Language: ChineseGermanSpanishFrenchDutchItalianRussian
123 Flash Chat Forums

Go Back   TOPCMM Community > 123 Flash Chat Server Software > 123 Flash Chat Support

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-02-2011, 07:54 PM
UCZ UCZ is offline
Junior Member
 
Join Date: Jul 2011
Posts: 14
Exclamation Why can people crash the chat rooms?

I and a few other sites have been targeted by someone who says he is a hacker and he crashes the 123flash chat rooms. Why are people being able to crash the chat rooms and disconnect everyone chatting?

Is anyone looking to get to the root of how someone is able to do this?

This is a major vulnerability that needs to be fixed. If this cant be fixed soon 123flash chat will be useless to me and anyone if they are constantly been crashed by anyone with a bit of knowledge. I would appreciate it very much that this "issue" gets looked at and fixed asap. I know im not the only one complaining about this one issue.
Reply With Quote
  #2 (permalink)  
Old 08-03-2011, 01:38 AM
UCZ UCZ is offline
Junior Member
 
Join Date: Jul 2011
Posts: 14
Default

I was told is not the software is the server that has been targeted and thats why they are able to disconnect the users. Find a way to protect the server against DDOS please.
Reply With Quote
  #3 (permalink)  
Old 08-03-2011, 08:39 AM
Administrator
 
Join Date: Dec 2008
Posts: 577
Default

First of all, 123flashchat is based on Java server which is very stable and secure, also very hard to hack.
And we're keeping fixing bugs to make it even harder.

Secondly we're sorry about the terrible issues you're experiencing, and we should take actions together to fight against the hackers.

For host buyers,
Be sure to create only one super admin account, since the super admin has full control over the chat room, and then assign more admins and mods to help the management.
And keep your billing email safe, cause that's an important way for us to recognize you and verify your identity.

For license buyers,
More or less the same, and do protect your chat server, especially the root access.
Reply With Quote
  #4 (permalink)  
Old 08-03-2011, 11:01 AM
UCZ UCZ is offline
Junior Member
 
Join Date: Jul 2011
Posts: 14
Default

Quote:
Originally Posted by admin View Post
First of all, 123flashchat is based on Java server which is very stable and secure, also very hard to hack.
And we're keeping fixing bugs to make it even harder.

Secondly we're sorry about the terrible issues you're experiencing, and we should take actions together to fight against the hackers.

For host buyers,
Be sure to create only one super admin account, since the super admin has full control over the chat room, and then assign more admins and mods to help the management.
And keep your billing email safe, cause that's an important way for us to recognize you and verify your identity.

For license buyers,
More or less the same, and do protect your chat server, especially the root access.
I agree 100%. Thank you. Im sure you are trying to find a way to protect your server against these attacks.
Reply With Quote
  #5 (permalink)  
Old 08-07-2011, 02:59 AM
Senior Member
 
Join Date: May 2011
Posts: 214
Default

>For license buyers,
>More or less the same, and do protect your chat server, especially the root access.

Something I don't understand then is why no one has yet to reply to my post asking for tips on securing FS. Not the OS but FS specifically. Are there ANY steps other than the admin account which should be taken?

I switched my database over to mysql so asked Support what I should use for permissions.
Since I could not find any information on this, I went ahead and set the permissions to;

Select,Insert,Update,Delete,Create,Drop,Index,Alte r,Create temp,Lock

FS seems to work fine with these permissions but I wanted to confirm with Support. Support told me to turn ALL permissions on which is a total security risk.

You should have a document that clearly shows settings such as this along with other basic security settings that would help license buyers.

Mike
Reply With Quote
  #6 (permalink)  
Old 08-29-2011, 05:20 PM
Senior Member
 
Join Date: May 2011
Posts: 214
Default

I am (somewhat) surprised that no one in Support wants to answer this important question.
Reply With Quote
  #7 (permalink)  
Old 09-14-2011, 05:42 AM
Junior Member
 
Join Date: Feb 2011
Posts: 2
Default

It's not an easy question to answer.

applebees coupons vegetable chopper gas furnace prices shrimp scampi recipe
Reply With Quote
  #8 (permalink)  
Old 09-15-2011, 02:14 PM
Senior Member
 
Join Date: May 2011
Posts: 214
Default

Quote:
Originally Posted by kswaby10 View Post
It's super easy. They should know what the software needs for access to the database. I suspect they never wrote it but have it outsourced for themselves by another company which is why they are so slow to respond or not respond at times.

Someone here must know. In the meantime, I've done my own testing to limit the permissions and things work fine as far as I can tell.
Reply With Quote
  #9 (permalink)  
Old 09-26-2011, 04:52 PM
Junior Member
 
Join Date: Sep 2011
Posts: 1
Default Same problem

I'm being crashed and can't figure out how to resolve it.

Tried recommendations from support. They are back in instantly screwing things up.

Need some specific suggestions.
Reply With Quote
  #10 (permalink)  
Old 09-26-2011, 06:41 PM
Senior Member
 
Join Date: May 2011
Posts: 214
Default

Have you looked to see if they have access to your server and not the chat program?
I seem to recall coming across the admin password being open text in a file somewhere in the directory tree.
However, I could be thinking of another piece of software.

If you are on Linux, do a netstat for example, see if you can see someone on your ssh port or something else that perhaps you've left open or that they have set up a back door on.
Reply With Quote
Reply

Was this information helpful?    Yes No



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:42 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.