Welcome to Geeklog, Anonymous Monday, December 30 2024 @ 03:51 pm EST

News

Command & Control Showing Unauthorized Controls

  • Tuesday, May 13 2003 @ 01:34 am EDT
  • Contributed by:
  • Views: 5,905
Security I just noticed this... Using Admin everything looks cool and signing in as a regular user, things are dandy *but* it seems whomever I give Command and Control access will see unauthorized controls....

Static pages - Chatterblock - Faqman - FileMgmt - Forum - Menu Editor and External pages show up in *their* command and control... *but* if they click on it they're faced with a Access Denied page...

Why is it these icons are showing up in the first place? The moderator clearly doesn't have access rights to static pages and most anything else... Also these plug-ins come from different developers but all have something in common for them to show up...

I am not nailing it... Has anyone seen this before or is this how it works by default?

Thanks for any info on this :)

Potential Security Flaw

  • Monday, May 12 2003 @ 10:50 pm EDT
  • Contributed by:
  • Views: 9,766
Security A friend of mine signed up and I forgot to assign him to a private group I created called "friends" on my geeklog.

He wanted to view the hidden stories but he couldn't... he found a way to get to the security settings by clicking on the "mail story" button.

Well this confused me because he wasn't supposed to be able to see the story anyway to mail it.

I had only checked the site as an anonymous user and it's true that when I was anonymous I couldn't see the topic listed in the "sections" list nor could I see the story listed on the front page.

Yet when I created a simple user account I could suddenly read the lead section of the story and have access to e-mail the entire story to myself. If I click on the "read more" link I am told that I am not a member of the site, although technically I am a member since I created an account.

Sort of nit picky on that part but the security flaw is sort of an issue.

Page navigation