|
|||
|
I and a few other sites have been targeted by someone who says he is a hacker and he crashes the 123flash chat rooms. Why are people being able to crash the chat rooms and disconnect everyone chatting?
Is anyone looking to get to the root of how someone is able to do this? This is a major vulnerability that needs to be fixed. If this cant be fixed soon 123flash chat will be useless to me and anyone if they are constantly been crashed by anyone with a bit of knowledge. I would appreciate it very much that this "issue" gets looked at and fixed asap. I know im not the only one complaining about this one issue. |
|
|||
|
First of all, 123flashchat is based on Java server which is very stable and secure, also very hard to hack.
And we're keeping fixing bugs to make it even harder. Secondly we're sorry about the terrible issues you're experiencing, and we should take actions together to fight against the hackers. For host buyers, Be sure to create only one super admin account, since the super admin has full control over the chat room, and then assign more admins and mods to help the management. And keep your billing email safe, cause that's an important way for us to recognize you and verify your identity. For license buyers, More or less the same, and do protect your chat server, especially the root access. |
|
|||
|
Quote:
|
|
|||
|
>For license buyers,
>More or less the same, and do protect your chat server, especially the root access. Something I don't understand then is why no one has yet to reply to my post asking for tips on securing FS. Not the OS but FS specifically. Are there ANY steps other than the admin account which should be taken? I switched my database over to mysql so asked Support what I should use for permissions. Since I could not find any information on this, I went ahead and set the permissions to; Select,Insert,Update,Delete,Create,Drop,Index,Alte r,Create temp,Lock FS seems to work fine with these permissions but I wanted to confirm with Support. Support told me to turn ALL permissions on which is a total security risk. You should have a document that clearly shows settings such as this along with other basic security settings that would help license buyers. Mike |
|
|||
|
It's not an easy question to answer.
applebees coupons vegetable chopper gas furnace prices shrimp scampi recipe |
|
|||
|
Quote:
Someone here must know. In the meantime, I've done my own testing to limit the permissions and things work fine as far as I can tell. |
|
|||
|
Have you looked to see if they have access to your server and not the chat program?
I seem to recall coming across the admin password being open text in a file somewhere in the directory tree. However, I could be thinking of another piece of software. If you are on Linux, do a netstat for example, see if you can see someone on your ssh port or something else that perhaps you've left open or that they have set up a back door on. |
![]() |
Was this information helpful? Yes No
| Thread Tools | |
| Display Modes | |
|
|