The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
|
#1
|
|||
|
|||
Guest can download free with .rar file type extension
My forum get trouble. Server allway shutdown. I find out that when I attachment some kind of file in a post, guest can download the file with .rar extension. They needn't sign in when they download file from my site. They copy attachment file link to other site and make my server overload.
FX: I have a post attached some files in .doc, .pdf, .rar, only .rar files guests can download (they can not .doc, .pdf). You even can use accelator download software (Flash get). I store the attachments in the filesystem. Do you think this is a security hole in VBB 3.8.4. I tried to find out at: 1. Admincp > Attachments > Attachment Permissions 2. I checked in Forum Permissions, look at the Unregistered Usergroup and set Unregistered Can Not Download Attachments. I also checked the same permission under Usergroup Manager > Unregistered Usergroup. But the problem still remain. What can I do to set permissions with .rar files ? Can you help me fix this problem ? My server, CPU and MySQL always hang, die... Help me please. Thanks. --------------- Added [DATE]1254717505[/DATE] at [TIME]1254717505[/TIME] --------------- In View Permission I found about permission setting for Unregistered / Not Logged In. All of them set No value for Can View Attachments and Can Post Attachments. |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|