Need help securing backend of website

Status
This thread has been locked.
PebbleHost
High performance, consistent uptime and fast support. Minecraft hosting that just works.

Ivann

Feedback score
1
Posts
15
Reactions
9
Resources
0
I think you've been watching to many hacking movies.
I think you'd be suprised how many servers get hacked every day. There are thousands if not millions of bots that just scout the web for servers and try various exploits on them.
 

dentmaged

Premium
Feedback score
2
Posts
110
Reactions
38
Resources
0
If you paid for a developer, and the website he made isn't secure, you should probably ask for a refund or get them to fix it. Do you know what problems there are?
 

Furex

EnderSetups & Manager of Kirbs!
Premium
Feedback score
0
Posts
1,047
Reactions
269
Resources
0
I think you'd be suprised how many servers get hacked every day. There are thousands if not millions of bots that just scout the web for servers and try various exploits on them.
Yes they get hacked but you make it sound like a its a major problem, think of it this way:
1 minecraft server gets hacked they loose a small amount of money. Unless it was hypixel or something it wouldn't be a huge issue.
 

Ivann

Feedback score
1
Posts
15
Reactions
9
Resources
0
Yes they get hacked but you make it sound like a its a major problem, think of it this way:
1 minecraft server gets hacked they loose a small amount of money. Unless it was hypixel or something it wouldn't be a huge issue.
It's not a "huge" issue but in most cases your server will be added to a bot-net and be taking apart in DDOS-attacks which mind end up getting your server suspended.
 

Mathew

Feedback score
2
Posts
1,078
Reactions
424
Resources
0
Yes they get hacked but you make it sound like a its a major problem, think of it this way:
1 minecraft server gets hacked they loose a small amount of money. Unless it was hypixel or something it wouldn't be a huge issue.

It is a major problem to small servers though regardless of how large they are. It is so easy to do this as there are so many tutorials out there that show you how to find xss and sql injection
 

Furex

EnderSetups & Manager of Kirbs!
Premium
Feedback score
0
Posts
1,047
Reactions
269
Resources
0
It's not a "huge" issue but in most cases your server will be added to a bot-net and be taking apart in DDOS-attacks which mind end up getting your server suspended.
That's why you get DDOS protection.[DOUBLEPOST=1470056943][/DOUBLEPOST]
It is a major problem to small servers though regardless of how large they are. It is so easy to do this as there are so many tutorials out there that show you how to find xss and sql injection
It isn't a major problem if they have been clever and taken a backup of there server...
 

Mathew

Feedback score
2
Posts
1,078
Reactions
424
Resources
0
It isn't a major problem if they have been clever and taken a backup of there server...

It's not the problem of them just deleting your website but with SQL injector etc, I would be able to access all of the emails, passwords and personal information of everyone that has registered to your website.
 

Xilcho

Web Designer
Supreme
Feedback score
0
Posts
109
Reactions
86
Resources
0
giphy.gif

We did it boys, we hacked the mainframe.
On a more serious note, you need to be way more specific about things if you want to get real help from anyone!

Have a good day,
Xasabam[DOUBLEPOST=1470092135][/DOUBLEPOST]
It's not the problem of them just deleting your website but with SQL injector etc, I would be able to access all of the emails, passwords and personal information of everyone that has registered to your website.
If they're not encrypting passwords, they've got much bigger problems.
 
Last edited:

Mathew

Feedback score
2
Posts
1,078
Reactions
424
Resources
0
iVHfwLc.gif

We did it boys, we hacked the mainframe.
On a more serious note, you need to be way more specific about things if you want to get real help from anyone!

Have a good day,
Xasabam[DOUBLEPOST=1470092135][/DOUBLEPOST]
If they're not encrypting passwords, they've got much bigger problems.

Wouldn't it just take a few hours though to decrypt all of the passwords depending on the encryption they are using?
 

Xilcho

Web Designer
Supreme
Feedback score
0
Posts
109
Reactions
86
Resources
0
Wouldn't it just take a few hours though to decrypt all of the passwords depending on the encryption they are using?
I don't see why someone wouldn't be using SHA-256 for passwords. With current computers, it's unrealistic to directly "decrypt" anything encrypted with SHA-256. Realistically, it can't be undone. The most effective method would be to try to guess the password, encrypt it, and then see if the result matches with the one in the database. Obviously, this has no benefit over just trying to guess their password directly, and unless their password is incredibly weak, will take a long time.

Of course, if they're not encrypting and/or are not using encryption that is equivalent to SHA-256, they have massive problems.
 

Samuel

The most serious person ever.
Supreme
Feedback score
33
Posts
2,210
Reactions
1,572
Resources
0
That's why you get DDOS protection.[DOUBLEPOST=1470056943][/DOUBLEPOST]
It isn't a major problem if they have been clever and taken a backup of there server...
DDoS protection wouldn't help if it's your server being used as one of the nodes in the botnet. DDoS protection usually only helps inbound, not outbound (though hosts will often suspend you if they detect malicious activity).
 

Furex

EnderSetups & Manager of Kirbs!
Premium
Feedback score
0
Posts
1,047
Reactions
269
Resources
0
DDoS protection wouldn't help if it's your server being used as one of the nodes in the botnet. DDoS protection usually only helps inbound, not outbound (though hosts will often suspend you if they detect malicious activity).
That's only if you get good hosting not some shit multicraft.
 

Samuel

The most serious person ever.
Supreme
Feedback score
33
Posts
2,210
Reactions
1,572
Resources
0
That's only if you get good hosting not some shit multicraft.
I'm pretty sure any host that isn't offshore and runs their own hardware has some solution in place to detect outbound attacks.
 

Furex

EnderSetups & Manager of Kirbs!
Premium
Feedback score
0
Posts
1,047
Reactions
269
Resources
0
I'm pretty sure any host that isn't offshore and runs their own hardware has some solution in place to detect outbound attacks.
Meh, that's what you think, some of there service isn't great trust me.
 

Samuel

The most serious person ever.
Supreme
Feedback score
33
Posts
2,210
Reactions
1,572
Resources
0
Meh, that's what you think, some of there service isn't great trust me.
Obviously some don't, and they get in trouble when bad clients join.
 

Skionz

ogminecraft.com
Premium
Feedback score
1
Posts
1,544
Reactions
1,527
Resources
0
It's not a "huge" issue but in most cases your server will be added to a bot-net and be taking apart in DDOS-attacks which mind end up getting your server suspended.
That is ridiculous. The attacker would have to add new software to you server such as a new plugin, or a modifier version of your server software. You can easily prevent that by keeping a backup of your server and if someone does gain access delete all the files and throw your backup on the server.
 

Mathew

Feedback score
2
Posts
1,078
Reactions
424
Resources
0
That is ridiculous. The attacker would have to add new software to you server such as a new plugin, or a modifier version of your server software. You can easily prevent that by keeping a backup of your server and if someone does gain access delete all the files and throw your backup on the server.

If it's a rat/trojan, and you reinstall your server software etc, it's still possible for it to come back as it has already been in the system and hard drive. That all depends on how good the code is for it.
 

Skionz

ogminecraft.com
Premium
Feedback score
1
Posts
1,544
Reactions
1,527
Resources
0
If it's a rat/trojan, and you reinstall your server software etc, it's still possible for it to come back as it has already been in the system and hard drive. That all depends on how good the code is for it.
If your host doesn't allow you to access the system / hard drive the "trojan" won't be able to either.
 
Status
This thread has been locked.
Top