PDA

View Full Version : Server Outage tonight 10/13! (not just the board)



Don Tomas
12-12-2007, 03:33 PM
There is a security issue I need to address. You won't even see a closed board message since the webserver won't be running, hence why I am posting this message here.

I will move the message tomorrow so it won't be up top (in this section) forever.

It will start around midnight EST!


Note: Something came up family related last night and I got home too late to start. I will be doing this tonight at midnight!

Jimmydr
12-12-2007, 03:39 PM
For how long?

Don Tomas
12-12-2007, 03:50 PM
Probably 1-2 hours.

You won't even get a 404 error! You will get IE's (or whatever browser you use) not found error.

SJG
12-12-2007, 04:47 PM
Is it the new Microsoft Security update requiring a reboot?

Don Tomas
12-12-2007, 04:49 PM
Is it the new Microsoft Security update requiring a reboot?

The server doesn't run on Microsloth!

SJG
12-12-2007, 05:18 PM
but, oddly, it still needs to be rebooted for security reasons....

Don Tomas
12-13-2007, 11:28 AM
but, oddly, it still needs to be rebooted for security reasons....

True but if it was Microsloth this would be a weekly thing, rather then 8-12 months!:rofl:

Don Tomas
12-14-2007, 09:45 AM
Sorry everyone it took a little longer then expected.

Actually I need to do a few more things, probably this weekend. But will let everyone get their fix for now.

Hunter
12-14-2007, 09:49 AM
Jimmy actually worked this morning. His boss is thrilled.

knotty
12-14-2007, 05:19 PM
did the site go down a couple hours ago? i tried getting on a couple of times, but it wasn't going through?

Jimmydr
12-14-2007, 07:25 PM
did the site go down a couple hours ago? i tried getting on a couple of times, but it wasn't going through?


Yes it was down for about 45 minutes.

Coolhand
12-16-2007, 02:25 AM
Don Tomas,
One of the new security tools that I think you will like is an Ip unmasker.This will help for blocking open proxy it has helped me a ton.

Don Tomas
12-16-2007, 12:39 PM
Don Tomas,
One of the new security tools that I think you will like is an Ip unmasker.This will help for blocking open proxy it has helped me a ton.

Thanks, I just checked it out, it looks like it is proprietary for phpBB forum which won't help us. We have a dedicated server so I actually add bad IPs directly to the firewall as I catch them doing something bad on the server like scanning directories, etc. As for banning for life from the board itself, well if they can't even load the web page, they can't log into the board either.

Not that it matters since I already did it, but the security update was for Apache, the webserver itself.

Coolhand
12-17-2007, 02:18 AM
They have a code for vbulletin as well, but I forget where I saw the code.I said this because I have read this is what alot of hackers are using these days.

Don Tomas
12-17-2007, 01:19 PM
They have a code for vbulletin as well, but I forget where I saw the code.I said this because I have read this is what alot of hackers are using these days.

I just did a search on Google and on vBulletin.org where addons are posted, both came up negative. If you recall where you saw it let me know thanks.

I could also go around and collect known malicious use proxies and just add then to the firewall but honestly I wouldn't want to ban every proxy server out there since they can be used for good reasons, such as accessing this site from less then friendly countries like China/Cuba/etc. or even from work places with blocking software looking at headers.

Don Tomas
12-17-2007, 09:53 PM
We have a dedicated server so I actually add bad IPs directly to the firewall as I catch them doing something bad on the server like scanning directories, etc.

With this thread being current I couldn't believe what I just found in the logs.

One of our members scanning directories! I sent a (not so nice) PM just to make sure it ain't a trojan he picked up when he opened a hot file called "BritneySpearsNaked.exe" or something.

Coolhand
12-18-2007, 01:09 PM
I told you there's alot of this crap going around. I have spoken with a few other site admins and they are saying the same thing.