| Author |
Message |
|
Thrawn
Commander
Joined: Fri Aug 20, 2004 2:00 am Posts: 1801 Location: Outer Rims
|
Sorry Vulcan, to make my post more clearer. I was trying to get to your main page, not the forum, to get a snapshot to add your site to the video I'm working on. You are the only one left. There is no rush, just let me know when I can get to it for a snap of it.
It's accessing the main page where I get the challenge response for authentication.
_________________ -Thrawn
But risk has always been an inescapable part of warfare.
--
Knight to Queen's Bishop 3
|
| Wed Dec 13, 2006 8:05 pm |
|
 |
|
Singularity
Veteran Op
Joined: Thu Jun 02, 2005 2:00 am Posts: 5558 Location: USA
|
Main page is IIS. Forum is Apache. Apache, the port 99, is not effected by this at all. It's IIS that's fudging up. Nobody can access / on the server. Sometimes the browser will cache this and won't present the auth challenge again, sometimes it won't and we'll be asked to enter a username/password. Result is the same.
_________________ May the unholy fires of corbomite ignite deep within the depths of your soul...
1. TWGS server @ twgs.navhaz.com 2. The NavHaz Junction - Tradewars 2002 Scripts, Resources and Downloads 3. Open IRC chat @ irc.freenode.net:6667 #twchan 4. Parrothead wrote: Jesus wouldn't Subspace Crawl.
*** SG memorial donations via paypal to: dpocky68@booinc.com
|
| Wed Dec 13, 2006 11:28 pm |
|
 |
|
Vulcan
Gameop
Joined: Fri Sep 03, 2004 2:00 am Posts: 2041 Location: Acworth, Georgis USA
|
kk Thrawn, I will look into it then and fix it.
_________________ Vulcan's Forge v1 TWGS telnet://vulcansforge.homeip.net:2002 v2 TWGS telnet://vulcansforge.homeip.net:23 Forum and site down for now. my Email is vulcan219@comcast.net now
|
| Thu Dec 14, 2006 2:14 am |
|
 |
|
Vulcan
Gameop
Joined: Fri Sep 03, 2004 2:00 am Posts: 2041 Location: Acworth, Georgis USA
|
Okay it is fixed now Thrawn, try it now. When we did all the security fixes it changed the permission of the website. now it is fixed
_________________ Vulcan's Forge v1 TWGS telnet://vulcansforge.homeip.net:2002 v2 TWGS telnet://vulcansforge.homeip.net:23 Forum and site down for now. my Email is vulcan219@comcast.net now
|
| Thu Dec 14, 2006 3:48 am |
|
 |
|
Thrawn
Commander
Joined: Fri Aug 20, 2004 2:00 am Posts: 1801 Location: Outer Rims
|
Vulcan wrote: Okay it is fixed now Thrawn, try it now. When we did all the security fixes it changed the permission of the website. now it is fixed
It worked. Thank you very much. I now have a complete list of sites and will put the video together tomorrow. I hope it will be to all the SysOp's liking. It will show their main page and URL, and the idea is to get the sites distributed out to the public to draw in a playerbase.
_________________ -Thrawn
But risk has always been an inescapable part of warfare.
--
Knight to Queen's Bishop 3
|
| Thu Dec 14, 2006 5:42 am |
|
 |
|
earth
Ambassador
Joined: Fri Feb 23, 2001 3:00 am Posts: 331 Location: USA
|
For all those who run servers out on the internet, you MUST make your server's secure.
Here is how:
If you install Windows, you have an account named Administrator. Well, know that i know the userId, i can sit and pound on your machine all day long trying to crack the password. This is what was happening to Vulcan's Forge. What i did it I set up user accounts for all users with administrator group rights and then I renamed the Administrator account so that the hacker now needs 2 pieces of information which makes it much harder since the username is now random to them.
