• Downloading from our site will require you to have a paid membership. Upgrade to a Premium Membership from 10$ a month today!

    Dont forget read our Rules! Also anyone caught Sharing this content will be banned. By using this site you are agreeing to our rules so read them. Saying I did not know is simply not an excuse! You have been warned.

Secure AdminCP XenForo

Admin

Well-Known Member
Staff member
Administrator
Both rogue members, guest, and cyber bots want to desperately gain access and take over your site. While nothing is 100% hack or crack proof, it's always a good idea to make things just a little harder.

1) Mask / Hide your Super Administrator

The idea is the less people who know what your user name is, the less chance anyone can log in as you.

TIP: It is important not to use common name for your Super Administrator.

For example, such names as



  • Super Administrator
  • Super Admin
  • Administrator
  • Admin
  • Owner
  • Founder
  • God
  • Devil
  • Evil Admin
  • 666
  • 999
  • Moderator
  • Mod
  • Super Moderator
  • Super Mod
  • The title name of your site
  • Your real name



Or generally anything else which maybe common.

You also do not want to keep with user ID 1

/library/config.php

Code:
$config['superAdmins'] = '1';




  • Change this USER ID to whatever user you plan to use as your Super Administrator.
  • CHMOD config.php to 640 to prevent anyone from remotely reading your config.php file.
  • Change your Super Administrator's title to Member or to whatever common title is used on your site



TIP:

Do NOT use your Super Administrator account to address anyone, make any announcements, or do anything that could associate it as you or anything officially associated with your site. The point is so that no one knows what your Super Administrator account is. Make a hello thread, post a few simple replies, so it's not just an account with 0 post, then leave it alone.

2) Super Administrator Password - Strong

You want this to be long and as complex as possible, but easy for yourself to remember. You don't want others guessing your password.

TIP:

Do NOT use the same password that you use anywhere else. This is a common mistake and not advised.

3) Password Protect AdminCP ( admin.php )

You will need to make a password protected .htpasswd file. This file will include a user name and password. You can do this using Cpanel,Direct Admin, Web Admin, and many other control panels. There are also some generator tools that you can user (do your homework).



  • Open .htaccess from within your XenForo root directory and add this on top.



Code:
AuthName "By Invitation Only"
AuthType Basic
AuthUserFile /.htpasswd
<Files "admin.php">
require valid-user
</Files>

CHMOD .htacess to 644 to prevent anyone from directly reading it.

TIP:

Do NOT use the same user name and password as your Super Administrator.

TIP

Do NOT use the path example above. Place your .htpasswd file some place above public access . You do not want anyone being able to directly access it.

Example:

Good = /some-place-else/.htpasswd
Bad = /public_html/some-place-else/.htpasswd

TIP:

If your host supports it or if you can configure it correctly. Do not use the standard name .htpasswd

TIP:

If your host support it or if you can configure it correctly. Do not use AuthType Basic, but rather use AuthType Digest. This will add encryption for better security.

TIP:

If you ever do give someone else access to your AdminCP (developer / hired help); Do NOT give them your user name and password to either your Super Administrator or .htaccess Rather give them their own temporary user name and password.

TIP:




  • If you ever give someone FTP access (developer / hired help), be sure to restrict their access to public directory and do not give them access to anything above it.
  • Remember to remove access once completed
  • You should also backup your database before & after.
  • Remember to change your database user name & password after completed (don't forget about your config.php file).
  • It may also be a good idea to change the name of your Super Administrator after as well (if they accessed this file, they know now who you are).



This guide was made to support most Apache / Apache2 setups including on basic shared web hosting. More advance methods can be used, but typically require more server access.


4) YOU




  • The error between user and keyboard



Even with all the security in the world, all the most powerful security programs, hardware, tweaks, tips, and even following all the above steps...

The biggest known security threat and security flaw in every computer in the world is... You.



  • Only YOU can learn how to better secure yourself (although my steps will surely get you started)
  • Only YOU can control your own user habits
  • Only YOU can remember NOT to ignore important messages (something way to many people seem to do)
  • Only YOU can learn what is safe or not safe
  • Only YOU can decided who can assess your site & accounts.



