Our server costs ~$56 per month to run. Please consider donating or becoming a Patron to help keep the site running. Help us gain new members by following us on Twitter and liking our page on Facebook!
Current time: February 2, 2025, 10:52 am

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Hack The Forums
#1
Hack The Forums
I've been thinking of doing something like this for a long time. Whilst I try my best to secure the server and run vulnerability scans against our site, I don't really go into much depth with them. I was planning on putting aside a few days to do a proper penetration test on the site with various tools.

Then I thought it might be fun for some of our more knowledgeable members to get involved.

Here's how I envision it working:

1) I'll create a separate copy of the forums at some other address, but make it virtually identical to these ones (i.e. it will have all the same files and database). For security, I'll remove / scramble all user details from the database files, but otherwise it will be an exact copy.

2) People who want to take part will give me the IP address that they will be working from. I'll add these to a temporary whitelist so that our Intrusion Detection System does not automatically ban them when attacks are detected. These people will also have to accept an agreement stating that any vulnerabilities they find will not be published until a fix is in place, nor will they attempt to test the vulnerability on the main site.

3) At a specified time, I'll enable the whitelist and allow people to test for a certain period of time (probably a few days to a week).

4) The only attacks which will be forbidden are denial of service and those that actively change / delete content from the server / database.

5) During and after the test, I'll go through all reported issues, confirm and (attempt to) fix them, and then add the user's name to a "Hall of Fame" part of the site. The user will then be allowed to talk about their exploit freely.

So firstly, are there any members out there who would be interested? You don't necessarily need to have a background in hacking / penetration testing, but obviously knowledge of exploits would help. If people just want to try out hacking, you're welcome as well, but it would probably be more beneficial to go to other "hack this site" type websites instead.

If I get some interest, I'll write a more verbose explanation of what is and is not allowed. I obviously want to make it as open as possible, but I don't also want the server being bombarded with traffic from tools at the same time (we may have to schedule testing times per user).

- Tiberius
Reply



Messages In This Thread
Hack The Forums - by Tiberius - March 19, 2013 at 9:07 pm
RE: Hack The Forums - by Lion IRC - March 19, 2013 at 9:43 pm
RE: Hack The Forums - by Tiberius - March 19, 2013 at 9:45 pm
RE: Hack The Forums - by C3P0 - March 20, 2013 at 9:03 am
RE: Hack The Forums - by LastPoet - March 20, 2013 at 9:13 am
RE: Hack The Forums - by frankiej - March 20, 2013 at 9:22 am
RE: Hack The Forums - by Tiberius - March 20, 2013 at 9:31 am
RE: Hack The Forums - by StuW - August 4, 2013 at 7:38 am
RE: Hack The Forums - by Napoléon - August 4, 2013 at 7:57 am
RE: Hack The Forums - by wolf39us - August 4, 2013 at 11:49 am

Possibly Related Threads...
Thread Author Replies Views Last Post
  [Serious] Future of the Forums (Discussion) Tiberius 130 26319 May 6, 2020 at 9:47 am
Last Post: The Grand Nudger
  Make Atheist Forums Great Again (Part 4) Tiberius 27 6219 April 27, 2019 at 3:44 pm
Last Post: Angrboda
  Make Atheist Forums Great Again (Part 1) Tiberius 201 35105 January 11, 2019 at 7:08 pm
Last Post: Cod
  Make Atheist Forums Great Again (Part 3) Forum Bot 33 7497 December 31, 2018 at 11:52 pm
Last Post: AFTT47
  [Serious] Make Atheist Forums Great Again (Part 2) Tiberius 81 14175 December 19, 2018 at 12:36 pm
Last Post: mlmooney89
  User Suggestions for Future of Atheist Forums Shell B 47 9536 November 30, 2018 at 12:39 am
Last Post: Tiberius
  Atheist Forums Financial Report 2017 Tiberius 12 3840 January 11, 2018 at 5:51 am
Last Post: Sal
  Cards Against Atheist Forums Tiberius 32 17746 September 27, 2017 at 5:07 pm
Last Post: Edwardo Piet
  Atheist Forums is now HTTPS only. Tiberius 19 4533 March 15, 2017 at 11:40 pm
Last Post: Autumnlicious
  Atheist Forums' 12 Days of Christmas Tiberius 19 5193 December 23, 2016 at 9:32 pm
Last Post: Catholic_Lady



Users browsing this thread: 3 Guest(s)