I've got some security problems on my forum.
The problem is that unauthorized users with the moderator status can access the forum by putting the direct link to the topic in their browser. once there inside they can post replies and read all that vital Private stuff.
They cannot see the topic list, at that point the hack blocks the unauthorized users.
But for now I've got a mayor leak on my board.
these problems are for both the hidden and private forums.
Can someone tell me where the conditions for entering these forums is set?
Cause it's obvious that it doesn't filter out the mods when they enter the direct link (as provided by wol) to the hidden/private topics.
Hagar
[ 01-04-2002 04:10 PM: Message edited by: Hagar ]