Hello,
I was wondering how databased can be hacked? Do different hosting companies provide better security?
When I say this, I mean how can one get the password to the vps.
Thanks.
|
|
Hello,
I was wondering how databased can be hacked? Do different hosting companies provide better security?
When I say this, I mean how can one get the password to the vps.
Thanks.

Cracking... Which is an art of itself.
shitty php websites is 98% of it, mainly php forums vbulletin and ipb being the big culprits in rsps. the other 2% is usually stupidity or social engineering.
run forums on a separate server, without any access to anything else, lock admin panel to ip and make sure you restrict all the crappy php functions via disable_functions, change any password cipher to bcrypt, script or argon2.
bruteforcing ssh which allows plaintext authentication, bruteforcing rdp with multiple proxies and again stupidity / social engineering. seen hosting companies reset root password from people who have got info from whois and said they lost the password, really that basic.
always lock down any way of controlling the server itself, if you have a static ip using ip restriction or a subnet of your ip if its dynamic, 2step auth anything which makes it so only YOU even if someone else got your password can get on the server.
(a vps can also be a webhost btw)
| « Host4Fun - Budget High Ram Windows VPS At 8 Locations (NYC/DAL/PHX/CA/FR/DE/UK/PL) | Sale of high-end servers for 30$. » |
| Thread Information |
Users Browsing this ThreadThere are currently 1 users browsing this thread. (0 members and 1 guests) |