MyBB Community Forums

Full Version: Guest (spambots) can post in calender, even if they don't have permissions
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
I found such kind of spam i my calender
Quote:Hello, nice site look this:
<a href="http://www.rollyo.com/search.html?q=knulle+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=knul...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=iniyo+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=iniy...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=wifeys+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=wife...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=jfoxxx+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=jfox...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=garils+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=gari...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=chudai+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=chud...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=wwoec+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=wwoe...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=sexxxx+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=sexx...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=sikiay+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=siki...fo&sid=web
<a href="http://www.rollyo.com/search.html?q=shosar+site:letoaaq.info&sid=web">link</a> link http://www.rollyo.com/search.html?q=shos...fo&sid=web

End ^) See you
Think this is some spambot, and i don't like it.
MyBB version: 1.2.9
PHP version: 4.4.6
DB version: MySQL 4.1.15
Maybe you should check the rights of the usergroups that are not registerd or awaiting activation. You probably gave those the ability to put things in the general calaneder.

Goto your Admin CP and Users and Groups and select: Manage groups and check the rights of your groups Unregistered / Not Logged In and Awaiting Activation

In the rights forum goto Permissions: Calendar and check the setting of Can Add Public Events.

I don't think it's elsewhere.
The new calendar has complete permissions in 1.4.
I cannot replicate this in MyBB 1.2 - I disabled guest calendar event posting and guests can no longer post calendar events.
Guests, users awaiting activation, banned and registred users don't have rights to post public or private events in calendar. First three groups don't see calendar.
Aren't bots under their own usergroup though?
judel Wrote:Aren't bots under their own usergroup though?

By default, search bots (those are the only bots which MyBB identify) are in the Unregistered usergroup and they have the same view as any visitor.