The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
Google/Guest reads an admin thread?
We see at least two Google bots trying to look into an admin forum. What should the screenshot below tell us and how do these bots get into this forum as guests?
Could there be problems with forum permissions? The admin fora are normally not visible for guests or registered users. We haven't checked the serverlogs yet but I call this a serious security issue. Btw, the thread shown in the screenshot was opened by an admin because of this undesirable activity. |
#2
|
|||
|
|||
See the stop sign? they are only viewing the no permissions page
|
#3
|
||||
|
||||
Thanks for trying to calm me down but I see only a red image delivered by a software under certain circumstances. We have seen the bots accidently on two different threads, both threads wrapped into an admin-only forum. As vBulletin showed the access, the respective thread was the topmost under a row of stickies. I do not blame vBulletin yet, I am just not sure that these Google crawlers can not read the title of the threads.
We can certainly learn more in a couple of hours when the admin scans the serverlog. But I am currently not relaxed. |
#4
|
||||
|
||||
A bot is simply an Unregistered user. Check the permissions for that group. And, if you don't believe those, logout of your forum and see what you can see. Whatever you can see is what a bot can see.
|
#5
|
|||
|
|||
do you have GoogleAds on your site? any Banners engine? Google Analytics will also check all the pages that you visited, because they log your pages content for keywords etc
|
#6
|
||||
|
||||
I checked the server log and, as an unregistered user, tried many of the URLs called by the Google bots. I saw only the login page. You were right and I am relieved.
One issue remains, the origin of the concern. I can reproduce it with one browser, but it is easier to test with two:
Is this a bug or do I have a little google glued to my shoes? |
#7
|
|||
|
|||
if you refresh a page from one browser to the other, you are still user X, so you share the session between the browsers, and you are in a single place.. the other detail is the google bot itself, not your other user.
|
#8
|
||||
|
||||
Quote:
--- I did a couple of other tests and guess I know what's going on: it looks like vBulletin's information is accurate and the bot is attached to myself: Peter Calgary is one of my test accounts and Peter Ostry is my admin account (same IP). The "guest" is a Google bot. It seems to follow Peter Ostry wherever he is. I am the one who ordered the GoogleAds. If this is related, I am not amused about the potential security risk and will remove this stuff as soon as possible. But however, the issue doesn't seem to be vBulletin related. |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|