You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 320 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Users can "fake" register without the email regist [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
HellRaizher
Corporal
Corporal


Joined: May 15, 2003
Posts: 52

Location: Denmark

PostPosted: Fri Dec 19, 2003 9:03 pm Reply with quoteBack to top

I use the email user activation on my site and it works fine when they use the register link built in to PHP Nuke. But if they go in to the members list or the forum (phpBB) there is a register link in those two, and if they use them they can register without email activation. So the same user can make mutiple accounts without the email check or with fake emails.
This should NOT be possible!
How do I remove these links? I cant find them in the pbpBB code.

_________________
WoWClan.dk - The danish World of Warcraft clan. We are also fans/players of other RPG games like Dungeons & Dragons.
Visit us, join us! Smile
Find all posts by HellRaizherView user's profileSend private messageVisit poster's websiteMSN MessengerICQ Number
maciekp
Sergeant
Sergeant


Joined: Sep 09, 2003
Posts: 94

Location: Perth, WA

PostPosted: Fri Dec 19, 2003 10:25 pm Reply with quoteBack to top

File: profile mode: register

_________________
ElectricDice 0.8 - password & MD5, sitekey generator tool

Use SHA1 in Nuke
Find all posts by maciekpView user's profileSend private messageVisit poster's website
HellRaizher
Corporal
Corporal


Joined: May 15, 2003
Posts: 52

Location: Denmark

PostPosted: Sat Dec 20, 2003 1:11 am Reply with quoteBack to top

Could you explain that a little more... Cant make any sens of that...

_________________
WoWClan.dk - The danish World of Warcraft clan. We are also fans/players of other RPG games like Dungeons & Dragons.
Visit us, join us! Smile
Find all posts by HellRaizherView user's profileSend private messageVisit poster's websiteMSN MessengerICQ Number
HellRaizher
Corporal
Corporal


Joined: May 15, 2003
Posts: 52

Location: Denmark

PostPosted: Sat Dec 20, 2003 11:44 pm Reply with quoteBack to top

Can someone please help with this problem. I would like to get this security problem corrected as soon as possible.

_________________
WoWClan.dk - The danish World of Warcraft clan. We are also fans/players of other RPG games like Dungeons & Dragons.
Visit us, join us! Smile
Find all posts by HellRaizherView user's profileSend private messageVisit poster's websiteMSN MessengerICQ Number
wizard_quest
Nuke Cadet
Nuke Cadet


Joined: Oct 29, 2003
Posts: 2


PostPosted: Sun Dec 21, 2003 9:44 pm Reply with quoteBack to top

A simple fix maybe to change the permissions on the Members List (Nuke side under Module administration) to registered users only. Then preventing non-members from seeing the members list and the register link inside.

Just a quick work around, not a code fix though.
Find all posts by wizard_questView user's profileSend private message
HellRaizher
Corporal
Corporal


Joined: May 15, 2003
Posts: 52

Location: Denmark

PostPosted: Mon Dec 22, 2003 10:51 pm Reply with quoteBack to top

Quote:
A simple fix maybe to change the permissions on the Members List (Nuke side under Module administration) to registered users only. Then preventing non-members from seeing the members list and the register link inside.

Just a quick work around, not a code fix though.


This does not solve the problem... If you set it to members only, you can still register in the forum menu without email activation!

_________________
WoWClan.dk - The danish World of Warcraft clan. We are also fans/players of other RPG games like Dungeons & Dragons.
Visit us, join us! Smile
Find all posts by HellRaizherView user's profileSend private messageVisit poster's websiteMSN MessengerICQ Number
whey
Nuke Soldier
Nuke Soldier


Joined: Nov 23, 2003
Posts: 11


PostPosted: Mon Dec 22, 2003 10:58 pm Reply with quoteBack to top

HellRaizher wrote:


This does not solve the problem... If you set it to members only, you can still register in the forum menu without email activation!


Then fix your configuration so they can't register without email activation.

http://www.phpbb.com/support/guide/#section3_2_2
Enable account activation - When set to None, a user may log in as soon as he/she registers. When set to User, a user must validate his email address before logging in. The user will be sent an email with an activation link. When the user clicks this link, their account is activated and he/she may log in. When set to Admin, a user's account must be activated by an administrator. For more information, see 3.5.3 User Management.
Find all posts by wheyView user's profileSend private message
HellRaizher
Corporal
Corporal


Joined: May 15, 2003
Posts: 52

Location: Denmark

PostPosted: Tue Dec 23, 2003 5:23 am Reply with quoteBack to top

Thanks... this finnaly solved my problem....

_________________
WoWClan.dk - The danish World of Warcraft clan. We are also fans/players of other RPG games like Dungeons & Dragons.
Visit us, join us! Smile
Find all posts by HellRaizherView user's profileSend private messageVisit poster's websiteMSN MessengerICQ Number
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.141 Seconds - 382 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::