Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-23-2013, 12:53 AM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › General Information Technology › General Discuss v
« Previous 1 ... 6 7 8 9 10 ... 18 Next »

[Tutor] Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]

Home General Computer Multimedia Business Lounge

Pages (3): 1 2 3 Next »
Post Reply 
Tweet
Threaded Mode | Linear Mode
Tutor Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
01-07-2012, 12:44 PM (This post was last modified: 01-07-2012 02:51 PM by ketek.)
Post: #1
wahyu_devilzc0de™ Offline
Rest In Peace
***
Posts: 1,573
Joined: Dec 2009
Reputation: 191
Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
Assalamu'alaikum, sobat devilzc0der . Salam sejahtera mawar

Pada bagian ini, ane sedikit berbagi tips bagaimana membuat server anda lebih joss dalam melindungi web2 anda dari serangan sesuatu piss, ok langsung aja.

skenario:
Di asumsikan ane sudah punya cpnel dan dengan mudah menginstall software web, seperti joomla,mybb,wp dll. Di sini ane memakai joomla sebagai contoh saja, asik

Pertanyaan:
Gimana sih, agak server itu aman, "intinya gak ada server yang aman" , Nah paling ndak kita ada usaha sedikit untuk mempolesnya.!!!

TKP:
1. create atau add domain pada path
Code:
/home/user/webku
diatas untuk menghindari jumping. ketawa nah, intinya jangan tepat pat /public_html

2. installasi software, ane di sini contohken joomla, setelah terintah jangan lupa chmod folder2 rawan uploading shell, ex: component,plugins,templates,images,modules,language atau tempat2 yang di kiranya sebagai ajang upload shell asik di sini ane chmod 777, dan nanti kita buktiken nanti hasilnya.
[Image: nxqng6.jpg]

3. minimalisiken templates joomla sedemikian rupa, "sesuai kebutuhan" ex: ane cuma butuh 1 aja, dan sudah full design dan cantik
[Image: ineio0.jpg]

4. beri sedikit php ini, untuk lebih sesuatu lagi "safemode=on dan disable_function" semakin joss, ketawa
berikut server yang sudah di beri racikan polesan
[Image: ogkxvq.jpg]
jika sobat butuh php.ini yang sesuatu untuk lebih secure, monggo:
Code:
[PHP]
engine = On
short_open_tag = On
asp_tags = Off
precision    =  12
y2k_compliance = On
output_buffering = Off
zlib.output_compression = Off
implicit_flush = Off
unserialize_callback_func=
serialize_precision = 100
allow_call_time_pass_reference = On
safe_mode = On
safe_mode_gid = Off
safe_mode_include_dir =                                
safe_mode_exec_dir =
safe_mode_allowed_env_vars = PHP_
safe_mode_protected_env_vars = LD_LIBRARY_PATH
; open_basedir = On
disable_functions = "system, exec, readfile, escapeshellarg, escapeshellcmd, passthru, proc_close, proc_get_status, proc_nice, proc_open, proc_terminate, shell_exec, popen, pclose, dl, pfsockopen, leak, apache_child_terminate, posix_kill, posix_mkfifo, posix_setsid, posix_setuid, posix_setpgid, ini_alter, show_source, define_syslog_variables, symlink, syslog, openlog, openlog, closelog, ocinumcols, listen, chgrp, apache_note, apache_setenv, debugger_on, debugger_off, ftp_exec, dll, ftp, myshellexec, socket_bind, fpassthru, dl"
disable_classes =
expose_php = Off
max_execution_time = 30     ; Maximum execution time of each script, in seconds
max_input_time = 60    ; Maximum amount of time each script may spend parsing request data
memory_limit = 16M      ; Maximum amount of memory a script may consume (32MB)
error_reporting  =  E_ALL & ~E_NOTICE
display_errors = Off
display_startup_errors = Off
log_errors = On
log_errors_max_len = 1024
ignore_repeated_errors = Off
ignore_repeated_source = Off
report_memleaks = On
track_errors = Off
;html_errors = Off
error_log = error_log
variables_order = "EGPCS"
register_globals = On
register_argc_argv = On
post_max_size = 8M
gpc_order = "GPC"
magic_quotes_gpc = On
magic_quotes_runtime = Off    
magic_quotes_sybase = Off
auto_prepend_file =
auto_append_file =
default_mimetype = "text/html"
;default_charset = "iso-8859-1"
include_path = ".:/usr/lib/php:/usr/local/lib/php"
doc_root =
user_dir =
extension_dir = "/usr/local/lib/php/extensions/no-debug-non-zts-20060613"
zend_extension="/usr/local/IonCube/ioncube_loader_lin_5.2.so"
zend_extension_ts="/usr/local/IonCube/ioncube_loader_lin_5.2_ts.so"
extension="eaccelerator.so"
eaccelerator.shm_size="16"
eaccelerator.cache_dir="/tmp/eaccelerator"
eaccelerator.enable="1"
eaccelerator.optimizer="1"
eaccelerator.check_mtime="1"
eaccelerator.debug="0"
eaccelerator.filter=""
eaccelerator.shm_max="0"
eaccelerator.shm_ttl="0"
eaccelerator.shm_prune_period="0"
eaccelerator.shm_only="0"
eaccelerator.compress="1"
eaccelerator.compress_level="9"
extension="suhosin.so"
enable_dl = Off
file_uploads = On
upload_max_filesize = 2M
allow_url_fopen = On
default_socket_timeout = 60
[Syslog]
define_syslog_variables  = Off