I also disabled all open user accounts and shut down any non-used public services. I guess the IIS account was linked to the Administrator account somehow. It should not have been and Vulcan fixed it.
You can see if you are being attacked by viewing the Security section of the Event Viewer.
earth.
_________________ ATTAC TCP/IP Helper
http://www.tw-attac.com
TWXSync Server (realtime data synchronization)
http://www.tw-attac.com/twxsync.html
|
| Thu Dec 14, 2006 6:17 pm |
|
 |
|
Cerne
Gameop
Joined: Sun Oct 08, 2006 2:00 am Posts: 991
|
There is a lockdown tool for IIS 6.0.
Here is the link to the tool
Cernnunos
_________________ "All warfare is based on deception..." - Art of War "Time will tell all tales" - SG Any advanced tactic in TW is indistinguishable from cheating.
|
| Thu Dec 14, 2006 8:00 pm |
|
 |
|
Vulcan
Gameop
Joined: Fri Sep 03, 2004 2:00 am Posts: 2041 Location: Acworth, Georgis USA
|
Cernnunos wrote:
There is a lockdown tool for IIS 6.0. Here is the link <span style="text-decoration: underline;">to the tool</span>Cernnunos
My server already has that tool, part of it, the tool is for if you upgrade from another IIS version to 6.0 My server came with 6.0 and the tool already installed.
But thanks for the info, cause someone may need it as well Good work there.
_________________ Vulcan's Forge v1 TWGS telnet://vulcansforge.homeip.net:2002 v2 TWGS telnet://vulcansforge.homeip.net:23 Forum and site down for now. my Email is vulcan219@comcast.net now
|
| Thu Dec 14, 2006 8:59 pm |
|
 |
|
River Rat
Chief Warrant Officer
Joined: Sat Feb 24, 2001 3:00 am Posts: 145
|
earth wrote: For all those who run servers out on the internet, you MUST make your server's secure.
Here is how:
If you install Windows, you have an account named Administrator. Well, know that i know the userId, i can sit and pound on your machine all day long trying to crack the password. This is what was happening to Vulcan's Forge. What i did it I set up user accounts for all users with administrator group rights and then I renamed the Administrator account so that the hacker now needs 2 pieces of information which makes it much harder since the username is now random to them.
I also disabled all open user accounts and shut down any non-used public services. I guess the IIS account was linked to the Administrator account somehow. It should not have been and Vulcan fixed it.
You can see if you are being attacked by viewing the Security section of the Event Viewer. earth.
Yes we had to do the same thing last summer when Alien Base was being hacked. They never got in but they sure spammed it
River Rat
_________________ twgs.alienbase.net www.alienbase.net
|
| Fri Dec 15, 2006 1:46 pm |
|
 |
|
Thrawn
Commander
Joined: Fri Aug 20, 2004 2:00 am Posts: 1801 Location: Outer Rims
|
earth wrote: For all those who run servers out on the internet, you MUST make your server's secure.
Here is how:
If you install Windows, you have an account named Administrator. Well, know that i know the userId, i can sit and pound on your machine all day long trying to crack the password. This is what was happening to Vulcan's Forge. What i did it I set up user accounts for all users with administrator group rights and then I renamed the Administrator account so that the hacker now needs 2 pieces of information which makes it much harder since the username is now random to them.
I also disabled all open user accounts and shut down any non-used public services. I guess the IIS account was linked to the Administrator account somehow. It should not have been and Vulcan fixed it.
You can see if you are being attacked by viewing the Security section of the Event Viewer. earth.
Good point Earth. Most people don't disable guest account, and leave Administrator as is. That just invites headaches down the road. Keeping services open that don't need to be also invites trouble. Also a good idea to create a backup Admin account, in case you forget the original one. Otherwise you may have to redo the entire OS.
_________________ -Thrawn
But risk has always been an inescapable part of warfare.
--
Knight to Queen's Bishop 3
|
| Fri Dec 15, 2006 1:58 pm |
|
 |
|