Security
Posted: 29 April 2007 03:29 PM   [ Ignore ]  
Lab Assistant
Avatar
RankRank
Total Posts:  124
Joined  12-31-2005

Just wondering ...

Is there a security advantage in using a multiple domain set-up EE where the main EE install is placed in some nonsensical domain (or subdomain) .. [eg. i3j6b.com] with the .htaccess (“deny from all .. allow allmydomains.com”) modified so that ONLY my other domain(s) can have access to it.

I can’t remember whose site, but there were a couple of “under development” sites I have seen from people here who have links to a “You Have been Hacked” page ..

I’ve actually been using an .htaccess protected subdomain which holds all of my images and css files and I’ve gotten a whole lot of 403’s and 500’s in the stats from some very funny looking domains excaim 

There were also a lot of people looking for my “system” directory, but I have a system directory with .htaccess protection .. the real system directory is called something like “b5j4o7i7e7” cool grin

Profile
 
 
Posted: 30 April 2007 03:52 AM   [ Ignore ]   [ # 1 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  768
Joined  03-16-2002

Obfuscating directories and subdomains does add some additional level of security - but it all depends on the weakest part of the chain. If, for example, the generated image, download and CSS paths reveal an obfuscated directory, it will be worthless. So, it all depends on (1) your setup, (2) your definition of “security” and (3) the enemies and risks you try to defeat. Obfuscation helps best against humans, even well against dictionary attacks, but not against brute force attacks.

That said, I’d like to add that I’d doubt that EE was the prime reason for any defacements - as far as I remember, only one major security problem was discovered in EE since the first release ... and that one was based on a common library and hit other CMS as well. Most “hacks” I know of happened due to problems in the server configuration or were based on other software packages installed that had security flaws. But maybe the EE staff will comment on that.

Of course, maintaining the EE installation, other software that is installed and the server configuration is the major task regarding security.

Profile
 
 
Posted: 01 May 2007 11:36 AM   [ Ignore ]   [ # 2 ]  
Lab Technician
Avatar
RankRankRankRank
Total Posts:  1472
Joined  08-28-2003
tulkul - 29 April 2007 03:29 PM

Just wondering ...

Is there a security advantage in using a multiple domain set-up EE where the main EE install is placed in some nonsensical domain (or subdomain) .. [eg. i3j6b.com] with the .htaccess (“deny from all .. allow allmydomains.com”) modified so that ONLY my other domain(s) can have access to it.

In a word, “not much.” Wait. That’s two words, so it’s twice the security. Every little bit helps, though running EE from an ultra obscure domain or subdomain probably won’t make much difference in most security issues. EE itself is quite secure from outside intrusion, so you’re more likely to have a problem from the server side.

I can’t remember whose site, but there were a couple of “under development” sites I have seen from people here who have links to a “You Have been Hacked” page ..

I’ve actually been using an .htaccess protected subdomain which holds all of my images and css files and I’ve gotten a whole lot of 403’s and 500’s in the stats from some very funny looking domains excaim 

There were also a lot of people looking for my “system” directory, but I have a system directory with .htaccess protection .. the real system directory is called something like “b5j4o7i7e7” cool grin

Renaming the /system directory provides about as much security as you can get without going totally paranoid. Of course, if everyone is out to get you, then paranoia is the right attitude.

Again, most hacks will come from the server side so make sure permissions are what they should be on the EE files.

 Signature 

RonnieMc

Honolulu, HI USA

HomeMac360

Profile
 
 
   
 
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 1149, on July 16, 2007 09:33 AM
Total Registered Members: 64939 Total Logged-in Users: 64
Total Topics: 81912 Total Anonymous Users: 47
Total Replies: 440328 Total Guests: 261
Total Posts: 522240    
Members ( View Memberlist )