Our server costs ~$56 per month to run. Please consider donating or becoming a Patron to help keep the site running. Help us gain new members by following us on Twitter and liking our page on Facebook!
Current time: April 25, 2024, 3:04 pm

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Hack The Forums
#1
Hack The Forums
I've been thinking of doing something like this for a long time. Whilst I try my best to secure the server and run vulnerability scans against our site, I don't really go into much depth with them. I was planning on putting aside a few days to do a proper penetration test on the site with various tools.

Then I thought it might be fun for some of our more knowledgeable members to get involved.

Here's how I envision it working:

1) I'll create a separate copy of the forums at some other address, but make it virtually identical to these ones (i.e. it will have all the same files and database). For security, I'll remove / scramble all user details from the database files, but otherwise it will be an exact copy.

2) People who want to take part will give me the IP address that they will be working from. I'll add these to a temporary whitelist so that our Intrusion Detection System does not automatically ban them when attacks are detected. These people will also have to accept an agreement stating that any vulnerabilities they find will not be published until a fix is in place, nor will they attempt to test the vulnerability on the main site.

3) At a specified time, I'll enable the whitelist and allow people to test for a certain period of time (probably a few days to a week).

4) The only attacks which will be forbidden are denial of service and those that actively change / delete content from the server / database.

5) During and after the test, I'll go through all reported issues, confirm and (attempt to) fix them, and then add the user's name to a "Hall of Fame" part of the site. The user will then be allowed to talk about their exploit freely.

So firstly, are there any members out there who would be interested? You don't necessarily need to have a background in hacking / penetration testing, but obviously knowledge of exploits would help. If people just want to try out hacking, you're welcome as well, but it would probably be more beneficial to go to other "hack this site" type websites instead.

If I get some interest, I'll write a more verbose explanation of what is and is not allowed. I obviously want to make it as open as possible, but I don't also want the server being bombarded with traffic from tools at the same time (we may have to schedule testing times per user).

- Tiberius
Reply
#2
RE: Hack The Forums
Applicants should write their expression of interest here?
Really? LOL
Reply
#3
RE: Hack The Forums
Or PM me. Either way.

Of course, don't post your IP address here...just indicate your interest.
Reply
#4
RE: Hack The Forums
(March 19, 2013 at 9:45 pm)Tiberius Wrote: Or PM me. Either way.

Of course, don't post your IP address here...just indicate your interest.

You can obtain our IP addresses if I'm correct.
Reply
#5
RE: Hack The Forums
(March 20, 2013 at 9:03 am)C3P0 Wrote: You can obtain our IP addresses if I'm correct.

Yes... But what Tiberius is saying is to not post them here so all the users can see them.
Reply
#6
RE: Hack The Forums
If I didn't have tons of course work to do and exams coming up, then I'd have the time for this... but I doubt I could do it just now. Tis a shame.

I study how to hack things, but when I actually get to hack stuff, I can't because of the damn course. Tongue We aren't usually allowed to do anything we do in the labs at home, since it would be pretty illegal. As I said, I doubt I'll have the time for it, but if I somehow manage to find some, then I'll let you know.
Cunt
Reply
#7
RE: Hack The Forums
(March 20, 2013 at 9:22 am)frankiej Wrote: If I didn't have tons of course work to do and exams coming up, then I'd have the time for this... but I doubt I could do it just now. Tis a shame.

I study how to hack things, but when I actually get to hack stuff, I can't because of the damn course. Tongue We aren't usually allowed to do anything we do in the labs at home, since it would be pretty illegal. As I said, I doubt I'll have the time for it, but if I somehow manage to find some, then I'll let you know.
If you get some free time I could set you up outside of the "regular" testing period. The more people who can participate the better.
Reply
#8
RE: Hack The Forums
It's been a quite few years since I did anything like this, and things have improved security wise since then, but I love a challenge Smile
Reply
#9
RE: Hack The Forums
I love a good necropost, especially when it's for something worthwhile Wink
Reply
#10
RE: Hack The Forums
The latest version of MyBB would be incredibly difficult to penetrate if all is in place. I've done my share of hacking into networks, Bluetooth connections with Linux, program exploits etc... I also am very familiar with PHP as we've discussed.

If I get time, I'll give it a shot but I'm not hopeful of much of an outcome
Reply



Possibly Related Threads...
Thread Author Replies Views Last Post
  [Serious] Future of the Forums (Discussion) Tiberius 130 20295 May 6, 2020 at 9:47 am
Last Post: The Grand Nudger
  Make Atheist Forums Great Again (Part 4) Tiberius 27 4875 April 27, 2019 at 3:44 pm
Last Post: Angrboda
  Make Atheist Forums Great Again (Part 1) Tiberius 201 27461 January 11, 2019 at 7:08 pm
Last Post: Cod
  Make Atheist Forums Great Again (Part 3) Forum Bot 33 6249 December 31, 2018 at 11:52 pm
Last Post: AFTT47
  [Serious] Make Atheist Forums Great Again (Part 2) Tiberius 81 11026 December 19, 2018 at 12:36 pm
Last Post: mlmooney89
  User Suggestions for Future of Atheist Forums Shell B 47 7536 November 30, 2018 at 12:39 am
Last Post: Tiberius
  Atheist Forums Financial Report 2017 Tiberius 12 3251 January 11, 2018 at 5:51 am
Last Post: Sal
  Cards Against Atheist Forums Tiberius 32 16109 September 27, 2017 at 5:07 pm
Last Post: Edwardo Piet
  Atheist Forums is now HTTPS only. Tiberius 19 3583 March 15, 2017 at 11:40 pm
Last Post: Autumnlicious
  Atheist Forums' 12 Days of Christmas Tiberius 19 4321 December 23, 2016 at 9:32 pm
Last Post: Catholic_Lady



Users browsing this thread: 1 Guest(s)