Skip to content
  • Categories
  • Recent
  • Groups
  • Users
  • Tags
  • Popular
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Zephyr)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Regular Blogs
  3. my thoughts on forum security

my thoughts on forum security

Scheduled Pinned Locked Moved Regular Blogs
4 Posts 2 Posters 60 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mapleundefined Offline
    mapleundefined Offline
    maple
    Coders computer nerds pansexual people stalker LGBTQ+ Of BDNS
    wrote last edited by
    #1

    i wanted to write about some security issues which many forums suffer from and have yet to be fixed. this isnt a callout post or anything, i just find it interesting. any details on specific forums, vulnerabilities, or specific software will be redacted until its fixed.

    quite frankly, forum security - like any other types of security - SUCKS HORRIBLYYY. there is a large forum vendor which is riddled with vulnerabilities, to give you context here are vague summaries of the vulnerabilities ive found in certain forum software:

    1. broken access control: any moderator, without the right privileges, is able to see user's data which should only be limited to admins.
    2. any user is able to grab another user's ip address, without any interaction or alert.
    3. any user is able to upload files which are prohibited.

    keep in mind, i only spent like.. an hour or two, doing a basic audit of the web interface part - i didnt even disassemble and decompile the binaries for potentially more serious vulnerabilities. and ofc, i reported all vulnerabilites to the vendor (which they claim they reply and triage within 24 hours - but its taking weeks :sob:)

    the point is. uhhhm. there is no point, just be careful online.

    she/her, 16

    1 Reply Last reply
    3
    • pawtheticundefined Offline
      pawtheticundefined Offline
      pawthetic
      Trans chronically online Cuddle Puddle Complete Dumbahh ΟωΟ | Certified Puppy Anti-Clanker IT'S OKAY TO PUNCH NAZIS ♥ Sweetheart ♥
      wrote last edited by
      #2

      do you know any good forums that arent this one? like ones for every device ofc

      dumb insecure puppygirl

      she/her if you use he/him on me i will hunt you down and kindly remind you to use she/her :heart:

      mapleundefined 1 Reply Last reply
      0
      • pawtheticundefined pawthetic

        do you know any good forums that arent this one? like ones for every device ofc

        mapleundefined Offline
        mapleundefined Offline
        maple
        Coders computer nerds pansexual people stalker LGBTQ+ Of BDNS
        wrote last edited by
        #3

        @pawthetic ummmmmm. no x.x im not familiar with many forums, i just look into the underlying software

        she/her, 16

        pawtheticundefined 1 Reply Last reply
        0
        • mapleundefined maple

          @pawthetic ummmmmm. no x.x im not familiar with many forums, i just look into the underlying software

          pawtheticundefined Offline
          pawtheticundefined Offline
          pawthetic
          Trans chronically online Cuddle Puddle Complete Dumbahh ΟωΟ | Certified Puppy Anti-Clanker IT'S OKAY TO PUNCH NAZIS ♥ Sweetheart ♥
          wrote last edited by
          #4

          @maple awww man ive been looking for a good forum community to get into. lmk if u find any

          dumb insecure puppygirl

          she/her if you use he/him on me i will hunt you down and kindly remind you to use she/her :heart:

          1 Reply Last reply
          0
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Groups
          • Users
          • Tags
          • Popular