  1. I have read some about that option but some experts seem to think it opens more security holes than it closes...and of course I don't know enough about it yet to know who is right When I was doing a lot of PERL programming I noticed that password protecting a directory like this didn't seem to lock out local programs. Not sure exactly whether that would fix this and I would need to set up another server to test it to...hmmm...maybe time to fire up this old linux box I have sitting here...ack!
  2. LOL! I had a feeling that might be the case...now that leaves me with a dilema. I suppose I will have to do the same just to be safe... I wonder if there is a mod floating around that addresses this problem somehow...
  3. I set up an SMF first to give it a try...there are good reasons that phpbb is more popular I am actually running the cache at 755 and haven't had any problems. The file ownership of the files in the cache is set up a bit different so they aren't as easy to chmod but I have read you can set them to 755 as well. I was just hoping there might be a phpbb guru lurking around here somewhere and speaking of users uploading their own avatars...I tried to replace mine here but it wouldn't take the new one...it just deleted the old one. I had to link to the pic on my site. Lee
  4. I recently installed the latest version of phpbb (2.0.22). I know I can't make it bullet proof but I want to come as close as possible. One thing I noticed is that the cache and avatar directories and their content are chmod 777. That gives me the heeby-jeebies because that is a rather dangerous permission combination. Is this just the way this particular program needs things set up? Can it, or should it be changed? And most of all...what is your best tip for phpbb security that I may not know? in case you are curious the forum is here... http://www.verchi.com/forum002/
  5. It has been a while since I posted anything here. To be honest, TCH is easy to forget about. I get up every morning and check my e-mail and it is always there without fail. Day after day, week after week, month after month, year after year, it just keeps working without attracting any attention. My web site is always there. When I want to post a picture on some other site it always works. In fact I can't remember the last time I had a problem with TCH. It makes it real easy to completely forget about these great people here quietly working away every day providing a high quality service th
  6. So yeah...I have the hotlink protection set up with a custom image to replace any image linked from an unauthorized site. I have had it set up that way for a long time. I have noticed in the past that the replacement image didn't show up when I checked on unauthorized links. I just got the standard little red X. I didn't really care that much so I just forgot about it. I was trying to track specific traffic through my site last night and the recent visitors link wasn't being cooperative so I downloaded the full log file for the first time in years. To my surprise I was getting up to 10 req
