MyBB Community Forums

Full Version: [Help] Review my forum [Pentest]
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hi,

I'm a newbie to Mybb, I recently started my site. I do want to make sure it's secure before I opened it to public. I see that this is a extremely helpful forum.

Board : www.y2kforums.com

Here are specs
  • Installed mybb 1.6.9
  • Darkfusion theme
  • Installed according to official instructions contained in the package.
  • PHP Version : 5.3.20
  • SQL Engine : MySQLi 5.1.61
  • Plugins are
  • Akismet 1.2.2
  • My Awards 1.3
  • Theme and plugins are downloaded from official sources.

I would really love to hear your feedback/advices/pentest results/vuln. .


If you want a test account let me know.

Thank You so much.
Hello,

Before i start i don't want you think i am just ripping your forum apart everything i am about to say is critical to help you hopefully make a better successful forum.

When i visit your site the colours, logo etc don't really tell me what the site is about, i have no idea what is going to be discussed here and to be honest if you hadn't put the link here if i had clicked the forum elsewhere i would of closed it immediately.

There are far too many sections, webmasters seem to think you need to create a section for every topic you "think" your members will talk about, lets remember you don't have these members yet nore do you have the posts so why not create these sections as the community grows?

The top bar, it looks like the login bar needs to be changed, if that stays there even when i am logged in it is one mighty distraction.

As for securing your forums there are LOADS or topics on here about this subject, for example http://www.y2kforums.com/admin/ could be moved or renamed, you could setup a honeypot to check if people are trying to login to your forums.

Hope this helps you a little bit

Rich
Thank you very much, I do love constructive criticisms.

For the many sections part, I didn't opened my forum to public and I've a group of members standing by to join so I'm in beta phase. I've members for all of that sections.

Thanks for the theme suggestions , I'll look in to that. I'll change admin location soon.

Thank You very much.
I can't access your site.
(2013-01-17, 02:14 AM)kamz89 Wrote: [ -> ]I can't access your site.

Same here. Domain DNS issue.
Fixed it, that was an issue with cloudflare, Now you can access
It's good but what's with your favicon?
(2013-01-19, 12:19 AM)kamz89 Wrote: [ -> ]It's good but what's with your favicon?

What do you mean by that ??

You can't see mine ??
[Image: favicon.ico]

I would like to BUMP Wink
(2013-01-19, 07:04 AM)Budhan Wrote: [ -> ]
(2013-01-19, 12:19 AM)kamz89 Wrote: [ -> ]It's good but what's with your favicon?

What do you mean by that ??

You can't see mine ??
[Image: favicon.ico]

I would like to BUMP Wink

I could see it but often people use favicons related to their site and you're using something that isn't close to your sites niche so wondering.
http://i.imgur.com/EbPTDnf.png

It's written Y2K Smile

I sucks in GFX but my team is on it Smile

Thanks Yar