Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
  #1  
Old 07-11-2009, 07:21 AM
Fresky Fresky is offline
 
Join Date: Feb 2009
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Security problem

Hi friends, we have a problem in our site.

The fact is that we have an unauthorized user entering and reading restricted forums. Is a user that do not logs in in any way, so appears as "Guest", but when we look at the "Who is connected" screen, we can see him READING a restricted forum only for moderators.

What can be the problem?

Do we need to install a security update, patch, module, or something?

Thanx a lot.
Reply With Quote
  #2  
Old 07-11-2009, 12:12 PM
ranz ranz is offline
 
Join Date: Dec 2005
Posts: 83
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Check your forum permissions, check your user group permissions and then check what access "guests" have to your forums. There is a fair bit to check there and it is possible that you may overlooked something.

If all your security settings are done properly there is no way a guest can see a restricted forum, other than logging in as a user.

Sometimes the Who's Online page shows that people are reading restricted pages - but if you look closely it shows that they get a warning or error message. This means that they've accessed the page but not the content and are presented with a message saying that they don't have sufficient access.

Other than that - what version do you have? Are you running the latest version? What hacks have you put in the system that could weaken the core security of VB?
Reply With Quote
  #3  
Old 07-16-2009, 07:40 AM
Fresky Fresky is offline
 
Join Date: Feb 2009
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ranz View Post
Check your forum permissions, check your user group permissions and then check what access "guests" have to your forums. There is a fair bit to check there and it is possible that you may overlooked something.

If all your security settings are done properly there is no way a guest can see a restricted forum, other than logging in as a user.

Sometimes the Who's Online page shows that people are reading restricted pages - but if you look closely it shows that they get a warning or error message. This means that they've accessed the page but not the content and are presented with a message saying that they don't have sufficient access.

Other than that - what version do you have? Are you running the latest version? What hacks have you put in the system that could weaken the core security of VB?
First of all, thank you very very much for your help.

I checked all the permissions, and everything seems to be OK. The problem was in fact what you said: The online users page was showing a user trying to read a restricted forum, so it was showing him the "no permissions" message.

It is a courious thing, but the permissions seems to be working ok. We don't have any hack installed, and we are running vb 3.8

We have some other problem, I don't know if you can help us also with this, anyway I open another thread.

:-)

Thanx again.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 08:16 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05482 seconds
  • Memory Usage 2,175KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (3)post_thanks_box
  • (3)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (3)post_thanks_postbit_info
  • (3)postbit
  • (3)postbit_onlinestatus
  • (3)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete