Security Suggestion
 
Notifications
Clear all

Security Suggestion

21 Posts
9 Users
0 Reactions
12.2 K Views
 JenR
(@jenr)
Posts: 9
Active Member
 

No, it shouldn't, because they can't access those files anyway.

Cool.  :mrgreen:  Thanks Becca.

Jen


"A trifling matter, and fussy of me, but we all have our little ways." - Eeyore, The House at Pooh Corner

 
Posted : 26/08/2006 7:38 pm
(@lazuli)
Posts: 61
Trusted Member
 

Another suggestion.  From the logs I've been sent it looks like our hacker is finding sites using google and searching for "Powered by eFiction".

Hopefully I make sense here...  (I spent my day running a garage sale.)  Another thing,

I've been keeping an eye on my logs and I've begun seeing 404 errors from people looking for the default eFiction folders/directories.

(Mainly directories named "efiction" and variants of that.)

If you've used these names, it might be a good time for a rename.


I'm sorry, but due to my schedule, I am not available for commissions.

Blog | DA Account

 
Posted : 26/08/2006 11:57 pm
(@eyedam)
Posts: 64
Trusted Member
 

(Mainly directories named "efiction" and variants of that.)

If you've used these names, it might be a good time for a rename.

Well, I would suggest you think twice before changing your eFic folder name, as keep in mind that all the links on other websites (including Internet search engines) and the static links on your site to stories, authors' profiles etc. will become broken.

Also I think that a software's security should not really depend on wether the hacker knows where it is placed. Especially such an openly available and widely used software as "eFiction".


The wireless music box has no imaginable commercial value. Who would pay for a message sent to nobody in particular? (1920)

 
Posted : 27/08/2006 3:47 pm
(@carissa)
Posts: 791
Member Moderator
 

I agree with eyedam that some of these solutions are somewhat reactionary. No one wants to be hacked, but you've got to decide if the risk is worth the extra trouble, especially since doing things like changing the name of your efic folder is no guarantee that you won't be hacked in the future. The best protection you have is to make sure your software is up-to-date.


 
Posted : 27/08/2006 5:16 pm
 JenR
(@jenr)
Posts: 9
Active Member
 

I agree with eyedam that some of these solutions are somewhat reactionary. No one wants to be hacked, but you've got to decide if the risk is worth the extra trouble, especially since doing things like changing the name of your efic folder is no guarantee that you won't be hacked in the future. The best protection you have is to make sure your software is up-to-date.

Carissa, would you and Tammy possibly consider setting up some kind of notification email list that would send everyone who's interested a notice whenever a new patch is released?  You could even just have one specific thread for announcing all patches/updates (the post with the details on it could still be separate so people could comment on it if needed) and the people who wanted to be notified could subscribe to it.

I get over here fairly often and check, but it would be really helpful to get some kind of notification as soon as a new patch comes out.  Just a thought.

Jen


"A trifling matter, and fussy of me, but we all have our little ways." - Eeyore, The House at Pooh Corner

 
Posted : 27/08/2006 5:31 pm
(@carissa)
Posts: 791
Member Moderator
 

That is a good idea, and someone asked before. For the 3.0 release, the site itself will also be undergoing to major changes, and I will try to work that in. I'm also going to try to put the news into a feed so people can be informed that way as well. The RSS feed was already on my to-do list, and I will try to figure out a way to set up a mailing list, or integrate the news with a forum thread so that people may subscribe and be notified via email if they choose.


 
Posted : 27/08/2006 5:42 pm
Page 2 / 2
Share: