View Full Version : Urgent!!!!People can see my backdoor.
manutdvn
10-9-05, 03:29 AM
Hello,
I donot why Any one can see my host content like this:
http://mydomain.com/forum/install or all folder in my host
If any one have customer ID they can install my forum. Please help me to fix this problem.
Thank you.
Hello,
I donot why Any one can see my host content like this:
http://mydomain.com/forum/install or all folder in my host
If any one have customer ID they can install my forum. Please help me to fix this problem.
Thank you.There is a line in .htaccess that will prevent viewing the listing of contents of directories.
http://kb.powweb.com/questions/341/Directory-Listing
As a backup measure (in case you're working on .htaccess file at some time), you could make sure each folder has a index.html file - possibly redirecting back to the main page.
manutdvn
10-9-05, 04:11 AM
Thank you.
Croc Hunter
10-9-05, 07:52 AM
Usually after you install applications like forums, phpBB etc.. you are told to delete any install and contrib type of directories as they pose a security risk. Check you installation guide again.
lardconcepts
10-9-05, 10:28 AM
Urgent!!!!People can see my backdoor.Whoa there! Powweb doesn't allow porn ;)
Security through obscurity is not security. As said above, any "install" scripts should be removed after the install is complete, or at least password protect them. Obscurity can help deflect attacks - I always recommend renaming "admin" type scripts or folders, but that's just one layer of defense and password-protection is a critical second layer. And you certainly want to prevent people from getting an index of any of your folders.
As for an index.html that redirects - as long as you have no links to it, search engines will never see it.
Record paths, yes. But your browsing causing a search engine to see a link? Well, maybe if you have spyware. I haven't seen evidence of this myself. Hosting logs that contain actual links and which are linked to from your site, yes, that will cause search engines to pick it up.
I don't believe that these toolbars feed back into the search engines. They record them in the local index only. I use Google's toolbar and I see no evidence that Google tries accessing private pages.
vBulletin v3.6.0, Copyright ©2000-2009, Jelsoft Enterprises Ltd.