Excellent Everettg, Thanks
-
☆ A M B ☆
- 1,780 Posts
Wow Everett!
Those are both scary and brilliant all at the same time. Really nice though.
Now how do we prevent someone from uploading one of these without permission?
-
☆ A M B ☆
- 2,475 Posts
Frogabog: security is a huge topic, but the lesson here is that if someone has FTP or shell access to your site, you are hacked. I recommend the following as a short check-list:
1. Use un-guessable usernames for your site and its services
2. Use long and strong passwords that do not appear in any hacking dictionary, and make sure you do not use the same password on multiple sites!
3. Install and maintain intrusion detection counter-measures
And 4, I generally like to turn off FTP altogether and instead use SSH keyed logins instead since they are practically impervious to brute force hacks.
-
☆ A M B ☆
- 1,780 Posts
Thank you Everett. Do you have any tips for intrusion detection counter-measures?