Page 1 of 1

[BUG] Anonymous people can post to Link Redirection Forums

PostPosted: Sat May 20, 2006 9:02 pm
Author: computerskillz
in Integramod 1.4, If you have a forum configured as a link redirection, then any anonymous person can make a thread in that forum simply by launching the posting URL and that forum ID EVEN if the forum is visible only to registered users. All the person needs is the forum ID.

For example if your Link Redirect Forum ID is 29, an anonymous person can simply enter......

http://www.yourdomain.com/posting.php?mode=newtopic&f=29

This should be fixed as soon as possible.

<img>

PostPosted: Sun May 21, 2006 6:46 am
Author: tmotley
Yep, it seems as though anyone can post in a link redirect forum that way. The question that pops into my head is why would they when you can't view the posting?

Sounds like possibly another use for that code that you can use to restrict access to various pages...

PostPosted: Mon May 29, 2006 9:29 am
Author: computerskillz
"tmotley";p="6780" wrote:Yep, it seems as though anyone can post in a link redirect forum that way. The question that pops into my head is why would they when you can't view the posting?

Sounds like possibly another use for that code that you can use to restrict access to various pages...


Yes you can view it. From the "Recent Topics" block. Spammers can post to the link redirect forum and have their topic show up in "Recent Topics" or "Topics Since" and when you go to click on the link, you're taken to a thread about Penis Enlargement, etc. And when you look at the nav links you'll see that you're in a Redirect forum reading a thread.

Its my guess there's no fix for this as of yet, as staff has yet to comment.

PostPosted: Mon May 29, 2006 9:46 am
Author: tmotley

PostPosted: Mon May 29, 2006 8:19 pm
Author: computerskillz
I doubt this will work because the spammer doesn't need to "load" the page.. all he needs to do is post to it via the posting form using the url and the forum ID.

It just might be that he won't be able to read the post, but once the <imput> is submitted the thread is created whether he/she reads it or not.

Thread injection under "Link redirection" forum

PostPosted: Mon Jun 19, 2006 4:47 pm
Author: Solomon
A guest was able to inject this thread under a "Link redirection" type forum.

HMXonline.com - The Online Gaming Syndicate Forum Index  » Discussions  » Gaming  » Software  » Action  » MMOFPS  » PlanetSide - planetside.HMXonline.com  » PlanetSide Essentials  » PS Dev Tracker  » Forex Ãà ¢Ã¢â€š ¬