[mail function]
smtp_port = 25
sendmail_path = "/usr/sbin/sendmail -t -i"

[SQL]
sql.safe_mode = Off
[ODBC]
odbc.allow_persistent = On
odbc.check_persistent = On
odbc.max_persistent = -1
odbc.max_links = -1  
odbc.defaultlrl = 4096  
odbc.defaultbinmode = 1  

[MySQL]
mysql.allow_persistent = On
mysql.max_persistent = -1
mysql.max_links = -1
mysql.default_port =
mysql.default_socket =
mysql.default_host =
mysql.default_user =
mysql.default_password =
mysql.connect_timeout = 60
mysql.trace_mode = Off

[mSQL]
msql.allow_persistent = On
msql.max_persistent = -1
msql.max_links = -1

[PostgresSQL]
pgsql.allow_persistent = On
pgsql.auto_reset_persistent = Off
pgsql.max_persistent = -1
pgsql.max_links = -1
pgsql.ignore_notice = 0
pgsql.log_notice = 0

[Sybase]
sybase.allow_persistent = On
sybase.max_persistent = -1
sybase.max_links = -1
sybase.min_error_severity = 10
sybase.min_message_severity = 10
sybase.compatability_mode = Off

[Sybase-CT]
sybct.allow_persistent = On
sybct.max_persistent = -1
sybct.max_links = -1
sybct.min_server_severity = 10
sybct.min_client_severity = 10

[dbx]
dbx.colnames_case = "unchanged"

[bcmath]
bcmath.scale = 0

[browscap]
;browscap = extra/browscap.ini

[Informix]
ifx.default_host =
ifx.default_user =
ifx.default_password =
ifx.allow_persistent = On
ifx.max_persistent = -1
ifx.max_links = -1
ifx.textasvarchar = 0
ifx.byteasvarchar = 0
ifx.charasvarchar = 0
ifx.blobinfile = 0
ifx.nullformat = 0

