Retro Security

Page 1 of 2 12 LastLast
Results 1 to 15 of 20
  1. #1
    Valued Member JordanEllis is offline
    MemberRank
    Aug 2009 Join Date
    EnglandLocation
    117Posts

    Retro Security

    Hey all, I was just wondering if my Habbo retro was secure, or not - if not, how can I improve it?

    I have Xampp (deleted webdav), portforwarded, BCStorm, HabboPHP, no-ip domain.

    Was just wondering if there are any known exploits I can patch, or anything else that needs injecting into my database to prevent SQL injects, etc - anything to make it secure before it goes public is much appreciated. Thanks, Jord!

    Here is my CMS - I can't see any potential areas for injection apart from registration?
    Hobba


  2. #2
    ...[ White Rabbit ]... MentaL is offline
      Administrator  Rank
    Jan 2001 Join Date
    31,625Posts

    Re: Retro Security

    Set a root password on phpmyadmin/sql.

  3. #3
    Resurrected Jam32 is offline
    MemberRank
    Aug 2008 Join Date
    JamoniaLocation
    2,394Posts

    Re: Retro Security

    I really wouldn't use xampp.
    Also your site seems to be down. Best thing to do is search through this section and the release section for exploits. There is plenty lingering about!

  4. #4
    Valued Member JordanEllis is offline
    MemberRank
    Aug 2009 Join Date
    EnglandLocation
    117Posts

    Re: Retro Security

    Hobba Hotel
    it shouldn't be down :(
    also I have the root password :p

    What else could I use instead of Xampp, seeing as it's being hosted on my laptop, rather than a VPS (for now)

  5. #5
    Resurrected Jam32 is offline
    MemberRank
    Aug 2008 Join Date
    JamoniaLocation
    2,394Posts

    Re: Retro Security

    If your running on a laptop you'll have to be super secure. There are many skids and kiddy booters, who will simply boot you offline over something pathetic. Not just the hotel goes down but your connection will too. (4 years ago you'd be alright, nowadays its e-suicide)

    If and when you get on a vps use IIS. For now on a laptop i'd personally use a proper apache and mysql setup(Not prepacked together like xampp)

  6. #6
    Banned V for Vendetta is offline
    BannedRank
    Feb 2007 Join Date
    1,809Posts

    Re: Retro Security

    I'll have to be honest that you need to following improvements.

    - If you're running on a VPS then you might want to add DdoS proxy for if people are going to try to attack your server

    - Don't use XAMPP just use IIS because that's much better and way secure.

    - Be sure that your passwords are on somewhere where nobody else can breach it, So be sure that you have it wrote down on a paper on your desk or such else.

    Last: Delete Anonymous. Via there people can upload to your files and just delete them easily.

  7. #7
    Developer Quackster is online now
    DeveloperRank
    Dec 2010 Join Date
    AustraliaLocation
    3,474Posts

    Re: Retro Security

    Your domain links to a LAN IP. Which is why it's down for us.

  8. #8
    Valued Member JordanEllis is offline
    MemberRank
    Aug 2009 Join Date
    EnglandLocation
    117Posts

    Re: Retro Security

    Quote Originally Posted by Quackster View Post
    Your domain links to a LAN IP. Which is why it's down for us.
    Does this work?

    Quote Originally Posted by Chaosfire View Post
    I'll have to be honest that you need to following improvements.

    - If you're running on a VPS then you might want to add DdoS proxy for if people are going to try to attack your server

    - Don't use XAMPP just use IIS because that's much better and way secure.

    - Be sure that your passwords are on somewhere where nobody else can breach it, So be sure that you have it wrote down on a paper on your desk or such else.

    Last: Delete Anonymous. Via there people can upload to your files and just delete them easily.
    I'm not running on a vps as of yet, so I guess IIS is out of the window? And the password isn't written anywhere apart from my config settings. Anonymous deleted, thankyou.

    Quote Originally Posted by Jam32 View Post
    If your running on a laptop you'll have to be super secure. There are many skids and kiddy booters, who will simply boot you offline over something pathetic. Not just the hotel goes down but your connection will too. (4 years ago you'd be alright, nowadays its e-suicide)

    If and when you get on a vps use IIS. For now on a laptop i'd personally use a proper apache and mysql setup(Not prepacked together like xampp)
    Any further help on the apache and mysql setup? As I am using a laptop for now, and xampp (suicide, I know)

  9. #9
    Pee Aitch Pee Dave is offline
    MemberRank
    Mar 2011 Join Date
    The NetherlandsLocation
    722Posts

    Re: Retro Security

    Use Cloudflare, NGINX and restrict special pages to your IP only.

  10. #10
    Banned V for Vendetta is offline
    BannedRank
    Feb 2007 Join Date
    1,809Posts

    Re: Retro Security

    Quote Originally Posted by SuperWaffle View Post
    Use Cloudflare, NGINX and restrict special pages to your IP only.
    How about no. Cloudflare sucks, he rather want to use DdoS proxy.

  11. #11
    Lurking since '06 1ntel is offline
    MemberRank
    Jul 2006 Join Date
    401Posts

    Re: Retro Security

    deleted
    Last edited by 1ntel; 30-04-13 at 09:33 PM.

  12. #12
    Valued Member JordanEllis is offline
    MemberRank
    Aug 2009 Join Date
    EnglandLocation
    117Posts

    Re: Retro Security

    Tell me more about CloudFlare, please, if you would

  13. #13
    I don't even know azaidi is offline
    MemberRank
    Apr 2010 Join Date
    the NetherlandsLocation
    2,065Posts

    Re: Retro Security

    Your SWF links in your client are set to 192.168.1.71, and your no-ip site is too. Please set everything to your IP 86.164.153.144 or to your no-ip domain.

  14. #14
    Valued Member JordanEllis is offline
    MemberRank
    Aug 2009 Join Date
    EnglandLocation
    117Posts

    Re: Retro Security

    Yeah I figured that out, had to create a new no-ip as the old one is on a different email, apparently.
    It's now hobba.no-ip.org, which is better

    ERRORDismissSorry, that domain ("no-ip.org") requires an extra step. Please contact us directly and we'll help you quickly.
    :(

  15. #15
    Banned V for Vendetta is offline
    BannedRank
    Feb 2007 Join Date
    1,809Posts

    Re: Retro Security

    Quote Originally Posted by matty13 View Post
    Explain what is wrong with Cloudflare?
    You can find the IP easily brother. You haven't read my previous post obviously yet but you are always able to get the VPS/Computer ip which makes them still able to screw around with you.



Page 1 of 2 12 LastLast

Advertisement