
mscott
Mscott's mindless security tips
Comments
| jerry79(positive) | 38 days ago![]() |
![]() | ![]() | |
![]() | Great Mike, fantastic tutorial. Thanks a lof for your whole work on this! I was writing to boonex to get something like this from the offical way as a blog post. Now you did it, congratz, well done! I think this wíll help a lot of peeps outthere! Cheers, Jerry | ![]() |
![]() | ![]() | ![]() |
| DoLaugh | 38 days ago![]() |
![]() | ![]() | |
![]() | Thanks MS! Renaming the plugins directory stopped the automated HACKER hits on that directory. Wish I could hide my index file..but Yahoo Hosting doesn't allow for .htaccess and of course they have the globals setting to ON....refused to change it, but it was a great suggestion! lol I await for Boonex security release....for us who are stuck with the globals setting to ON. DoLaugh | ![]() |
![]() | ![]() | ![]() |
| DoLaugh | 38 days ago![]() |
![]() | ![]() | |
![]() | Apparently these guys are not that lazy. They figured out I changed the plugins directory and have been hitting me hard right into the tiny_mce directory. What kind of files are these?? tiny_mce_7631bebfb79200122b9933688c5a2479.gz | ![]() |
![]() | ![]() | ![]() |
View 2 replies to this comment
| gameutopia(positive) | 37 days ago![]() |
![]() | ![]() | |
![]() | Some really good tips I'm sure a number of members will get some good use out of these. | ![]() |
![]() | ![]() | ![]() |
| DoLaugh | 37 days ago![]() |
![]() | ![]() | |
![]() | mscott, thanks again! great advice! jtadeo and gamutopia...any ideas on the tiny_mce files I asked about? | ![]() |
![]() | ![]() | ![]() |
| gameutopia | 36 days ago![]() |
![]() | ![]() | |
![]() | The tinymce you mention in your earlier post that I touched on regarding: tiny_mce_7631bebfb79200122b9933688c5a2479.gz That is just caching one of the tinymce editors for faster loading if you post something else soon. They are later cleared, and will return again once someone else posts a blog, event, etc. That particular file you mention is normal activity. However if you are seeing odd .php files showing up I might be a little more concerned. | ![]() |
![]() | ![]() | ![]() |
View 1 replies to this comment
| DoLaugh | 36 days ago![]() |
![]() | ![]() | |
![]() | mscott(positive) 1 day ago I could be mistaken but I believe that might be a file that is created by tiny_mce.. I have those in my /cache directory all the time. The only way to know for sure if you are still being hit is to look at your log files. Make sure you set Cpanel up so it archives them and doesn't just save one days worth. Sometimes I feel so stupid,,,,,where do I find my log files? Dolaugh | ![]() |
![]() | ![]() | ![]() |
| gameutopia | 36 days ago![]() |
![]() | ![]() | |
![]() | Hey DoLaugh I'm not sure how familiar you are with hosting, mscott is referring to your hosting control panel. Cpanel is the most common, but there are others out there. If your host does have the latest cpanel v11+ depending on the theme or skin you should find an area somewhere after logging in for "Logs". Then find and click on the icon or link for "Raw Access Logs". On the next screen towards the bottom you will be able to download your current HTTP Access Logs if you want to do that right now. Towards the top of this same page you will find a box you can check to "Archive Logs to your home directory" and save this. Then over time you will be able to download a much larger range of logs. If you are not too familiar with cpanel play around with it, there are many things you can check ftp logs, you can check your stats and traffic. See where they are coming from, any error/page not found, awstats is nice, etc, etc. If you have something other than cpanel, you might ask your host how to go about doing this. Good Luck!! | ![]() |
![]() | ![]() | ![]() |
| mscott(positive) | 35 days ago![]() |
![]() | ![]() | |
![]() | Gameutopia is exactly right (as always).. and I have gotten so used to Cpanel over the years that I wouldn't know how to use anything else. It has some PRICELESS features.. You can find out if your host has it by typing www.yoursite.com/cpanel .. if you have it the Apache login box will popup. Another priceless Cpanel feature is "Full Backup" it will backup your WHOLE account and send you an email when it's done! Then you can FTP the file to your harddrive and burn it on a CD or DVD. | ![]() |
![]() | ![]() | ![]() |
Post a Comment
Please login to post a comment.




































