Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Current Version (Old)
 Big time security problem
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

dethfire
Starting Member

20 Posts

Posted - 15 March 2001 :  17:56:54  Show Profile
Ok, I've got this rude, jerk that I want to ban... ok no biggie so I lock him, but he was smart enough to download the whole Access DB!!! anyone can see everything, nothing is sercure. The jerk has all the information, what can I do??? How can I stop him from ruining my great forums?

gor
Retired Admin

Netherlands
5511 Posts

Posted - 15 March 2001 :  18:09:21  Show Profile  Visit gor's Homepage
You need to rename the database to something only you know and then use that name in the config.asp
Since some (free) providers use default directories for databases, someone could easely find your database if you don't rename it.

Some of the free providers like Brinkster have other security problems, there it could be possible that another user that is on the same server as you are still downloads your database. There is absolutely nothing we or anybody else could change in the forumcode to prevent that.

Since your "jerk" has downloaded your database, he knows all the passwords of all your users. The only way you can prevent him from using any of the other accounts is to change all the passwords in the database and send your members a mail with a link to the pages were they can request their password (use the same link as is being used in the "Forgot you Password ?" hyperlink.

Pierre
Go to Top of Page

mama2000
Junior Member

Canada
100 Posts

Posted - 15 March 2001 :  23:50:32  Show Profile  Visit mama2000's Homepage
If you rename the database, say in ws_ftp, then rename it in config.asp. Is that all you have to do? I have mucked up and had to fix so much trying to be creative with my limited knowledge!
:)
Kelly



Edited by - mama2000 on 15 March 2001 23:51:03
Go to Top of Page

gor
Retired Admin

Netherlands
5511 Posts

Posted - 16 March 2001 :  04:06:48  Show Profile  Visit gor's Homepage
Like I said, on some ISPs a problem with the security on the server would enable someone who really knows ASP to get it no matter what, but by renaming it like you said, you'll at least make it hard(er) to do that.

Again: that is a problem with the ISPs not with the forum code.

Pierre
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.38 seconds. Powered By: Snitz Forums 2000 Version 3.4.07