[Session]
session.save_handler = files
;session.save_path = /tmp
session.use_cookies = 1
session.name = PHPSESSID
session.auto_start = 0
session.cookie_lifetime = 0
session.cookie_path = /
session.cookie_domain =
session.serialize_handler = php
session.gc_probability = 1
session.gc_divisor     = 100
session.gc_maxlifetime = 1440
session.bug_compat_42 = 1
session.bug_compat_warn = 1
session.referer_check =
session.entropy_length = 0
session.entropy_file =
;session.entropy_length = 16
;session.entropy_file = /dev/urandom
session.cache_limiter = nocache
session.cache_expire = 180
session.use_trans_sid = 0
url_rewriter.tags = "a=href,area=href,frame=src,input=src,form=,fieldset="

[MSSQL]
mssql.allow_persistent = On
mssql.max_persistent = -1
mssql.max_links = -1
mssql.min_error_severity = 10
mssql.min_message_severity = 10
mssql.compatability_mode = Off
;mssql.connect_timeout = 5
;mssql.timeout = 60
;mssql.textlimit = 4096
;mssql.textsize = 4096
;mssql.batchsize = 0
;mssql.datetimeconvert = On
mssql.secure_connection = Off
;mssql.max_procs = 25

[Assertion]
;assert.active = On
;assert.warning = On
;assert.bail = Off
;assert.callback = 0
;assert.quiet_eval = 0

[Ingres II]
ingres.allow_persistent = On
ingres.max_persistent = -1
ingres.max_links = -1
ingres.default_database =
ingres.default_user =
ingres.default_password =

[Verisign Payflow Pro]
pfpro.defaulthost = "test-payflow.verisign.com"
pfpro.defaultport = 443
pfpro.defaulttimeout = 30
;pfpro.proxyaddress =
;pfpro.proxyport =
;pfpro.proxylogon =
;pfpro.proxypassword =

[com]
;com.typelib_file =
;com.allow_dcom = true
;com.autoregister_typelib = true
;com.autoregister_casesensitive = false
;com.autoregister_verbose = true

[Printer]
;printer.default_printer = ""

[mbstring]
;mbstring.language = Japanese
;mbstring.internal_encoding = EUC-JP
;mbstring.http_input = auto
;mbstring.http_output = SJIS
;mbstring.encoding_translation = Off
;mbstring.detect_order = auto
;mbstring.substitute_character = none;
;mbstring.func_overload = 0

[FrontBase]
;fbsql.allow_persistent = On
;fbsql.autocommit = On
;fbsql.default_database =
;fbsql.default_database_password =
;fbsql.default_host =
;fbsql.default_password =
;fbsql.default_user = "_SYSTEM"
;fbsql.generate_warnings = Off
;fbsql.max_connections = 128
;fbsql.max_links = 128
;fbsql.max_persistent = -1
;fbsql.max_results = 128
;fbsql.batchSize = 1000

[Crack]

[exif]
;exif.encode_unicode = ISO-8859-15
;exif.decode_unicode_motorola = UCS-2BE
;exif.decode_unicode_intel    = UCS-2LE
;exif.encode_jis =
;exif.decode_jis_motorola = JIS
;exif.decode_jis_intel    = JIS
extension=pdo.so
extension=pdo_sqlite.so
extension=sqlite.so
extension=pdo_mysql.so


[Zend]
zend_extension_manager.optimizer=/usr/local/Zend/lib/Optimizer-3.3.3
zend_extension_manager.optimizer_ts=/usr/local/Zend/lib/Optimizer_TS-3.3.3
zend_optimizer.version=3.3.3




zend_extension=/usr/local/Zend/lib/ZendExtensionManager.so
zend_extension_ts=/usr/local/Zend/lib/ZendExtensionManager_TS.so
save as php.ini kemudian chmod 444

5. seditikit polesan .htaccess untuk melindungi config dari symslink asik
Code:
Redirect 301 /configuration.php http://youtube.com
intinya, kita ada orang yg akan symslink, nah ketika akan meliatnya maka ada di redirect ke youtube.com, save ke .htaccess ketawa

6. demo, testing hasil folder2 yang telah kita chmod tadi, dengan 777, asumsikan di dir itu shell si anu .
file upload ane:
Code:
http://wahyu.jkrtenteramelaka.gov.my/templates/rhuk_milkyway/upload.php
dan
http://wahyu.jkrtenteramelaka.gov.my/images/upload.php
pasti akan muncul pesen :
Quote:Internal Server Error

The server encountered an internal error or misconfiguration and was unable to complete your request.

Please contact the server administrator, webmaster@wahyu.jkrtenteramelaka.gov.my and inform them of the time the error occurred, and anything you might have done that may have caused the error.

More information about this error may be available in the server error log.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
wawa kok sesuatu banget yah ketawa

7. ndak ada server yang sempurna sekuritinya, dan usahalah untuk pencegahan dari semua itu, laen kata" ndak ada penyakit yang sembuh tanpa kita obati dan usaha"

Semoga ini dpt bermanfaat bagi sobat2 ane semua,

Salam devilzc0der

Wassalamau'alaikum.
Visit this user's website Find all posts by this user
Quote this message in a reply
 Reputed by :  rusuh(+1) , anko_kum4ru(+1) , thedexwan(+1) , kapiten_maeram(+1) , Killu4(+1) , ditatompel(+1) , ketek(+1) , beezone(+1) , n0wn(+1) , ganatha(+1) , lionel(+1) , PrOReBeLL(+1) , ./ rex(+1) , poticous(+1) , Lintang27™(+1)
01-07-2012, 12:48 PM (This post was last modified: 01-07-2012 12:48 PM by tabun.)
Post: #2
tabun Offline
./Junk3r C4d3t
Posts: 1,777
Joined: Dec 2011
Reputation: 33
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
keren abis... mantap
omz wahyu keren nih... asik
Code:
http://wahyu.jkrtenteramelaka.gov.my/
hah hah
Find all posts by this user
Quote this message in a reply
01-07-2012, 12:50 PM
Post: #3
rusuh Away
sepik'ers
**
Moderators
Posts: 455
Joined: Oct 2011
Reputation: 77
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
joss mas smiley_beer
mencegah emg lebih baek daripada mengobati ngakak
jangan sampe database ilang dah kena symlink orang ngakak
Visit this user's website Find all posts by this user
Quote this message in a reply
01-07-2012, 12:56 PM
Post: #4
wahyu_devilzc0de™ Offline
Rest In Peace
***
Posts: 1,573
Joined: Dec 2009
Reputation: 191
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
(01-07-2012 12:48 PM)tabun Wrote:  keren abis... mantap
omz wahyu keren nih... asik
Code:
http://wahyu.jkrtenteramelaka.gov.my/
hah hah
hehehe, saya padamu mas ketawa

(01-07-2012 12:50 PM)rusuh Wrote:  joss mas smiley_beer
mencegah emg lebih baek daripada mengobati ngakak
jangan sampe database ilang dah kena symlink orang ngakak
ho'oh, monggo2 semoga semakin sesuatu asik
Visit this user's website Find all posts by this user
Quote this message in a reply
01-07-2012, 01:14 PM
Post: #5
Super Moderator Offline
Wahyu Adi Prasetyo
****
Global Moderators
Posts: 6,944
Joined: Jan 2010
Reputation: 237
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
wah,kk wahyu udah pinter buat website ya sekarang?
nympe security servernya kyk gitu ketawa
bagi2 project kk,kalo build web,kali aja dapet uang saku lebih malu
Visit this user's website Find all posts by this user
Quote this message in a reply
01-07-2012, 01:16 PM
Post: #6
wahyu_devilzc0de™ Offline
Rest In Peace
***
Posts: 1,573
Joined: Dec 2009
Reputation: 191
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
(01-07-2012 01:14 PM)linuxer46 Wrote:  wah,kk wahyu udah pinter buat website ya sekarang?
nympe security servernya kyk gitu ketawa
bagi2 project kk,kalo build web,kali aja dapet uang saku lebih malu

