Thread: Databases

Page 1 of 2 12 LastLast
Results 1 to 10 of 13
  1. #1 Databases 
    Registered Member
    Join Date
    Dec 2016
    Posts
    110
    Thanks given
    8
    Thanks received
    0
    Rep Power
    11
    Hello,

    I was wondering how databased can be hacked? Do different hosting companies provide better security?
    When I say this, I mean how can one get the password to the vps.

    Thanks.
    Reply With Quote  
     

  2. #2  
    Banned

    Join Date
    Mar 2011
    Posts
    657
    Thanks given
    105
    Thanks received
    75
    Rep Power
    0
    Cracking... Which is an art of itself.
    Reply With Quote  
     

  3. #3  
    Respected Member

    Join Date
    Jan 2009
    Posts
    5,682
    Thanks given
    1,093
    Thanks received
    3,494
    Discord
    View profile
    Rep Power
    5000
    shitty php websites is 98% of it, mainly php forums vbulletin and ipb being the big culprits in rsps. the other 2% is usually stupidity or social engineering.

    run forums on a separate server, without any access to anything else, lock admin panel to ip and make sure you restrict all the crappy php functions via disable_functions, change any password cipher to bcrypt, script or argon2.
    Reply With Quote  
     

  4. #4  
    Registered Member
    Join Date
    Dec 2016
    Posts
    110
    Thanks given
    8
    Thanks received
    0
    Rep Power
    11
    Quote Originally Posted by Stuart View Post
    shitty php websites is 99% of it, mainly php forums vbulletin and ipb being the big culprits in rsps. the other 1% is usually stupidity
    Alright, but that is webhost. I'm talking about VPS
    Reply With Quote  
     

  5. #5  
    Respected Member

    Join Date
    Jan 2009
    Posts
    5,682
    Thanks given
    1,093
    Thanks received
    3,494
    Discord
    View profile
    Rep Power
    5000
    Quote Originally Posted by Lowkey Skiller View Post
    Alright, but that is webhost. I'm talking about VPS
    bruteforcing ssh which allows plaintext authentication, bruteforcing rdp with multiple proxies and again stupidity / social engineering. seen hosting companies reset root password from people who have got info from whois and said they lost the password, really that basic.

    always lock down any way of controlling the server itself, if you have a static ip using ip restriction or a subnet of your ip if its dynamic, 2step auth anything which makes it so only YOU even if someone else got your password can get on the server.

    (a vps can also be a webhost btw)
    Reply With Quote  
     

  6. #6  
    Registered Member
    Join Date
    Dec 2016
    Posts
    110
    Thanks given
    8
    Thanks received
    0
    Rep Power
    11
    Quote Originally Posted by Stuart View Post
    bruteforcing ssh which allows plaintext authentication, bruteforcing rdp with multiple proxies and again stupidity / social engineering.

    (a vps can also be a webhost btw)
    So a simple solution to this would be to not buy a very cheap VPS? Buy one from a decent company?
    Reply With Quote  
     

  7. #7  
    Respected Member

    Join Date
    Jan 2009
    Posts
    5,682
    Thanks given
    1,093
    Thanks received
    3,494
    Discord
    View profile
    Rep Power
    5000
    Quote Originally Posted by Lowkey Skiller View Post
    So a simple solution to this would be to not buy a very cheap VPS? Buy one from a decent company?
    Yes, use someone with history and seen all the tricks before. Do not allow wildcard access to database software too.
    Reply With Quote  
     

  8. #8  
    Registered Member
    Join Date
    Dec 2016
    Posts
    110
    Thanks given
    8
    Thanks received
    0
    Rep Power
    11
    Quote Originally Posted by Stuart View Post
    Yes, use someone with history and seen all the tricks before. Do not allow wildcard access to database software too.
    You know any good VPS hosting companies that I should use?
    Reply With Quote  
     

  9. #9  
    Banned
    Join Date
    Dec 2011
    Age
    28
    Posts
    640
    Thanks given
    1
    Thanks received
    4
    Rep Power
    0
    Quote Originally Posted by Lowkey Skiller View Post
    You know any good VPS hosting companies that I should use?
    You're welcome to look into our VPS plans here, which are secure enough to run a properly configured MySQL server: [Only registered and activated users can see links. ]

    Been running for over 5 years and no complaints over any MySQL exposures as of yet - and I'm sure it'll stay that way
    Reply With Quote  
     

  10. #10  
    Registered Member
    Join Date
    Dec 2016
    Posts
    110
    Thanks given
    8
    Thanks received
    0
    Rep Power
    11
    Quote Originally Posted by Terrum View Post
    You're welcome to look into our VPS plans here, which are secure enough to run a properly configured MySQL server: [Only registered and activated users can see links. ]

    Been running for over 5 years and no complaints over any MySQL exposures as of yet - and I'm sure it'll stay that way
    So I want to get something straight. If my webhost and vpshost are two different companies... The hacker can't get my rsps database that is on my vps, right? Unless he tries to get the forum database, and hopes that the passwords match. Am I correct?
    Reply With Quote  
     

Page 1 of 2 12 LastLast

Thread Information
Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)


User Tag List

Similar Threads

  1. Replies: 16
    Last Post: 05-04-2008, 09:14 PM
  2. Item database
    By wildy in forum Configuration
    Replies: 8
    Last Post: 04-29-2008, 12:33 PM
  3. working XAMPP and mySQL databases's
    By yankee in forum Tutorials
    Replies: 14
    Last Post: 03-20-2008, 07:33 PM
  4. The best and Biggest RS Download database on the web!
    By Afghano4Life in forum RS2 Server
    Replies: 8
    Last Post: 09-30-2007, 07:08 PM
  5. Kulma Download Database
    By Jim in forum Downloads
    Replies: 2
    Last Post: 07-22-2007, 10:13 PM
Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •