1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

How to test if your site is safe from hacker.

Discussion in 'Security' started by miexl, Aug 10, 2009.

  1. #1
    guys, how to test if your site if safe from hacker or any suspicious activity
     
    miexl, Aug 10, 2009 IP
  2. premiumscripts

    premiumscripts Peon

    Messages:
    1,062
    Likes Received:
    48
    Best Answers:
    0
    Trophy Points:
    0
    #2
    There is no test you can do to see if you're safe. All you can try and do is make sure you're using the most up to date scripts and sensible passwords. Or are you using custom scripts?
     
    premiumscripts, Aug 12, 2009 IP
  3. manikas

    manikas Peon

    Messages:
    43
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Of course you can test ur site.
    Try acunetix vulnerability scanner.
     
    manikas, Aug 14, 2009 IP
  4. j4k3yyy

    j4k3yyy Peon

    Messages:
    35
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    What good is acunetix vulnerability scanner if he can't interperet the results? Also, it's not a free software it's extremely expensive and you wont find the latest version without paying for it.

    Nothing is ever 100% secure. The best thing you can do like previous poster mentioned is keep your stuff up to date, don't use stupid passwords and don't use the same password for everything.
     
    j4k3yyy, Aug 15, 2009 IP
  5. jacksmith12

    jacksmith12 Guest

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I know the answer hire a pen tester which is some one who you pay to hack your site.:D
     
    jacksmith12, Aug 15, 2009 IP
  6. campolar

    campolar Peon

    Messages:
    2,683
    Likes Received:
    244
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Hire a hacker and ask him to try and hack ur site :p If he can, u lose... If he cant, ur safe
     
    campolar, Aug 15, 2009 IP
  7. j4k3yyy

    j4k3yyy Peon

    Messages:
    35
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Just because one person can't doesn't mean it's safe... How many people do you think look for exploits in wordpress? And of that number, how many actually find them?
     
    j4k3yyy, Aug 15, 2009 IP
  8. Steve Powers

    Steve Powers Peon

    Messages:
    1,196
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #8
    This problem is so complicated. If you only want to test whether it is safe or not, you can try to find some able guys to attack it. There's definitely no absolute safety to your website. But you still can do many things to avoid hacking. For example, make sure the server your website is on is trustworthy. That means you should choose a good hosting provider.Also use encryption technology and do not set some simple even stupid password. What's more you can use some software to scan the hole of your site so that it can be repaired in time. Finally, maybe it would be better for you to hire a competent guy to manage your website and the network. Some hackers use the weakness of network to campaign attacks. In a word, no way to promise a absolute safety, just try your best to make it safer.
     
    Steve Powers, Aug 15, 2009 IP
  9. campolar

    campolar Peon

    Messages:
    2,683
    Likes Received:
    244
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Thats why you should hire a good one.

    About wordpress, you can use the login lockdown plugin which locks brute force attempts...

    and for a server, u can just DDoS it and see if its good in handling DDoS attacks..
     
    campolar, Aug 16, 2009 IP
  10. j4k3yyy

    j4k3yyy Peon

    Messages:
    35
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Whilst i agree it's a good idea to hire a decent pen tester it's still not a guarantee of security, plus do you know how much it costs to hire someone who's CCISP certified for a day? :p

    Off topic: Thanks for that plugin, i was unaware of it's existence \o/. Definitely gonna check it out :)
     
    j4k3yyy, Aug 16, 2009 IP
  11. coun_vincent

    coun_vincent Well-Known Member

    Messages:
    803
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    130
    #11
    am security and also i said there's not safe site , just be carefully and watch ur site security and thnx god u are still alive .
    be cuz hacker can access not only from site bugs they can access from apeach or make u ddos attack or ......
     
    coun_vincent, Aug 16, 2009 IP
  12. campolar

    campolar Peon

    Messages:
    2,683
    Likes Received:
    244
    Best Answers:
    0
    Trophy Points:
    0
    #12
    If you are making such a site that you know there'll be attempts to crack it, then your already spending much money, why not spend some more? If your just making another website on the internet, why bother? just make sure your site is safe...

    And your welcome for the plugin, here's a link to the wordpress site: http://wordpress.org/extend/plugins/login-lockdown/
     
    campolar, Aug 17, 2009 IP
  13. SunstarShop

    SunstarShop Peon

    Messages:
    582
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #13
    I think you should view the server log and see what is not normal!
     
    SunstarShop, Aug 17, 2009 IP
  14. Professional Dude

    Professional Dude Prominent Member

    Messages:
    6,261
    Likes Received:
    430
    Best Answers:
    0
    Trophy Points:
    330
    #14
    Does server log has info about login attempts?
     
    Professional Dude, Aug 17, 2009 IP
  15. campolar

    campolar Peon

    Messages:
    2,683
    Likes Received:
    244
    Best Answers:
    0
    Trophy Points:
    0
    #15
    It will show login attempts on the server itself, not the website
     
    campolar, Aug 17, 2009 IP
  16. j4k3yyy

    j4k3yyy Peon

    Messages:
    35
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Depends how you've got logging configured. By default on most linux/unix's you should at least be able to see who accessed what pages.
     
    j4k3yyy, Aug 17, 2009 IP
  17. ChrisMiller

    ChrisMiller Prominent Member

    Messages:
    1,934
    Likes Received:
    81
    Best Answers:
    0
    Trophy Points:
    315
    #17
    ChrisMiller, Aug 18, 2009 IP
  18. Susanjia

    Susanjia Banned

    Messages:
    226
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #18
    Maybe there are some software can do that.
     
    Susanjia, Aug 18, 2009 IP
  19. premiumscripts

    premiumscripts Peon

    Messages:
    1,062
    Likes Received:
    48
    Best Answers:
    0
    Trophy Points:
    0
    #19
    Err guys, if someone hacks your entire server, they can easily change the logs to remove all traces of them having been there.
     
    premiumscripts, Aug 19, 2009 IP
  20. campolar

    campolar Peon

    Messages:
    2,683
    Likes Received:
    244
    Best Answers:
    0
    Trophy Points:
    0
    #20
    But if he fails, we can know what was the attack, and we can just ban all IPs that did it...
     
    campolar, Aug 19, 2009 IP