The forum of the forums
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Hidden Topics not exactly Hidden

Go down

Hidden Topics not exactly Hidden Empty Hidden Topics not exactly Hidden

Post by Fighter Control February 21st 2009, 9:35 pm

Hi.

There seems to be a bit of a security issue.

On my forum, I set up an area that was hidden from members and guests and only viewable by the forums moderators and Admin.

My forum was originally on phpbb2 and then I updated it to phpbb3.

However a post was made by a normal member stating that he had written some code that could view the titles of the hidden topics of our hidden area.

And had posted a screen dump.

Naturally one of the moderators of my forum acted and removed the post and I was alerted and had to immediately delete the hidden area.

It seems that it is possible to modify a TOPICS ANYWHERE hack and insert the main index of the forum name and it will list all the topics including the hidden topics.

Therefore I have had change over to one of the other forum software and setup new skins.
avatar
Fighter Control
New Member

Posts : 3
Reputation : 0
Language : English

Back to top Go down

Hidden Topics not exactly Hidden Empty Re: Hidden Topics not exactly Hidden

Post by Fighter Control February 21st 2009, 10:12 pm

One of my members works for a large IT security consultancy, and states is it possible for ALL free forum admins to have access to ROBOTS.txt so we can make sure that the web bots such as Yahoo, MSN, Google et al are restricted in to what they can access.
avatar
Fighter Control
New Member

Posts : 3
Reputation : 0
Language : English

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum