<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : Security Issue</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : Security Issue]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Fri, 03 Apr 2026 23:40:15 +0000</pubDate>
  <lastBuildDate>Mon, 03 Nov 2003 05:06:20 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=6934</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[Security Issue : I&amp;#039;ve looked at all teh queries...]]></title>
   <link>https://forums.webwiz.net/security-issue_topic6934_post34430.html#34430</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 6934<br /><strong>Posted:</strong> 03&nbsp;November&nbsp;2003 at 5:06am<br /><br />I've looked at all teh queries in the search.asp page but they are socomplex I can't find a way to also look at the permisisons for the userwithout a search taking 10 minutes.]]>
   </description>
   <pubDate>Mon, 03 Nov 2003 05:06:20 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/security-issue_topic6934_post34430.html#34430</guid>
  </item> 
  <item>
   <title><![CDATA[Security Issue : Thats great news Borg...I didn&amp;#039;t...]]></title>
   <link>https://forums.webwiz.net/security-issue_topic6934_post34422.html#34422</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=5886">Nick-V</a><br /><strong>Subject:</strong> 6934<br /><strong>Posted:</strong> 03&nbsp;November&nbsp;2003 at 4:35am<br /><br /><P>Thats great news Borg...I didn't find the discussion despite some searching but I'm sure I'll find the new SQL Stored Procedure.</P><P><strong>Borg, does the new version also fix the search issue or shall I continue to look into what it does and how to get around it?</strong></P><P>PS. I think I found pre-release stored procedure (Active Topics not Search) but I'm waiting for new version as it need to be called with 4 bits of data in the linkage. For those interested its at <A href="http://forums.webwiz.net/forum_posts.asp?TID=6268&amp;KW=active+topics+procedure" target="_blank"> http://forums.webwiz.net/forum_posts.asp?TID=6268&a mp;KW=active+topics+procedure</A></P><span style="font-size:10px"><br /><br />Edited by Nick-V</span>]]>
   </description>
   <pubDate>Mon, 03 Nov 2003 04:35:22 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/security-issue_topic6934_post34422.html#34422</guid>
  </item> 
  <item>
   <title><![CDATA[Security Issue : The next version that I will release...]]></title>
   <link>https://forums.webwiz.net/security-issue_topic6934_post34420.html#34420</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 6934<br /><strong>Posted:</strong> 03&nbsp;November&nbsp;2003 at 4:30am<br /><br />The next version that I will release today won't show topic titles for forums the user can't view on the active users page.<br><br>This was discussed in quite some length a few weeks ago and many thingstried out which resulted in a new stored procedure for SQL server and anew query for Access that I did post somewhere on this forum.<br>]]>
   </description>
   <pubDate>Mon, 03 Nov 2003 04:30:59 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/security-issue_topic6934_post34420.html#34420</guid>
  </item> 
  <item>
   <title><![CDATA[Security Issue : I am no technical authority but...]]></title>
   <link>https://forums.webwiz.net/security-issue_topic6934_post34418.html#34418</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=5886">Nick-V</a><br /><strong>Subject:</strong> 6934<br /><strong>Posted:</strong> 03&nbsp;November&nbsp;2003 at 4:28am<br /><br /><DIV><FONT face=Arial size=2>I am no technical authority but carried out some user testing and wish to share my results to encourage solutions.</FONT></DIV><DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV><DIV><FONT face=Arial size=3><strong><U>The Active Topics Issue</U></strong></FONT></DIV><DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV><DIV><FONT face=Arial size=2>First, The Search Issue is different and will be looked into separately.</FONT></DIV><DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV><DIV><FONT face=Arial size=2>It appears that forums can be included or excluded in the Active Topics list based on the following criteria:</FONT></DIV><DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV><DIV><FONT face=Arial size=2><strong>If the Generic Forum Permission named Forum Access is set to All Users the forum topics will be included in the Active Topics list. Under all other circumstances the topics will not display.</strong></FONT></DIV><DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV><DIV><FONT face=Arial size=2>Group Permissions are not considered in the display of topic names but do control access to the postings as one would expect. The issue, therefore, is controlling the display of the topic name. To help you:</FONT></DIV><UL><LI><FONT face=Arial size=2>if you have attempted to secure your forums using generic permissions, active topics will not work for NO-ONE.</FONT> <LI><FONT face=Arial size=2>If you wish EVERYONE (including guests) to see all of your topic names set the Generic Forum Permission to All Users and use Group Permissions to control access to the forum's content. Thus, topic names can be seen but threads cannot be read.</FONT> <LI><FONT face=Arial size=2>If you wish to prevent EVERYONE (including users with forum access) from seeing the topic names in specific forums, set the Generic Forum Permission for the specific forums to Private Groups and set up Group Permissions to control access to the forum's content.</FONT></LI></UL><DIV><FONT face=Arial size=2>If you wish to have increasing levels of users like Guests, Customers, Staff and Managers and use Active Topics you'll have to set up separate forums!!! The only three options are hidden for all, hidden for no-one, hidden for private forums.</FONT></DIV><DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV><DIV><FONT face=Arial size=2>As mentioned previously, the deficiency is that it is not possible to secure topic names without losing use of the Active Topics facility (even for those permitted to see the threads themselves).</FONT></DIV><DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV><DIV><FONT face=Arial size=2>I'd appreciate any ideas or feedback on this.</FONT></DIV><span style="font-size:10px"><br /><br />Edited by Nick-V</span>]]>
   </description>
   <pubDate>Mon, 03 Nov 2003 04:28:10 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/security-issue_topic6934_post34418.html#34418</guid>
  </item> 
  <item>
   <title><![CDATA[Security Issue : I also searched and could only...]]></title>
   <link>https://forums.webwiz.net/security-issue_topic6934_post34414.html#34414</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=5886">Nick-V</a><br /><strong>Subject:</strong> 6934<br /><strong>Posted:</strong> 03&nbsp;November&nbsp;2003 at 3:05am<br /><br /><P>I also searched and could only find <A href="http://forums.webwiz.net/forum_posts.asp?TID=1058&amp;KW=search+topics+hidden" target="_blank"> http://forums.webwiz.net/forum_posts.asp?TID=1058&a mp;KW=search+topics+hidden</A>.</P><P>The thread provides a line of code not instructions where to enter it. I suspect it just changes the topic name displayed to "Special Topic" if the topic found is from forum 1 or whatever you determine to be the sensitive forums.</P><P>As he states, its a fast cover-up but not a solution.</P>]]>
   </description>
   <pubDate>Mon, 03 Nov 2003 03:05:19 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/security-issue_topic6934_post34414.html#34414</guid>
  </item> 
  <item>
   <title><![CDATA[Security Issue : can somone give link ?  i searched...]]></title>
   <link>https://forums.webwiz.net/security-issue_topic6934_post34401.html#34401</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=7827">zadax</a><br /><strong>Subject:</strong> 6934<br /><strong>Posted:</strong> 03&nbsp;November&nbsp;2003 at 1:24am<br /><br /><P>can somone give link ? </P><P>i searched and searched and didnt find it</P>]]>
   </description>
   <pubDate>Mon, 03 Nov 2003 01:24:29 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/security-issue_topic6934_post34401.html#34401</guid>
  </item> 
  <item>
   <title><![CDATA[Security Issue : i think someone made a mod for...]]></title>
   <link>https://forums.webwiz.net/security-issue_topic6934_post34383.html#34383</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=9756">dead_angel</a><br /><strong>Subject:</strong> 6934<br /><strong>Posted:</strong> 02&nbsp;November&nbsp;2003 at 7:28pm<br /><br />i think someone made a mod for this, but not sure who or when or where it was posted, search back in the mod foums or on mad dogs site. i'm pretty sure it's been covered somewhere.]]>
   </description>
   <pubDate>Sun, 02 Nov 2003 19:28:21 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/security-issue_topic6934_post34383.html#34383</guid>
  </item> 
  <item>
   <title><![CDATA[Security Issue : Is it true that ALL topics headings,...]]></title>
   <link>https://forums.webwiz.net/security-issue_topic6934_post34374.html#34374</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=5886">Nick-V</a><br /><strong>Subject:</strong> 6934<br /><strong>Posted:</strong> 02&nbsp;November&nbsp;2003 at 5:16pm<br /><br /><P>Is it true that ALL topics headings, even those&nbsp;in private and hidden (secure?) forums can be seen by ALL users when they use SEARCH and ACTIVE TOPICS?</P><P>WWF contains some good security features but this sounds like a recent and significant flaw. I believe that securing topic names is just as important as securing the message itself. Just imagine !!!</P><P>Has anyone got a work-around or an add-on for this. I'd rather live with some slower performance or more basic security that allow all topic headings to be seen publicly.</P><P>Did I misunderstand this issue or what?</P>]]>
   </description>
   <pubDate>Sun, 02 Nov 2003 17:16:31 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/security-issue_topic6934_post34374.html#34374</guid>
  </item> 
 </channel>
</rss>