Saw this in the who's online:
Unknown Action (Action: ../../../../../../../../../../../../etc/passwd)
Is it some kind of silly kiddie script attempting to gain access to the Linux user password file? Isn't the passwd file encrypted anyways?
Lol pathetic attempt :D
indeed it won't work.
Anything BUT an an Allowed Action listed in the array in the Index.php will not be accepted as an action
and SmF will fall through to the board index.
Most other variables like topic= and board= also have sanitation and validation on it.
It doesn't stop the hackers/spammers though, I get about a hundred of them on a daily basis. Some don't even use SMF variables, but that of other software. Doesn't stop them trying though.