Rogue Guest on Private Forum

Started by Prids, September 13, 2013, 09:18:38 PM

Previous topic - Next topic

Prids

Hi,

I have noticed a 'guest' appear on the 'who is online' on my forum, which is odd as the forum is strictly members by invitation only; registration disabled; guests not allowed and no guest permissions checked anywhere.

Looking in the error log (because I have not got around to fixing them all yet  :) ) a corresponding 'guest' entry is present from the IP of a member.

My thought process is that a member has logged in and not out, so the cookie has eventually expired and they have become a 'guest'.

I have 3 SMF forums, all set up the same way, so I'm looking for clarification of my thoughts, or if I need to be alert to someone breaking in.

All security updates applied.

Thanks

Paul

mashby

It's more likely that your guest is one of your members trying to get to a page without logging in first. I'm assuming your members have the ability to logout. Also, you can still have guests. Your site is in the public area, but you've set it up so that guests cannot really do that much if anything. But they'll still show up as a guest. :)
Always be a little kinder than necessary.
- James M. Barrie

Roadmaster

Hi Paul,

Let me have a look at your forum and I'll see what I can do to help.

Best Wishes,

Richard

Prids

Thank you mashby for your reassuring thoughts.

Members do have the ability to log out, but because of what we do the cookie length is set for 8 hours.  I'm assuming the member just hasn't logged out and the cookie has expired, or as you suggest, they are going to a direct link without logging in (which should then require them to log in).

I occasionally have people (of varying degrees of technical ability) attempt to break in as guests, but nobody has managed it yet  :)

That's just one of the many reasons that I love SMF!

Thank you Roadmaster for your kind offer, but I cannot allow non-members access to anything, due to the nature of our group.  It's not earth shattering or national secrets, but there are copyright issues.

Thanks

Paul








Colin

Paul,

It looks like you have everything sorted out. I will go ahead and mark this as solved. If you need anything else please do not hesitate to start a new topic.
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

Roadmaster

Quote from: Prids on September 13, 2013, 10:13:42 PM
Thank you mashby for your reassuring thoughts.

Members do have the ability to log out, but because of what we do the cookie length is set for 8 hours.  I'm assuming the member just hasn't logged out and the cookie has expired, or as you suggest, they are going to a direct link without logging in (which should then require them to log in).

I occasionally have people (of varying degrees of technical ability) attempt to break in as guests, but nobody has managed it yet  :)

That's just one of the many reasons that I love SMF!

Thank you Roadmaster for your kind offer, but I cannot allow non-members access to anything, due to the nature of our group.  It's not earth shattering or national secrets, but there are copyright issues.

Thanks

Paul

I understand what you mean.

I'm glad to have been thought to give this offer.

Prids

Thanks all.

The support here is fantastic  :)

Paul

Advertisement: