[BUG] Anonymous people can post to Link Redirection Forums

Support for IntegraMOD 140

Moderator: Integra Moderator

[BUG] Anonymous people can post to Link Redirection Forums

PostAuthor: computerskillz » Sat May 20, 2006 9:02 pm

in Integramod 1.4, If you have a forum configured as a link redirection, then any anonymous person can make a thread in that forum simply by launching the posting URL and that forum ID EVEN if the forum is visible only to registered users. All the person needs is the forum ID.

For example if your Link Redirect Forum ID is 29, an anonymous person can simply enter......

http://www.yourdomain.com/posting.php?mode=newtopic&f=29

This should be fixed as soon as possible.

<img>
Last edited by computerskillz on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
testing apostrophe''s in the singature''''s

computerskillz
Members
Members
 
Posts: 45
Likes: 0 post
Liked in: 0 post
Joined: Thu May 18, 2006 1:23 pm
Cash on hand: 0.00

PostAuthor: tmotley » Sun May 21, 2006 6:46 am

Yep, it seems as though anyone can post in a link redirect forum that way. The question that pops into my head is why would they when you can't view the posting?

Sounds like possibly another use for that code that you can use to restrict access to various pages...
Last edited by tmotley on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
User avatar
tmotley
IntegraMODerators
IntegraMODerators
 
Posts: 524
Likes: 0 post
Liked in: 0 post
Joined: Mon Mar 27, 2006 3:56 am
Cash on hand: 0.00
Location: Missouri, USA

PostAuthor: computerskillz » Mon May 29, 2006 9:29 am

"tmotley";p="6780" wrote:Yep, it seems as though anyone can post in a link redirect forum that way. The question that pops into my head is why would they when you can't view the posting?

Sounds like possibly another use for that code that you can use to restrict access to various pages...


Yes you can view it. From the "Recent Topics" block. Spammers can post to the link redirect forum and have their topic show up in "Recent Topics" or "Topics Since" and when you go to click on the link, you're taken to a thread about Penis Enlargement, etc. And when you look at the nav links you'll see that you're in a Redirect forum reading a thread.

Its my guess there's no fix for this as of yet, as staff has yet to comment.
Last edited by computerskillz on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
testing apostrophe''s in the singature''''s

computerskillz
Members
Members
 
Posts: 45
Likes: 0 post
Liked in: 0 post
Joined: Thu May 18, 2006 1:23 pm
Cash on hand: 0.00

PostAuthor: tmotley » Mon May 29, 2006 9:46 am

Last edited by tmotley on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
User avatar
tmotley
IntegraMODerators
IntegraMODerators
 
Posts: 524
Likes: 0 post
Liked in: 0 post
Joined: Mon Mar 27, 2006 3:56 am
Cash on hand: 0.00
Location: Missouri, USA

PostAuthor: computerskillz » Mon May 29, 2006 8:19 pm

I doubt this will work because the spammer doesn't need to "load" the page.. all he needs to do is post to it via the posting form using the url and the forum ID.

It just might be that he won't be able to read the post, but once the <imput> is submitted the thread is created whether he/she reads it or not.
Last edited by computerskillz on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
testing apostrophe''s in the singature''''s

computerskillz
Members
Members
 
Posts: 45
Likes: 0 post
Liked in: 0 post
Joined: Thu May 18, 2006 1:23 pm
Cash on hand: 0.00

Thread injection under "Link redirection" forum

PostAuthor: Solomon » Mon Jun 19, 2006 4:47 pm

A guest was able to inject this thread under a "Link redirection" type forum.

HMXonline.com - The Online Gaming Syndicate Forum Index  » Discussions  » Gaming  » Software  » Action  » MMOFPS  » PlanetSide - planetside.HMXonline.com  » PlanetSide Essentials  » PS Dev Tracker  » Forex Ãà ¢Ã¢â€š ¬
Last edited by Solomon on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
[hr]

Solomon
Members
Members
 
Posts: 90
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 9:22 am
Cash on hand: 0.00


Return to IntegraMOD 140

Who is online

Registered users: App360MonitorBot, Bing [Bot], Google [Bot]