YOU are your best friend and your worse enemy. This is the most important advise ANY except or computer wizard could ever give you. Please remember it and apply it
 

Facebook Comments

Similar threads
Thread starter Title Forum Replies Date
Admin F-Secure miễn phí VPN 3 năm Sử dụng, chia sẻ, hỏi đáp 2
Admin Secure Shell Client 3.2.9 - Phần mềm SSH/SFTP tốt nhất Phần mềm 0
K Secure your server from PHP shells! Local attack 0
Admin Secure Folder v6.5 + Keygen - Bảo vệ thư mục an toàn Phần mềm 1
Admin [ShikiSuen] CSCN Anniversary theme (for AdminCP Only) Xenforo 0
Admin Hướng dẫn cải tiến chức năng thống kê nhanh trong admincp cho vBulletin Vbb tutorial 0
Admin Share giao diện admincp vbullletin 2015 Style vbb 0
Admin Hướng dẫn fix lỗi trắng trang admincp xenforo Xenforo 0
Admin Hướng dẫn tạo trang đăng nhập admincp giả cho xenforo Xenforo 0
Admin AdminCP News as Posts or PMs by BOP5 (Get your Admin CP News PMed to you!) Add-ons 0
Admin Giao diện win 7 cho admincp Style vbb 0
Admin SCANU's vBFinder - A Web File Manager directly on you admincp! [AJAX] Add-ons 0
Admin Hướng dẫn lấy lại pass admincp cho xenforo đơn giản và nhanh chóng Xenforo 4
J Hướng dẫn Tăng cường bảo mật AdminCP cho XenForo Kiến thức lập trình 0
Admin vt.Lai VBB Anti CSRF 1.2 - Chống tấn công CSRF vào AdminCP vBulletin Add-ons 0
Admin vt.Lai VBB Anti CSRF 1.1 - Chống tấn công CSRF vào AdminCP vBulletin Add-ons 0
Admin Cách bật chế độ Development trong AdminCP Xenforo 0
Admin Hướng dẫn fix lỗi trong css Invalid argument supplied for foreach() in [path]/admincp/css.php on line 451 vbb Vbb tutorial 0
KhangSkull Help Lỗi sai data trong adminCP của VBB Vbulletin 0
KhangSkull Help giúp em về ADMINCP Vbulletin 1
M Help Code TTVN AdminCP error Vbb released 4
S Share Bảo vệ và trang trí cho Admincp Mã nguồn web 0
Admin Tăng cường bảo mật admincp cho xenforo Bảo mật 0
K Bug Vượt AdminCP. Local attack 0
congtust24 Share Share style vista admincp rất đẹp Style vbb 0
chickIT Share Skin admincp Simplicity v4 Style vbb 0
Admin Gửi mail thông báo cho Admin khi có người login vào AdminCP nhưng không thành công Add-ons 0
Admin Hướng dẫn backup forum bằng admincp Vbulletin 0
Admin Hướng dẫn backup forum bằng admincp Vbulletin 0
Admin Tut upload shell vbb qua mysqldumper không cần vào admincp Local attack 0
Admin Updated Products List In Admincp Home Add-ons 0
Admin Hướng dẫn sử dụng admincp cho vbb từ a đến z Vbulletin 0
tubotocdo Bảo vệ và trang trí cho Admincp Vbulletin 2
Admin Cách disable tất cả các plugin, mod để vào admincp trong trường hợp diễn đàn bị lỗi Vbulletin 9
Admin Fix [E_WARNING] inet_pton(): Unrecognized address unknown xenforo 2.2.10 Xenforo 0
V Giới hạn dung lượng ảnh tải lên trong Xenforo 2 Xenforo 0
V Hướng dẫn tạo logo giống Xenforo Xenforo 4
V Help Tiện ích thống kê bài viết cho Xenforo 2 Xenforo 0
hungdanchoi5 Forum Xenforo Thảo luận chung 1
Admin Your profile xenforo Xenforo 0
Admin Member Watch xenforo Xenforo 0
@kiss@ xin giúp đỡ về xenforo Hỗ trợ sử dụng diễn đàn 1
Admin Pro Black Xenforo 2 Xenforo 0
olalavui Hướng dẫn Enable User-ID tracking in Google Analytics for Xenforo Xenforo 3
Admin A2soft-pics - (A2)Upload Postimages picture xenforo 2 Xenforo 0
Admin Disable email and password edit xenforo 2 Xenforo 0
Admin Object Storage Adapter xenforo 2 Xenforo 0
cuongpro9x Share Tích hợp toàn bộ sticker xịn của zalo vào xenforo Xenforo 0
Admin Xenforo 2 - Random Ads Code Xenforo 0
Admin Quick Theme Switcher xenforo 2 Xenforo 0

Similar threads

New posts New threads New resources

Back
Top