Platinum Sif said:I remember when it was RunescapeForums, and Carbon was setting up a irc and he said his password and someone delete RSF :L
Anyways, glad to hear we're more of a respectful site than others.
Carbon said:That never happened, RSF's cpanel and $super_admin had a 40+ char password.
Platinum Sif said:Well then you trolled everyone, because I'm pretty sure I TV'd Jeterfan as he did it.
Carbon said:Nawp you must be thinking of something else, maybe the irc itself because that did happen but it was a free IRC and the password was localised to just the IRC.
gfxer said:Easy fix.
- Make sure anyone with ACP/MySQL/SSH access has very strong passwords. Non-dictionary 12+ character passwords
- Deny access to profile for guests. Blocks majority of automated tools. You could also block the search feature for guests.
- Deny from all except said IPs (htaccess) for sensitive areas (ACP & whatever you use to manage mysql)
- Change the directory that the ACP is under. Make is very random.
- The emails connected to sensitive (ACP/mod) accounts should ONLY be used for these accounts. They should never be revealed.
- Implement an IP block for RBL'd/detected proxies IPs. That is what Hackforum does and it eliminates sooo many problems. Search around for a php script that automatically negates access if proxied IP is detected.
That eliminates a lot of future problems. Whoever is targeting RG... I guarantee that they aren't a threat. Just skids.
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?