TP-Docs
HTML5 Icon HTML5 Icon HTML5 Icon
TP on Social Media

Recent

Welcome to TinyPortal. Please login or sign up.

May 22, 2024, 04:55:11 AM

Login with username, password and session length
Members
Stats
  • Total Posts: 195,197
  • Total Topics: 21,221
  • Online today: 99
  • Online ever: 3,540 (September 03, 2022, 01:38:54 AM)
Users Online
  • Users: 0
  • Guests: 78
  • Total: 78

WARNING

Started by deniz, April 18, 2006, 09:25:51 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

anunlike


Mitchâ„¢

So if we dont show the shoutbox will we be ok?

JayBachatero

Yes you should be on if you have the shoutbox disabled.  Just to be on the safe side apply the patch.

bloc

It is/was only active when you allow guests shouting. Thats also why I missed that hole - its some code I haven't looked at for some while.

JayBachatero

I don't allow guests to shout (it was getting spammed).  The person registered as exploit and exploited my forum.

bloc

So he registered and still managed to post a message which re-directed the site?

JayBachatero

Yea he registered and posted the redirect.  Same happened to agridocs site.  That's when I found out about my site.

palorber

Same thing happened to me. I

They registered as ertan... His IP is 85.106.142.123
Host name:  dsl85-106-36475.ttnet.net.tr