Quote:
Originally Posted by Knightmane
Apparently there are some data thieves out there using script programs to activate and run your own forum's Impex programs and the script will save your forum's data to any server they designate in the script itself, which allows these thieves to look through your data at their own leisure.
The first time I saw these people doing this, my first thought wasn't piracy; it was, "Hey, I don't have Impex installed. What's going on?"
|
You are contradicting yourself.
Also the part where you say "will save your forum's data to any server they designate" does not make much sense as the target database (and MySQL server) for ImpEx is in the config file that resides on the same server as the ImpEx script, so without FTP access they can not change the target.
If they are hosting ImpEx on their own server, all of the following requirements would still need to be true in order to read your data:
- Your server must allow external connections to the database
- Your databasename must be known
- Your MySQL username & password must be known
Finally passwords are stored hashed in the database and can by no way be retrieved.
If you have any evidence that ImpEx (might) be insecure, please open a Support Ticket providing as much details as possible. At this time there are however no known security issues.