Aller au contenu

Photo

NeverwinterVault.org - is Rolo Here?


  • Veuillez vous connecter pour répondre
3 réponses à ce sujet

#1
Baaleos

Baaleos
  • Members
  • 1 330 messages
Hi All,
Is Rolo Kipp around here?

I found a serious security flaw at NeverwinterVault.org - I think hes the owner, isnt he?

I posted the details of the bug / flaw to his user Account on that site - but got no response - just checked the bug is still there.

Its a big bug - lets anyone get partial administrative access to the vault - I was able to increase my karma points by 150 - just to test it out etc.
It also allows anyone the ability to mess with / tamper projects, articles and resources uploaded to the site.


Not sure if it exists in all drupal sites or just the vault.

If someone can get him to check his vault pvts - he should get the details there.

#2
henesua

henesua
  • Members
  • 3 882 messages

I'll poke him

 

thanks.

 

--edit: caught him. he doesn't have time but he forwarded the communication on to some others who have code skillz and volunteer at the vault.


  • Zwerkules, Tarot Redhand, Wall3T et 1 autre aiment ceci

#3
Fester Pot

Fester Pot
  • Members
  • 1 394 messages

You're a Developer, that's why Baaleos. Certain administrative functions are available to those with Developer access, even though a Developer does not receive the admin menu that is displayed on every screen like those with Administrative access do. You can give yourself all the points you want if you'd like, or go into the panel however it is you stumbled upon it and explore freely.

 

Whomever gave you Developer access probably didn't pass along the power such access offers, but they must trust you enough, and so I have no reason to worry. :ph34r: ... or do i? Dun-dun-dun! :)

 

FP!


  • Michael DarkAngel, henesua et Rolo Kipp aiment ceci

#4
rjshae

rjshae
  • Members
  • 4 508 messages

keep-calm-it-s-not-a-bug-it-s-a-feature-


  • Zwerkules, Estelindis, henesua et 3 autres aiment ceci