Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,900 Members
165,091 Posts
33 Users Online

Please welcome our newest member, Jors308932!

Affiliates
Go Back AdminFusion » Management » Security and Legal Issues » Are your test accounts unsecure?
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 02-22-2007, 12:12 AM   #1

Ashley's Avatar


Title: www.Centicero.com

Points: 6,754, Level: 24Points: 6,754, Level: 24Points: 6,754, Level: 24
Level up: 25%, 296 Points neededLevel up: 25%, 296 Points neededLevel up: 25%, 296 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jan 2006

Posts: 1,017

Location: Devon, United Kingdom

Ashley is a splendid one to beholdAshley is a splendid one to beholdAshley is a splendid one to beholdAshley is a splendid one to beholdAshley is a splendid one to beholdAshley is a splendid one to beholdAshley is a splendid one to beholdAshley is a splendid one to behold
Send a message via ICQ to Ashley Send a message via AIM to Ashley Send a message via MSN to Ashley Send a message via Yahoo to Ashley  
 
Arrow Are your test accounts unsecure?

About half an hour ago, I came across a forum that disabled guest searching. For some reason, my attention turned to the login box. I simply typed in the username and password 'test' and bingo - it worked! And I did my search.

Then I started to think - there must be other forum admins with test accounts. Now a user account typically can't do more than completley spam your forum <which is quite easy to clean with a click of the magic "delete all posts by this user" button>, but if, for example, you were testing moderator/administrator accounts on your forum, and your test account had a simple-to-guess password with mod/admin rights - then some nasty person could wreck havoc on your forum. So, secure those test accounts! Just put a password which isn't easy to guess on them, or simply delete the account when you're done testing.
Reply With Quote
Old 02-22-2007, 12:24 AM   #2

demojames's Avatar



Title: Just keeping it real

Points: 12,316, Level: 33Points: 12,316, Level: 33Points: 12,316, Level: 33
Level up: 34%, 334 Points neededLevel up: 34%, 334 Points neededLevel up: 34%, 334 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Oct 2005

Posts: 2,856

Location: Kent, WA

demojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant futuredemojames has a brilliant future
Send a message via AIM to demojames Send a message via MSN to demojames  
 
If they were smart I am sure that the test account only has viewing permissions only, no posting privileges.
__________________
My Blog - Follow Me on Twitter
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Blue Devil Test Mule Get Shorty Off Topic 2 11-18-2006 05:52 AM
Check Your POP3 Mail Accounts Anywhere ! - FREE 911 MB E-Mail Accounts Tolstoy Buy and Sell 0 02-22-2006 12:17 AM
Internet Addiction Test (IAT) Ryan Off Topic 17 01-18-2006 06:18 PM

AdminFusion

All times are GMT +1. The time now is 02:46 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72