The following warnings occurred:
Warning [2] Undefined variable $unreadreports - Line: 26 - File: global.php(961) : eval()'d code PHP 8.2.25 (Linux)
File Line Function
/global.php(961) : eval()'d code 26 errorHandler->error
/global.php 961 eval
/showthread.php 28 require_once





× This forum is read only. As of July 23, 2019, the UserSpice forums have been closed. To receive support, please join our Discord by clicking here. Thank you!

  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
danger: us4.2, us4.3 hackable easly
#3
@SavageStyle,
I really appreciate the detailed response. I've never felt comfortable with the vericode system, but yeah, we missed an obvious check there. Thank you SO MUCH for the detailed post and and the solutions.

I'll issue a patch for 4.2 and 4.3.

One of the discussions we've been having with auto-banning is how to not allow the vericode system to be a source of DOSing the users of the system. In other words, if it only takes 3 guesses or something, I can get you blocked by requesting your password 3 times. Stuff like that. Again...thanks so much for the detailed post and we'll get this sorted this week.
  Reply


Messages In This Thread
danger: us4.2, us4.3 hackable easly - by Brandin - 11-05-2017, 06:21 PM
danger: us4.2, us4.3 hackable easly - by mudmin - 11-06-2017, 01:12 PM
danger: us4.2, us4.3 hackable easly - by mudmin - 11-12-2017, 12:59 PM

Forum Jump:


Users browsing this thread: 2 Guest(s)