Only logged in members can reply and interact with the post.
Join SimilarWorlds for FREE »

Similar Worlds should tighten their firewall

As a concerned member of your site, I thought I'd bring this up.

1. You shouldn't be advertising all these services on your main domain, let alone on the standard/well known ports. Get them to listen on a sub-domain on non-conventional ports.

2. Although, I will give you credit for this. Public/Private key 2-factor auth is good. :) - You could go one step further and make sysadmins log into a VPN service and only allow hosts on the VPN subnet to connect.

3. You're using FTP, which is completely unencrypted, switch to FTP over SSL. Also, the system log on banner is advertising that you're running Pure-FTPd. If I was a malicious uB3r Hax0r. I would be searching public CVE vulnerability lists to see if there are any known exploits for this.

4. Why is your server listening on 143 when your IMAP service doesn't allow authentication over plaintext? You have an IMAPS service running on here!

I could go on and on and on... - But I'd rather this stuff get addressed first.
This page is a permanent link to the reply below and its nested replies. See all post replies »
shakenama · M
You need to bring this up to https://similarworlds.com/Andrew
Looks as though he's an admin
TheFakeSlimShady · 31-35, M
I have tried to communicate with Nuno and Andrew numerous times, I've even offered to assist the site on a voluntary basis. They simply just don't reply to me. It's only a matter of time until a script kiddie owns this site.

They don't even moderate the questions/stories that get posted here. The amount of shit that gets put on here is slowly wreaking the site anyway.
shakenama · M
@TheFakeSlimShady: yup... I've only been on for a week and noticed the lack of moderatrs. All the adult stuff being posted is making this trashy.
This comment is hidden. Show Comment