I was almost hacked into. It only happened after I allowed images in posts. (fopen wrappers=on)
Please set the Knowledge Base to not allow posting. I had someone almost hack in.
He was able to (as a user), but was just a guest, write an article.
Just set the permissions to not allow posting to the Knowledge base, and you will be better off.
The user name was a lot of letters and numbers. ctracker kept them out. I have a record of it in the ctracker database.
:mrgreen:
Be Careful With This---it's A Security Warning.
Subject: Re: Be Careful With This---it's A Security Warning.
In my inbox, I had a message from this "anonymous" user. That hacker was a guest and was able to post in the KB.
Of course, when I found out, I disallowed KB articles of any type.
Here is a pic of the message.
When you click to read the article, you get this:
:)
Of course, when I found out, I disallowed KB articles of any type.
Here is a pic of the message.

When you click to read the article, you get this:
Quote:
:)
Subject: Re: Be Careful With This---it's A Security Warning.
This is not necessarily a hacker. In my forum I was getting notifications of KB modifications being with the user IP... the Google Bot IP! :shock:
I think it's a bug in IP, but it doesn't let a real modification or submission of an article but just generates the notification when it shouldn't do it.
I think it's a bug in IP, but it doesn't let a real modification or submission of an article but just generates the notification when it shouldn't do it.
Subject: Re: Be Careful With This---it's A Security Warning.
I don't think so. IMHO it's a permissions issue only: if you don't set permissions correctly then you could get that kind of problems. :wink:
hal9000 wrote: [View Post]
I don't think so. IMHO it's a permissions issue only: if you don't set permissions correctly then you could get that kind of problems. :wink:
Subject: Re: Be Careful With This---it's A Security Warning.
I'll take a look again, but I think when that happened I already looked at the permission and it was configured to only admins could post or modify. I don't remember well though.
buldo wrote: [View Post]
I'll take a look again, but I think when that happened I already looked at the permission and it was configured to only admins could post or modify. I don't remember well though.
Page 1 of 1
You cannot post new topicsYou cannot reply to topics
You cannot edit your posts
You cannot delete your posts
You cannot vote in polls
You cannot attach files
You can download files
You cannot post calendar events
This is a "Lo-Fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Powered by Icy Phoenix based on phpBB
Generation Time: 0.9417s (PHP: 2% SQL: 98%)
SQL queries: 16 - Debug Off - GZIP Enabled