Page 1 of 1

security problem

Posted: Thu Apr 30, 2009 11:12 am
by ding
I found when I'm logged out if I click on "who is online" then on a user name I can see all there details. Is this just on my board and a Problem I need to sort or is it a PHP3 problem.


Support Request Template
What version of phpBB are you using? phpBB 3.0.4
What is your board's URL? http://finstrokes.com/scubaforum/index.php
Who do you host your board with? wiserhosting
How did you install your board? I used the download package from phpBB.com
Is your board a fresh install or a conversion? Fresh Install
Do you have any MODs installed? Yes
What MODs do you have installed? ajax chat and a twilightBB template
Please describe your problem. I found when I'm logged out if I click on "who is online" then on a user name I can see all there details. Is this just on my board and a Problem I need to sort or is it a PHP3 problem.
What styles do you currently have installed? twilightBB
What language(s) is your board currently using? english
Which database type/version are you using? I Don't Know
What is your level of experience? New to PHP and phpBB
Generated by SRT Generator ($Rev: 2931 $)

Re: security problem

Posted: Thu Apr 30, 2009 11:16 am
by Pit$Bull
That is an administrator 'tool', yes it is normal.

Re: security problem

Posted: Thu Apr 30, 2009 11:29 am
by swissboney3
hmmm surely though if you're logged out you shouldnt be able to see it? when i log out on my forums the "who is online" link is disabled

Re: security problem

Posted: Thu Apr 30, 2009 11:38 am
by Pit$Bull
Sorry, I missed the "when logged out" statement.
You should check your permissions.
Knowledge Base - phpBB3 Permissions
Guests should not have access to this information.
Please use the Support Request Template Generator to fill out the support template for you and then post it here.



Thank you swissboney3 for bringing this to my attention.

Re: security problem

Posted: Thu Apr 30, 2009 2:53 pm
by ding
Have added the template to my original post

Re: security problem

Posted: Thu Apr 30, 2009 3:00 pm
by stevemaury
In Groups forum permissions, give the Guests group a Read only access Role on all forums. In group permissions for the Guests group, Advanced permissions, select All No and submit.

Re: security problem

Posted: Thu Apr 30, 2009 5:08 pm
by ding
Have done the permitions and I can still see the "who is online" any ideas

Re: security problem

Posted: Thu Apr 30, 2009 5:32 pm
by narqelion
@ding, can you do what I asked the other person in this post and report back the results?

Re: security problem

Posted: Thu Apr 30, 2009 6:28 pm
by ding
Dont understand the permitions yet

it worked and thank you for the help.

Will have to study the permitions more..... :D