MyBB Community Forums

Full Version: Guest glitch
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2
I just hear from 1 of my co-owners that someone found a security breach and is able to see the owners forum, And he won't tell us what it is.

My forum is nerfbot.com
Plugins:

Newsmessage
Default avatar
Fit on page
Game section
infobar
Myshoutbox
Mysupport
Mytube
Newpoints
Pagemanager
Recaptcha
Advanced spoiler
Thank you like
Undo delete

I don't think an test account is needed since he was able to view the owners forum as an Guest, and yes the permissions say Guest can't vieuw that section
I can't see the owners forum. Could you provide a link to the owners forum? That way we can see if we get a no permissions page or not. Smile
(2012-08-10, 05:42 PM)Vernier Wrote: [ -> ]I can't see the owners forum. Could you provide a link to the owners forum? That way we can see if we get a no permissions page or not. Smile

I allready tested it, http://www.nerfbot.com/forumdisplay.php?fid=72
I'm getting a no permission error.

Check the forum's permissions.

Admincp -> Forums & Posts -> Forum Managemet -> Owners Forum -> Permissions.

Check only your usergroup can see them. If only your usergroup can, then he cannot access it unless he's in that usergroup.
I might found the glitch i clicked custom permissions. and then i saw this enabled:

'Can view forum?'
'Can search forum?'

So maybe was that the problem and with a glitch he could come in the forums.
Admincp -> Forums & Posts -> Forum Managemet -> Owners Forum -> Permissions.

Only permissions for your usergroup should be on the left<. All the others should be on the right>.
(2012-08-10, 06:05 PM)Vernier Wrote: [ -> ]Admincp -> Forums & Posts -> Forum Managemet -> Owners Forum -> Permissions.

Only permissions for your usergroup should be on the left<. All the others should be on the right>.

I had that but somehow they where able to look into it.
Are you sure they were able to look into it and aren't just saying they did to worry you?
We saw it in the Who's Online list.
(2012-08-10, 06:17 PM)stickeric Wrote: [ -> ]We saw it in the Who's Online list.

The who's online list respects your permissions. If you have access to that forum, it will show the forum name to you. For regular members it would just say viewing the no permissions page.
Pages: 1 2