Active Topics

 


Reply
Thread Tools
giecsar's Avatar
Posts: 91 | Thanked: 34 times | Joined on Apr 2010 @ Italy
#1
I would like to bring this issue, which I believe is a vulnerability that grants people access to the administration area, to the attention of the staff members.

Basically what happens is that when I login I sometimes get access (the links appear at the top of the page) to admin areas where I can edit sensitive information, as you can see from the screenshot (attachment).
Attached Images
 
__________________
Programmer, web designer/developer, abstract artist. Curently working on an experimental next-gen website, http://www.forum2point0.net
 

The Following User Says Thank You to giecsar For This Useful Post:
jd4200's Avatar
Posts: 451 | Thanked: 424 times | Joined on Apr 2010 @ England
#2
Screenshot is too small.
Maybe they're going to make you the new admin
__________________
BTC:
19ePiXZUdxqNAq9tStLzZV4dduSQeGPJzj
 
ossipena's Avatar
Posts: 3,159 | Thanked: 2,023 times | Joined on Feb 2008 @ Finland
#3
what sensitive information? and wtf with sometimes? those are always there when your user account has sufficient rights to access certain features of midgard. don't know if the policies are too loose though.
__________________
Want to know something?
K.I.S.S. approach:
wiki category:beginners. Browse it through and you'll be much wiser!
If the link doesn't help, just use
Google Custom Search
 
YoDude's Avatar
Posts: 2,869 | Thanked: 1,784 times | Joined on Feb 2007 @ Po' Bo'. PA
#4
When you select "website" on that menu at the top is "Midgard Administration UI" enabled or is it grayed out?
__________________

SLN member # 009
 
giecsar's Avatar
Posts: 91 | Thanked: 34 times | Joined on Apr 2010 @ Italy
#5
Screenshot is too small.
Not my fault, the website resizes the image when I upload it.

Originally Posted by ossipena View Post
what sensitive information?
Stuff like page metadata and stuff related to administration.


Originally Posted by ossipena View Post
and wtf with sometimes? those are always there
No. They don't always appear. Which is why I'm saying it's a bug or something.

Originally Posted by ossipena View Post
when your user account has sufficient rights to access certain features of midgard.
Well my account has no rights at all, I'm not part of the staff.
__________________
Programmer, web designer/developer, abstract artist. Curently working on an experimental next-gen website, http://www.forum2point0.net

Last edited by giecsar; 2010-08-06 at 15:30.
 
giecsar's Avatar
Posts: 91 | Thanked: 34 times | Joined on Apr 2010 @ Italy
#6
So.. apart from regular users who can't do anything about it, nobody cares? Interesting.
__________________
Programmer, web designer/developer, abstract artist. Curently working on an experimental next-gen website, http://www.forum2point0.net
 
Posts: 889 | Thanked: 537 times | Joined on Mar 2010 @ scotland
#7
gimme an extra thousand 'thanks' and watch the uproar that ensues over that! maybe pm'ing a mod directly might be more effective for getting their attention though?
__________________
sarcasm may be the lowest form of wit, but its the only wit i have.

its a sad day when i can't slip at least one hitchhiker reference in somewhere.
 
giecsar's Avatar
Posts: 91 | Thanked: 34 times | Joined on Apr 2010 @ Italy
#8
Originally Posted by festivalnut View Post
gimme an extra thousand 'thanks' and watch the uproar that ensues over that! maybe pm'ing a mod directly might be more effective for getting their attention though?
Hey, I'm not their security advisor. The mods should be checking out every thread anyway. If they don't care, I'm not going to bother PM'ing them.
__________________
Programmer, web designer/developer, abstract artist. Curently working on an experimental next-gen website, http://www.forum2point0.net
 
HellFlyer's Avatar
Posts: 1,148 | Thanked: 613 times | Joined on Mar 2010 @ Toronto
#9
Yesterday I saw Reggie viewing this thread ,he didnt respond hence there is nothing to worry about
__________________
The quieter you become the more you are able to hear


"I'm a N900 user, can I haz Flash 10 plz?!11!?" © Jaffa


Elopocalypse started on 11.02.2011
 
Jaffa's Avatar
Posts: 2,535 | Thanked: 6,681 times | Joined on Mar 2008 @ UK
#10
Originally Posted by giecsar View Post
Not my fault, the website resizes the image when I upload it.
Then can you please do one of:
  1. Attach it to a new bug report, including details of what you did to get there; the username you've logged on with and a series of screenshots showing each expanded menu entry.
  2. Crop it and re-attach.

(1) would be the most productive, FWIW.

Originally Posted by HellFlyer View Post
Yesterday I saw Reggie viewing this thread ,he didnt respond hence there is nothing to worry about
Reggie has no control over the Midgard portion of maemo.org.
__________________
Andrew Flegg -- mailto:andrew@bleb.org | http://www.bleb.org
 

The Following 3 Users Say Thank You to Jaffa For This Useful Post:
Reply


 
Forum Jump


All times are GMT. The time now is 13:00.