aku kui iso opo toh xer xer, ket biyen mung tukang turu, trus kuliah mung nyimak duduk paling mburi, trus molor ketawa ,
Visit this user's website Find all posts by this user
Quote this message in a reply
01-07-2012, 01:18 PM
Post: #7
CitooZz Offline
./pemburu kimblak
**
Moderators
Posts: 1,297
Joined: Jun 2011
Reputation: 22
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
thanks om wahyu ketawa

buru2 benerin site ngacir
Find all posts by this user
Quote this message in a reply
01-07-2012, 01:19 PM
Post: #8
Super Moderator Offline
Wahyu Adi Prasetyo
****
Global Moderators
Posts: 6,944
Joined: Jan 2010
Reputation: 237
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
(01-07-2012 01:16 PM)wahyu_devilcode Wrote:  
(01-07-2012 01:14 PM)linuxer46 Wrote:  wah,kk wahyu udah pinter buat website ya sekarang?
nympe security servernya kyk gitu ketawa
bagi2 project kk,kalo build web,kali aja dapet uang saku lebih malu

aku kui iso opo toh xer xer, ket biyen mung tukang turu, trus kuliah mung nyimak duduk paling mburi, trus molor ketawa ,

ah kk bisa aja malu
sekarang udah banyak project ketawa
Visit this user's website Find all posts by this user
Quote this message in a reply
01-07-2012, 01:24 PM
Post: #9
wahyu_devilzc0de™ Offline
Rest In Peace
***
Posts: 1,573
Joined: Dec 2009
Reputation: 191
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
(01-07-2012 01:18 PM)CitooZz Banditozz Wrote:  thanks om wahyu ketawa

buru2 benerin site ngacir
monggo kang citoz, cendol jg gak nolak ketawa

(01-07-2012 01:19 PM)linuxer46 Wrote:  ah kk bisa aja malu
sekarang udah banyak project ketawa
hehehe ayam bakar wong jowo enak ya xer wawa
Visit this user's website Find all posts by this user
Quote this message in a reply
01-07-2012, 01:28 PM
Post: #10
Killu4 Away
./Devilz Advisor
Posts: 744
Joined: Nov 2011
Reputation: 16
RE: Beri Sedikit Polesan Server Anda Pada Hosting Dgn Cpanel [Full Tips]
Wow full of tips,Nice banget dah om mantap
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Pages (3): 1 2 3 Next »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [Tutor] TIPS DASAR BUAT PEMULA UNTUK BELAJAR TENTANG IT x.intruders 40 2,982 05-06-2013 11:08 AM
Last Post: x.intruders
  [Tutor] cpanel gratis :D aliend 43 1,081 02-12-2013 05:35 PM
Last Post: aliend
  Domain dan cpanel Gratis gan hajarr bazrezs 15 539 02-12-2013 12:08 PM
Last Post: g4mp4ng
Information Dollar Code – Kode Rahasia pada mata uang Dollar Amerika ubuntux 19 1,089 12-18-2012 04:19 PM
Last Post: fuxnbums
Thumbs Up Tips dan Trik Merawat Printer Inkjet agita30 8 151 12-10-2012 09:31 AM
Last Post: agita30
  Perbedaan Linux Hosting dan Windows Hosting MrKcr 6 213 11-16-2012 09:20 AM
Last Post: Super Moderator
  [Tutor] Membuat File PDF pada Word 2007 MrKcr 8 386 11-05-2012 12:32 AM
Last Post: ulZaAceh
  [Solved] cara pindah hosting forum mybb fitra_ctr 7 388 08-15-2012 05:55 PM
Last Post: chaer.newbie
Lightbulb [Tutor] Membuat Partisi pada Flash Disk MrKcr 17 816 08-06-2012 03:21 PM
Last Post: ./root
  [Tutor] Menggunakan PGP Untuk Enkripsi Isi Email Pada Thunderbird ditatompel 8 382 08-02-2012 09:21 AM
Last Post: ditatompel

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-23-2013, 12:53 AM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE