Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Snitz Forums 2000 DEV-Group
 DEV Discussions (General)
 Possible security problem
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

James
Average Member

USA
539 Posts

Posted - 01 September 2002 :  17:47:42  Show Profile  Visit James's Homepage
There's an extremly limited security issue that will display the physical path to your database (including database name). If your database is inaccessable for any reason, (such as during making a backup of it, etc.), then the forum code will display:


Microsoft JET Database Engine error '80004005' 

Could not find file 'x:\xxxx\xxxx\xxxx.xxx\xxxx\databasename'. 

/forum/inc_top.asp, line 75 


where the databasename is what you named the database and the x's are the exact path to it. Is it possible to make it display a "database path is incorrect" message or something else. I know the chances are extremly rare of catching the error will the file is being backed up, etc., but it still poses a security hazard.

EDIT:I'm noticing this with 3.3.03 as I'm getting ready to upgrade, but I'm sure it'll affect 3.4 too.

*Interested in Radio Control*
*The RC Web Board - http://www.rcwebboard.com/*

Edited by - James on 01 September 2002 17:52:57

Nikkol
Forum Moderator

USA
6907 Posts

Posted - 01 September 2002 :  18:33:06  Show Profile
I believe this is corrected in 3.4.xx because there is a chunk of code in inc_header that will write "There is a problem..."
Forget that ... if you are making a backup, you should down the forum first. And if you do that, a message will be displayed.

Nikkol ~ Help Us Help You | ReadMe | 3.4.03 fixes | security fixes ~

Edited by - Nikkol on 01 September 2002 18:34:47
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.34 seconds. Powered By: Snitz Forums 2000 Version 3.4.07