SMF Support > SMF 2.0.x Support
Possible Security Issues with Guests.
(1/1)
br360:
Hi all.
So as I'm viewing the "who's online" link, I am noticing that there are guests that are doing things that I know I disabled; checking another member's profile, sending a message, etc...
I personally made it so that guests had to register to see anything on the forum, and set their permissions to zero. In fact, when I open another browser, and try to snoop as a guest, I get nothing but the typical "You must be a registered member to read the forum"
Doing some more research, I noticed that each time this has happened, the ip address does not match any other member on the forum, and they all seem to be proxy ips.
Any feedback or advice?
Arantor:
Yup, there is no security issue whatsoever.
The log shows what people are *trying* to do, but it doesn't check if they actually *can*. So while you see logs of people trying to access profiles, they actually can't. There isn't such a check for performance reasons.
br360:
Thank you for the reply. At least I can stop being paranoid now. :D
ApplianceJunk:
But if you stop being paranoid they will get you for sure. ;)
Navigation
[0] Message Index
Go to full version