Black Hat Forum
Go Back   Black Hat Forum > BlackHatWorld Forum > Forum Suggestions & Feedback

Forum Suggestions & Feedback Something you like or don't like about the forum? Have some suggestions that might make BHW a better place? Please Let us know!

Search
 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-09-2008, 01:08 AM
Newbie
 
Join Date: May 2008
Posts: 9
Thanks: 0
Thanked 0 Times in 0 Posts
Activity: 0%
Longevity: 17%
Today: 0/5
Default How is the Firewall Script working out?

I see BHW has the Firewall Script installed. How is that working out? Has it been able to stop any attacks that you know of? I was thinking of buying it myself and would love some thoughts on it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-09-2008, 07:37 AM
trophaeum's Avatar
Executive VIP
 
Join Date: Dec 2007
Posts: 640
Thanks: 9
Thanked 105 Times in 32 Posts
Activity: 48%
Longevity: 30%
Today: 2/5
Default Re: How is the Firewall Script working out?

you mean the fact that if someone puts the keyword s*y*s*t*e*m in a post or 1 of a hundred other things it likes to block the post? or that it doesnt play properly with suhosin and keeps blocking people randomly for nulls in their raw cookie data? i could go on but im stopping for now, its still in early versions but personally this is not the place i would put a defense line up, get a better codebase and lockdown the server properly

i do think it can work for some people when setup right but i think for vb on here its a pita... time and new versions will tell i guess though
__________________
A SQL query goes into a bar, walks up to two tables and says, "Can I join you?"
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-09-2008, 07:46 AM
BANNED
 
Join Date: Jun 2008
Posts: 305
Thanks: 0
Thanked 11 Times in 6 Posts
Activity: 0%
Longevity: 16%
Today: 0/5
Default Re: How is the Firewall Script working out?

i glanced over the firewall script site and i have to say that as someone who knows how to exploit php scripts I am skeptical. a good test would be to install an old version of a script that has a lot of security holes and see if intrusion attempts get blocked.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 06-09-2008, 07:50 AM
foxler's Avatar
Jr. VIP
 
Join Date: Mar 2008
Posts: 314
Thanks: 62
Thanked 90 Times in 24 Posts
Activity: 32%
Longevity: 24%
Today: 0/5
Default Re: How is the Firewall Script working out?

Quote:
Originally Posted by Ic3m4n View Post
I see BHW has the Firewall Script installed. How is that working out? Has it been able to stop any attacks that you know of? I was thinking of buying it myself and would love some thoughts on it.
I would recommend something thats better built. I would suggest looking into modsecurity which has to be installed on the server itself but does a way better job
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 06-09-2008, 08:00 AM
Essential Clix's Avatar
Administrator
 
Join Date: Jul 2007
Location: USA
Posts: 3,182
Thanks: 361
Thanked 944 Times in 304 Posts
Activity: 76%
Longevity: 43%
Today: 4/5
Default Re: How is the Firewall Script working out?

Yeah, trust me firewallscript is just one line of defense. Trophaeum has taken the proper steps to setup the "proper" security Nothing's perfect, of course, but I think Troph's done a damn fine job.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 06-09-2008, 08:20 AM
trophaeum's Avatar
Executive VIP
 
Join Date: Dec 2007
Posts: 640
Thanks: 9
Thanked 105 Times in 32 Posts
Activity: 48%
Longevity: 30%
Today: 2/5
Default Re: How is the Firewall Script working out?

ug, theres still more random things to go dude lol

security, the never ending uphill battle... *sigh* vbulletin certainly doesnt help that matter either!
__________________
A SQL query goes into a bar, walks up to two tables and says, "Can I join you?"
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 06-09-2008, 08:24 AM
trophaeum's Avatar
Executive VIP
 
Join Date: Dec 2007
Posts: 640
Thanks: 9
Thanked 105 Times in 32 Posts
Activity: 48%
Longevity: 30%
Today: 2/5
Default Re: How is the Firewall Script working out?

Quote:
Originally Posted by foxler View Post
I would recommend something thats better built. I would suggest looking into modsecurity which has to be installed on the server itself but does a way better job
btw, mod_security is VERY flawed, it does NOT process the post data etc in the same way as each scripting language, it really is a BAD solution, i refuse to install it on any server, its just a bad joke and EATS resources, stay away, far far away
__________________
A SQL query goes into a bar, walks up to two tables and says, "Can I join you?"
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 06-09-2008, 04:26 PM
YoungGuns's Avatar
Jr. VIP
 
Join Date: May 2008
Location: Tennessee, US
Posts: 278
Thanks: 71
Thanked 29 Times in 21 Posts
Activity: 55%
Longevity: 16%
Today: 5/5
Default Re: How is the Firewall Script working out?

I can't post new threads because of this firewall script that I very much need to make, and sometimes I can't pm people. It's making me mad.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 06-09-2008, 05:20 PM
trophaeum's Avatar
Executive VIP
 
Join Date: Dec 2007
Posts: 640
Thanks: 9
Thanked 105 Times in 32 Posts
Activity: 48%
Longevity: 30%
Today: 2/5
Default Re: How is the Firewall Script working out?

Quote:
Originally Posted by YoungGuns View Post
I can't post new threads because of this firewall script that I very much need to make, and sometimes I can't pm people. It's making me mad.
please pm me any errors that you get with it under normal use, we are trying to set it 'right' (at this point personally i want to take to it with a whacking stick and disable it though but thats just me)
__________________
A SQL query goes into a bar, walks up to two tables and says, "Can I join you?"
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 06-10-2008, 05:30 AM
YoungGuns's Avatar
Jr. VIP
 
Join Date: May 2008
Location: Tennessee, US
Posts: 278
Thanks: 71
Thanked 29 Times in 21 Posts
Activity: 55%
Longevity: 16%
Today: 5/5
Default Re: How is the Firewall Script working out?

Hate to bug ya'll, but I still can't post new threads.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 06-10-2008, 05:34 AM
YoungGuns's Avatar
Jr. VIP
 
Join Date: May 2008
Location: Tennessee, US
Posts: 278
Thanks: 71
Thanked 29 Times in 21 Posts
Activity: 55%
Longevity: 16%
Today: 5/5
Default Re: How is the Firewall Script working out?

I just figured out it won't let me post my thread because the thread had a code in it. So I just posted the thread without the code.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 06-10-2008, 05:49 AM
BANNED
 
Join Date: Jun 2008
Posts: 305
Thanks: 0
Thanked 11 Times in 6 Posts
Activity: 0%
Longevity: 16%
Today: 0/5
Default Re: How is the Firewall Script working out?

okay heres the deal with the firewall script the way i see it. I have done some research and I think you guys should uninstall it. It's going to cause more headaches than good (which its already doing). The likelihood that the firewall script will prevent an attack is minimal. the best defense you have is keeping the forum and server software up to date.

Some days ago when i first questioned the firewall script i did a little digging around on this site and discovered that the forum code was out of date and there were people trying to develope an exploit for a bug (which turned out to be nothing big but still).

You guys don't need the firewall script. What you need to do is check for updates to vbulletin and vbul addons you have installed on a daily basis. Also, you need to edit your forum code to not display the vbulletin version info. This is a horrible thing. In fact, a good security measure would have been for you to remove any and all bannering info from the beginning.

As it stands right now... Lets say a major security hole comes out... You can use google to search for phrases in sourcecode. Go ahead right now and right click this page, view the source, and you will see in the html head: vBulletin 3.7.1 .

If an exploit were to come out right now for vbulletin and was left unpatched for more than an hour there is a good chance you would have a very serious problem on your hands.

Heres a good fix for that.. Connect to the forum FTP and download the entire site to a folder. Use the program "advanced find and replace" to find any instance of the phrase "vBulletin 3.7.1" and replace with the phrase "BHW Forum."

You should also find and replace the same term in the mysql database (can be done from with phpmyadmin). Do this each time you upgrade the forum and you will be much better off.

Also, you have a forum thread for php and other server side programming.. Use it to your advantage. Even if a vulnerability gets released that there isnt an official patch for yet, we could come up with quick patches for you. Its really not hard.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 06-10-2008, 08:41 AM
trophaeum's Avatar
Executive VIP
 
Join Date: Dec 2007
Posts: 640
Thanks: 9
Thanked 105 Times in 32 Posts
Activity: 48%
Longevity: 30%
Today: 2/5
Default Re: How is the Firewall Script working out?

Quote:
Originally Posted by jaeden View Post
okay heres the deal with the firewall script the way i see it. I have done some research and I think you guys should uninstall it. It's going to cause more headaches than good (which its already doing). The likelihood that the firewall script will prevent an attack is minimal. the best defense you have is keeping the forum and server software up to date.

Some days ago when i first questioned the firewall script i did a little digging around on this site and discovered that the forum code was out of date and there were people trying to develope an exploit for a bug (which turned out to be nothing big but still).

You guys don't need the firewall script. What you need to do is check for updates to vbulletin and vbul addons you have installed on a daily basis. Also, you need to edit your forum code to not display the vbulletin version info. This is a horrible thing. In fact, a good security measure would have been for you to remove any and all bannering info from the beginning.

As it stands right now... Lets say a major security hole comes out... You can use google to search for phrases in sourcecode. Go ahead right now and right click this page, view the source, and you will see in the html head: vBulletin 3.7.1 .

If an exploit were to come out right now for vbulletin and was left unpatched for more than an hour there is a good chance you would have a very serious problem on your hands.

Heres a good fix for that.. Connect to the forum FTP and download the entire site to a folder. Use the program "advanced find and replace" to find any instance of the phrase "vBulletin 3.7.1" and replace with the phrase "BHW Forum."

You should also find and replace the same term in the mysql database (can be done from with phpmyadmin). Do this each time you upgrade the forum and you will be much better off.

Also, you have a forum thread for php and other server side programming.. Use it to your advantage. Even if a vulnerability gets released that there isnt an official patch for yet, we could come up with quick patches for you. Its really not hard.
another day im treated like a n00b yet again *sigh* the forum is dave's, dave bought firewall script, its his choice what we do with it, he wanted to see if we could work with it, it was doing ok however now its going downhill more and more by the day so it is likely to get nuked over the next few days

im gonna walk away from this thread now before i say something that i may regret
__________________
A SQL query goes into a bar, walks up to two tables and says, "Can I join you?"
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!