<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[my thoughts on forum security]]></title><description><![CDATA[<p dir="auto">i wanted to write about some security issues which many forums suffer from and have yet to be fixed. this isnt a callout post or anything, i just find it interesting. any details on specific forums, vulnerabilities, or specific software will be redacted until its fixed.</p>
<p dir="auto">quite frankly, forum security - like any other types of security - SUCKS HORRIBLYYY. there is a large forum vendor which is riddled with vulnerabilities, to give you context here are vague summaries of the vulnerabilities ive found in certain forum software:</p>
<ol>
<li>broken access control: any moderator, without the right privileges, is able to see user's data which should only be limited to admins.</li>
<li>any user is able to grab another user's ip address, without any interaction or alert.</li>
<li>any user is able to upload files which are prohibited.</li>
</ol>
<p dir="auto">keep in mind, i only spent like.. an hour or two, doing a basic audit of the web interface part - i didnt even disassemble and decompile the binaries for potentially more serious vulnerabilities. and ofc, i reported all vulnerabilites to the vendor (which they claim they reply and triage within 24 hours - but its taking weeks :sob:)</p>
<p dir="auto">the point is. uhhhm. there is no point, just be careful online.</p>
]]></description><link>https://browsedns.net/topic/18477/my-thoughts-on-forum-security</link><generator>RSS for Node</generator><lastBuildDate>Tue, 16 Jun 2026 19:25:17 GMT</lastBuildDate><atom:link href="https://browsedns.net/topic/18477.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 12 Jun 2026 01:25:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to my thoughts on forum security on Fri, 12 Jun 2026 03:12:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maple">@<bdi>maple</bdi></a> awww man ive been looking for a good forum community to get into. lmk if u find any</p>
]]></description><link>https://browsedns.net/post/211058</link><guid isPermaLink="true">https://browsedns.net/post/211058</guid><dc:creator><![CDATA[pawthetic]]></dc:creator><pubDate>Fri, 12 Jun 2026 03:12:08 GMT</pubDate></item><item><title><![CDATA[Reply to my thoughts on forum security on Fri, 12 Jun 2026 01:40:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/pawthetic">@<bdi>pawthetic</bdi></a> ummmmmm. no x.x im not familiar with many forums, i just look into the underlying software</p>
]]></description><link>https://browsedns.net/post/211038</link><guid isPermaLink="true">https://browsedns.net/post/211038</guid><dc:creator><![CDATA[maple]]></dc:creator><pubDate>Fri, 12 Jun 2026 01:40:12 GMT</pubDate></item><item><title><![CDATA[Reply to my thoughts on forum security on Fri, 12 Jun 2026 01:38:29 GMT]]></title><description><![CDATA[<p dir="auto">do you know any good forums that arent this one? like ones for every device ofc</p>
]]></description><link>https://browsedns.net/post/211037</link><guid isPermaLink="true">https://browsedns.net/post/211037</guid><dc:creator><![CDATA[pawthetic]]></dc:creator><pubDate>Fri, 12 Jun 2026 01:38:29 GMT</pubDate></item></channel></rss>