News:

Want to get involved in developing SMF, then why not lend a hand on our github!

Main Menu

Member can view IPs in posts

Started by Krashsite, January 28, 2013, 10:16:50 PM

Previous topic - Next topic

Sir Osis of Liver


Have a guy running a 2.0.1 forum, and a member has told him he's found a back way to view any member's IP in posts.

This is how it's supposed to work -

"Your IP address is shown only to you and moderators. Remember that this information is not identifying, and that most IPs change periodically.

You cannot see other members' IP addresses, and they cannot see yours."

AFAIK, there is no setting or permission to allow/disallow users from viewing IPs.  Putting aside the obvious "Why would anyone bother?", I can remove the IP field from the display template (I do it on my boards), but without knowing how he's doing it, don't know if that would solve the problem.

Trying to get more info, but curious if this has come up before.

Ashes and diamonds, foe and friend,
 we were all equal in the end.

                                     - R. Waters

Arantor

There is a mod that allows making it a permission.

Plus, the permission that grants it is surprisingly wide ranging, moderate-forum-members will allow you to see everyone's IP, without the above mentioned mod installed.

* Arantor would prefer that it were converted to be tied to the ban permission, personally, there's no need to see an IP address unless you can do something with it.

Sir Osis of Liver


Making it a permission would allow admin to make IPs visible to members who currently don't see them.  Problem here is a regular member (not admin or mod) claims to have found a way to make them visible to himself on all posts.

Ashes and diamonds, foe and friend,
 we were all equal in the end.

                                     - R. Waters

Arantor

Yes... that's why I wrote a mod for it.

I'd be willing to bet the admin installed the mod and gave out the permission. Or there's something else wrong with permissions.

Or even, something else that's modified things and spilt it to everyone, it's not like it's impossible. But an unmodified SMF doesn't.

Sir Osis of Liver


No, that mod isn't installed.  I don't see anything in permissions that would make IPs visible.

Ashes and diamonds, foe and friend,
 we were all equal in the end.

                                     - R. Waters

Arantor

Get the admin to give you a list of all the permissions that user has.

Sir Osis of Liver


I'll see what I can get, but the user is almost certainly in the subscriber group, and my test member in the same group doesn't see IPs, just 'logged'.  It doesn't appear to be a general problem, just one guy that claims he's found a backdoor.

Ashes and diamonds, foe and friend,
 we were all equal in the end.

                                     - R. Waters

emanuele

Quote from: Arantor on January 28, 2013, 10:19:22 PM
Plus, the permission that grants it is surprisingly wide ranging, moderate-forum-members will allow you to see everyone's IP, without the above mentioned mod installed.

* Arantor would prefer that it were converted to be tied to the ban permission, personally, there's no need to see an IP address unless you can do something with it.
It's "early" morning and I'm in a hurry, cannot check and I don't remember how wide is moderate-forum-members. Judging by the name it may include also be able to verify if the use has a duplicate account, in that case have access to the IPs would be reasonable I think.


Take a peek at what I'm doing! ;D




Hai bisogno di supporto in Italiano?

Aiutateci ad aiutarvi: spiegate bene il vostro problema: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.

Arantor

OK, so some research.

moderate_forum permission is scary wide ranging. We tend to think of it as a global moderator permission but it covers many many things. In this case, yes, it also covers access to the IP address.

Perhaps the answer is to break it up a bit, don't know.

Advertisement: