MyBB Community Forums

Full Version: Can i get hacked if i set BOT permissions to Admin ?
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2
I have set the permissions of google bot to Admin.So are there any chances hackers can hack through the BOT and gain admin right s ? Sad
I have no idea what happens but I do not recommend this.
do they make bots run queries that admin can do, if we give them admin permissions? as everyone can know what are the admin queries that are executed, if we look into mybb package.
Don't really know for sure, but why on earth would you want to do this?? You'll gain absolutely nothing from it whatsoever...
Why would you do this? People can just change their user agent to Googlebot and access your admin features. Change it asap!
are really admin and moderator features available to them?

i thought they would just get 'read' access as the group they are in.
1) Doing this is against Google's Website Crawling Policy and your site will be penalised.
2) The googlebot won't be hacked because it belongs to Google, the chance they'll ever be hacked is 1%
3) This is completely pointless.
(2011-02-08, 01:04 PM)Shukaku Wrote: [ -> ]1) Doing this is against Google's Website Crawling Policy and your site will be penalised.
2) The googlebot won't be hacked because it belongs to Google, the chance they'll ever be hacked is 1%
3) This is completely pointless.

No one's talking about hacking the Google Bot!? (how the hell do you hack a bot?)

Anyway, @OP MyBB checks if the visitor is a bot which is in your list (e.g. Google Bot) by checking against the user agent. So, if I go to your website and change my user agent to the Google's user agent I'll be able to gain admin rights which is not what you want.
What I highly recommend you is that you immediately change the user group of the bots.
I do not know if bots can view the forum like regular users (haven't checked the code for that) but probably yes so...your forum is definitely exposed.

Edit:
It seems I was incorrect. The ACP link is only shown if you're logged in and in order to login you must have an account. To login to ACP you need an account too and bots do not have an account, thus they can't access ACP. There should be no problem at all but still, you don't need it.
(2011-02-08, 08:06 PM)Pirata Nervo Wrote: [ -> ]
(2011-02-08, 01:04 PM)Shukaku Wrote: [ -> ]1) Doing this is against Google's Website Crawling Policy and your site will be penalised.
2) The googlebot won't be hacked because it belongs to Google, the chance they'll ever be hacked is 1%
3) This is completely pointless.

No one's talking about hacking the Google Bot!? (how the hell do you hack a bot?)
Er, no. I said "The chance that they'll ever be hacked is 1%." which is talking about Google, not their bot...

Anyway, I'll stay clear of this thread to avoid an argument
(2011-02-08, 08:11 PM)Shukaku Wrote: [ -> ]
(2011-02-08, 08:06 PM)Pirata Nervo Wrote: [ -> ]
(2011-02-08, 01:04 PM)Shukaku Wrote: [ -> ]1) Doing this is against Google's Website Crawling Policy and your site will be penalised.
2) The googlebot won't be hacked because it belongs to Google, the chance they'll ever be hacked is 1%
3) This is completely pointless.

No one's talking about hacking the Google Bot!? (how the hell do you hack a bot?)
Er, no. I said "The chance that they'll ever be hacked is 1%." which is talking about Google, not their bot...

Anyway, I'll stay clear of this thread to avoid an argument

No one is talking about hacking Google, I don't really understand what you mean. I edited my other post by the way, it seems it is not insecure at all.
Pages: 1 2