Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-27, 23:12:32

Author Topic: Mysql Security in Kloxo-MR  (Read 10126 times)

0 Members and 1 Guest are viewing this topic.

Offline prgs1971

  • Valuable Member
  • *
  • Posts: 81
  • Karma: +0/-0
    • View Profile
    • http://premium-prestashop-hosting.com
Re: Mysql Security in Kloxo-MR
« Reply #15 on: 2013-08-18, 21:17:03 »
With a increase of 1600%(one thousand and six hundred percent) in Hackers attacks in 2013 i start to get very concerned about security in my VPS.

Now i look for every detail that can compromise security ;)

I will try to learn the language used in that script and i will change it my self.

I hope that will not be to hard to prompt the user for a input in this language.

I will post that when done ;)
« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Mysql Security in Kloxo-MR
« Reply #16 on: 2013-08-18, 21:19:54 »
I am not paranoid.

VPS for this forum not using firewall (like iptables/CSF). Why?. Because I think protect from nginx and lxguard is enough!.
« Last Edit: 1970-01-01, 01:00:00 by Guest »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline prgs1971

  • Valuable Member
  • *
  • Posts: 81
  • Karma: +0/-0
    • View Profile
    • http://premium-prestashop-hosting.com
Re: Mysql Security in Kloxo-MR
« Reply #17 on: 2013-08-18, 21:20:38 »
Quote from: "MRatWork"
If you not select 'mod_php' (already remove from Kloxo-MR) and only you (as root/admin) able access to ssh, no reason to worry other people able access to bash history (because impossible).

I think that only with ssh access as root/admin, as you say, will be possible to see that file, but i will take this caution anyway.

Thank you very much for your help and advice's ;)
« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Mysql Security in Kloxo-MR
« Reply #18 on: 2013-08-18, 21:35:37 »
Remember, someone try access to your vps via ssh/ftp/panel will banned if fail until 20 (depend on your setting).

Also, sql-injection bug on Kloxo official already fixed in Kloxo-MR.
« Last Edit: 1970-01-01, 01:00:00 by Guest »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline prgs1971

  • Valuable Member
  • *
  • Posts: 81
  • Karma: +0/-0
    • View Profile
    • http://premium-prestashop-hosting.com
Re: Mysql Security in Kloxo-MR
« Reply #19 on: 2013-08-18, 22:00:08 »
Quote from: "MRatWork"
Remember, someone try access to your vps via ssh/ftp/panel will banned if fail until 20 (depend on your setting)

I have it enabled, but without a firewall you can exceed the max attempts you have configured.

Lxguard read from a log file the failed attempts and then blocks the ip...

I prefer to use Iptables or CSF to have real time blocking.

Quote from: "MRatWork"
Also, sql-injection bug on Kloxo official already fixed in Kloxo-MR.
I was not aware of this one :(
« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Mysql Security in Kloxo-MR
« Reply #20 on: 2013-08-18, 22:27:02 »
Sql-injection in Kloxo official is critical issue because it's make someone from external to access/take-over your server after successful login.
« Last Edit: 1970-01-01, 01:00:00 by Guest »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline prgs1971

  • Valuable Member
  • *
  • Posts: 81
  • Karma: +0/-0
    • View Profile
    • http://premium-prestashop-hosting.com
Re: Mysql Security in Kloxo-MR
« Reply #21 on: 2013-08-18, 22:59:01 »
You mean successful login to kloxo admin interface or user interface?
« Last Edit: 1970-01-01, 01:00:00 by Guest »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Mysql Security in Kloxo-MR
« Reply #22 on: 2013-08-18, 23:09:15 »
With sql-injection, possible someone login as 'admin' to Kloxo official panel.
« Last Edit: 1970-01-01, 01:00:00 by Guest »
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

 


Top 10 Social Networking:    Facebook    Twitter    LinkedIn    Pinterest    Google Plus    Tumblr    Instagram    VK    Flickr    Vine

Page created in 0.078 seconds with 19 queries.

web stats analysis