Security question(s)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • splooge
    Senior Member
    • Mar 2001
    • 215

    Security question(s)

    I seem to be having a heck of a time setting up my security on the boards. Either that or someone out there is just 10 times smarter than I am and can keep getting into things.

    I shut my original board down and brought it up as a new install, to start from scratch with a new 'guild' of folks I game with.

    My forums are setup pretty simple right now. Kinda looks like this:

    -Public Forums
    --Public Discussion
    -Private Forums
    --Private Discussion

    I've made a new user group and put the guild members in it. When I change people to this usergroup they get access to the Private Forums like they should, all seems well.

    When you log out, you can only view the public forums -- works as intended.

    When logging in as registered users, you can see and post on the public forums -- works as intended.

    HOWEVER, when I was browsing the 'Who's On-line' I noticed this:

    "Guest Viewing Attachment in Thread I'm bored at work.. RL pic thread... 10:02 AM"

    An unregistered, un-logged in user that shows up as 'Guest' was reading a message on our PRIVATE boards.

    Currently access masks are off. I don't quite understand how they're used as the forum permissions have always been good enough for me...(Or so I thought?)

    I would appreciate any input to my problem here. My board is located at http://vex.pwned.com and my customer info is filled out in my profile. I'd be happy to PM someone with the admin password if they'd be willing to just take a quick look.

    Regards,

    Chris
  • Mike Sullivan
    Former vBulletin Developer
    • Apr 2000
    • 13327
    • 3.6.x

    #2
    That's not to say they're *actually* viewing it, but rather trying to view it most likely (and getting a no permission screen).

    Try it yourself -- logout and try to go to that attachment.

    Comment

    • splooge
      Senior Member
      • Mar 2001
      • 215

      #3
      Thanks for the reply, and a great piece of software.

      I have two follow up questions.

      1) You're right, when I logout I cannot see the attachment. How is it possible that someone would 'try' to view that attachment when they shouldn't ever know about it (or the link to it, which was in the private forum (The link being the link to the picture in the database, not a picture inserted with the IMG option)) in the first place? It seems like http://vex.pwned.com/attachment.php?s=&postid=138 would be an awful hard link to "guess" at if you didn't have permission to view the forums in the first place.

      2) Regarding access masks being on or off. Are these good for anything other than assigning implicit permissions to users for certain forums that may fall out of their normal usergroup access via the "Edit forum access for this user" option? I haven't found anything regarding access masks in the on-line documentation. =(

      Thanks again for the quick reply it's most appreciated.

      Comment

      • Mike Sullivan
        Former vBulletin Developer
        • Apr 2000
        • 13327
        • 3.6.x

        #4
        1. They're probably just manipulating the URL, looking at all the attachments.

        Regarding access masks being on or off. Are these good for anything other than assigning implicit permissions to users for certain forums that may fall out of their normal usergroup access via the "Edit forum access for this user" option?
        That's about the purpose they serve IMO (and I coded them!) -- it saves creating a bunch of usergroups if you have a bunch of different groups of people who don't meet the "normal" settings.

        Comment

        • splooge
          Senior Member
          • Mar 2001
          • 215

          #5
          Much appreciated! You've taken a load off my mind. =)

          The access masks were confusing to me until explained just now, I felt I was doing something terribly wrong. Apparently some things can be as easy as they seem.

          Thanks again.

          Comment

          • splooge
            Senior Member
            • Mar 2001
            • 215

            #6
            I still seem to be having an issue. Is there any logical explanation for this? This is a cut/paste of who's on-line.

            Aedra Viewing Thread Going to be gone for a week or two. 02:59 PM 64.208.159.230
            Matroni Vexare Forums Main Index 02:56 PM 199.84.173.3
            Rashen Viewing Thread twinks? 03:02 PM 24.247.63.200
            Reipin Pillage Vexare Forums Main Index 03:02 PM 207.198.251.52
            Guest Viewing Attachment in Thread I'm bored at work.. RL pic thread... 02:57 PM 64.208.159.230
            Guest Viewing Attachment in Thread I'm bored at work.. RL pic thread... 02:57 PM 64.208.159.230

            look at aedras IP and the two guests IP's. This user is behind a firewall of some sort -- is that the problem?

            My users are screaming mad about security at the moment. They're convinced that people are coming and reading our private forums -- because this attachment that the user 'guest' is viewing is in a private forum. Unfortunately I don't know enough to even try to convince them otherwise.

            Can someone tell me if they can get access to my private boards? I guess I may have security set up wrong. http://vex.pwned.com

            I am probably over reacting. =(

            Comment

            • Freddie Bingham
              Former vBulletin Developer
              • May 2000
              • 14057
              • 1.1.x

              #7
              And your sure that those guest sessions aren't actually from Aedra before he/she logged in?

              At any rate, as said before, Who's Online does not give any one special powers, it is only relating what is in the session table.

              Comment

              • Mike Sullivan
                Former vBulletin Developer
                • Apr 2000
                • 13327
                • 3.6.x

                #8
                Can someone tell me if they can get access to my private boards?
                Nope -- only see the public stuff.

                Comment

                • seemaxrun
                  Member
                  • Jul 2001
                  • 59

                  #9
                  Have you double checked your forum jump menu while not logged in? I have private forums that show up on the jump menu -- no one without authorization can access the private forums using the jump menu but they can see them to try to access them. I have not changed it because it is not important to me whether they know what is in there just that they cannot enter the private forums without permission but that could be a way your guests are seeing those forums to try to look at them.

                  You can edit the jump forum menu in your templates if that is a problem.

                  Also have you double checked all user groups' permissions including users waiting for email notification? I missed that one on my first run through and had some interesting things happening with registered users not being able to post places where non-registered members could post and were not supposed to be able to.
                  max

                  http://www.seemaxrun.com/forum

                  Comment

                  • SuprSurfr
                    New Member
                    • May 2007
                    • 8

                    #10
                    Is there a way that attachments posted in a private forum can be kept private?
                    If someone that has access to the forums and copies the link to the attachment ID and gives the link to someone without access, they can view the attachement. I would like it to ask them to login if they try to view the attachment, and if they dont have permissions to the forum where the attachment resides to give them an access denied message.


                    Is this possible?

                    Comment

                    • SuprSurfr
                      New Member
                      • May 2007
                      • 8

                      #11
                      Bump

                      Comment

                      • Steve Machol
                        Former Customer Support Manager
                        • Jul 2000
                        • 154488

                        #12
                        If the permissions are set correctly, then this will not happen with the default vB. If you have further question you should start a new thread with all the relevant info.
                        Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
                        Change CKEditor Colors to Match Style (for 4.1.4 and above)

                        Steve Machol Photography


                        Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


                        Comment

                        widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                        Working...