are connecting and see a public folder, then anonymous FTP is not enabled. (That folder is not on your account; it is on the server.)
Update : 2013 - 04 - 06
I forgot to put some other things to the tutorial really sorry for it but here you go.
normally all database detail in inc/config.php so we should secure inc folder and config.php file. follow my this small steps to secure your inc folder and config.php file.
Look at step 1 on the tutorial. Edit that .htaccess file again put this code in to that .htaccess file
PHP Code:
# eHackerz.net Mybb config.php secure
<Files config.php>
order allow,deny
deny from all
</Files>
after that now change your inc folder CHMOD to :
Code:
400and
config.php CHMOD to :
Code:
100here is one other thing you can save your forum from hackers if you have an .htaccess file you can use mod_rewrite to block hackers from scanning your site with various security scanners.
PHP Code:
RewriteEngine On
<IfModule mod_rewrite.c>
RewriteCond %{HTTP_USER_AGENT} ^w3af.sourceforge.net [NC,OR]
RewriteCond %{HTTP_USER_AGENT} dirbuster [NC,OR]
RewriteCond %{HTTP_USER_AGENT} nikto [NC,OR]
RewriteCond %{HTTP_USER_AGENT} SF [OR]
RewriteCond %{HTTP_USER_AGENT} sqlmap [NC,OR]
RewriteCond %{HTTP_USER_AGENT} fimap [NC,OR]
RewriteCond %{HTTP_USER_AGENT} nessus [NC,OR]
RewriteCond %{HTTP_USER_AGENT} whatweb [NC,OR]
RewriteCond %{HTTP_USER_AGENT} Openvas [NC,OR]
RewriteCond %{HTTP_USER_AGENT} jbrofuzz [NC,OR]
RewriteCond %{HTTP_USER_AGENT} libwhisker [NC,OR]
RewriteCond %{HTTP_USER_AGENT} webshag [NC,OR]
RewriteCond %{HTTP:Acunetix-Product} ^WVS
RewriteRule ^.* http://127.0.0.1/ [R=301,L]
</IfModule>
paste this in your htaccess file and you shouldn't be scanned by anyone. Will update this as i find out about more scanners.
Well i hope this tutorial help full for you. if you have any problem or if you want me to secure your website post here. i'll try to do my best for you

Have a nice day and Thanks for reading
Special Thanks to Nathan Malcolm


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)


Thank you, hope you learn something with the tutorial
![[Image: OkXCq.gif]](http://i.imgur.com/OkXCq.gif)
