<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : Protential security Hole</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : Protential security Hole]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Tue, 07 Apr 2026 13:09:57 +0000</pubDate>
  <lastBuildDate>Fri, 16 Jan 2004 18:16:40 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=8983</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[Protential security Hole : This was fixed/changed quite a...]]></title>
   <link>https://forums.webwiz.net/protential-security-hole_topic8983_post47419.html#47419</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 8983<br /><strong>Posted:</strong> 16&nbsp;January&nbsp;2004 at 6:16pm<br /><br />This was fixed/changed quite a few versions ago.<br><br>The way the user code is created was changed tocontaing the user name then appended to the end of it is a set of10 random letters and numbers.<br><br>If this is not the case in your forum, try updating to the latest version.<br><span style="font-size:10px"><br /><br />Edited by -boRg-</span>]]>
   </description>
   <pubDate>Fri, 16 Jan 2004 18:16:40 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/protential-security-hole_topic8983_post47419.html#47419</guid>
  </item> 
  <item>
   <title><![CDATA[Protential security Hole : I am sure DJ Air knows the documentation...]]></title>
   <link>https://forums.webwiz.net/protential-security-hole_topic8983_post47398.html#47398</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=2267">michael</a><br /><strong>Subject:</strong> 8983<br /><strong>Posted:</strong> 16&nbsp;January&nbsp;2004 at 3:52pm<br /><br />I am sure DJ Air knows the documentation and the forum fairly well, well enough that he is just pointing it out as a suggestion to remove the last two letters of the passoword from the user code. ]]>
   </description>
   <pubDate>Fri, 16 Jan 2004 15:52:46 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/protential-security-hole_topic8983_post47398.html#47398</guid>
  </item> 
  <item>
   <title><![CDATA[Protential security Hole : Read the documentation and you...]]></title>
   <link>https://forums.webwiz.net/protential-security-hole_topic8983_post47393.html#47393</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1070">MadDog</a><br /><strong>Subject:</strong> 8983<br /><strong>Posted:</strong> 16&nbsp;January&nbsp;2004 at 3:26pm<br /><br /><P>Read the documentation and you wont have any security problems.</P>]]>
   </description>
   <pubDate>Fri, 16 Jan 2004 15:26:08 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/protential-security-hole_topic8983_post47393.html#47393</guid>
  </item> 
  <item>
   <title><![CDATA[Protential security Hole : iis 6.0 should take car of this...]]></title>
   <link>https://forums.webwiz.net/protential-security-hole_topic8983_post47390.html#47390</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=2334">Badaboem</a><br /><strong>Subject:</strong> 8983<br /><strong>Posted:</strong> 16&nbsp;January&nbsp;2004 at 3:01pm<br /><br />iis 6.0 should take car of this as well. Meta base does not allow files with mdb extension to be downloaded etc. You can allow or disallow extension types yourself. ]]>
   </description>
   <pubDate>Fri, 16 Jan 2004 15:01:27 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/protential-security-hole_topic8983_post47390.html#47390</guid>
  </item> 
  <item>
   <title><![CDATA[Protential security Hole : i use it in a private directory...]]></title>
   <link>https://forums.webwiz.net/protential-security-hole_topic8983_post47389.html#47389</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=2216">dj air</a><br /><strong>Subject:</strong> 8983<br /><strong>Posted:</strong> 16&nbsp;January&nbsp;2004 at 2:53pm<br /><br />i use it in a private directory ... but i thought i would say about it ... for those that don't use a private directory ...]]>
   </description>
   <pubDate>Fri, 16 Jan 2004 14:53:10 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/protential-security-hole_topic8983_post47389.html#47389</guid>
  </item> 
  <item>
   <title><![CDATA[Protential security Hole : Change the extension of the access...]]></title>
   <link>https://forums.webwiz.net/protential-security-hole_topic8983_post47388.html#47388</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=9949">dpyers</a><br /><strong>Subject:</strong> 8983<br /><strong>Posted:</strong> 16&nbsp;January&nbsp;2004 at 2:49pm<br /><br />Change the extension of the access db from .mdb to .asp (and also the connection strings). The access engine will still open it and work with it, but when someone tries to download it, the web server will try to run it as an asp script and return an error.]]>
   </description>
   <pubDate>Fri, 16 Jan 2004 14:49:21 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/protential-security-hole_topic8983_post47388.html#47388</guid>
  </item> 
  <item>
   <title><![CDATA[Protential security Hole : Hi guys, this isn&amp;#039;t a major...]]></title>
   <link>https://forums.webwiz.net/protential-security-hole_topic8983_post47383.html#47383</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=2216">dj air</a><br /><strong>Subject:</strong> 8983<br /><strong>Posted:</strong> 16&nbsp;January&nbsp;2004 at 2:28pm<br /><br /><P>Hi guys,</P><P>this isn't a major security hole thought it would be wise to say..</P><P>say you have a password 4 charecters long .. </P><P>then if someone whats to get into your account and you dont have it in a folder outside the root folder ... ie they can download it....</P><P>they then can open the database.. look at the User_code and see what the last to letters are ...</P><P>say your password was <strong>help.</strong>&nbsp; in the User_code it would have lp on the end.</P><P>so if someone really wanted to get in they would only have to look in a dictionary and go through all them.. you can tell how long the password is by looking at the salt code .... also common words they would try .. </P><P>the only thing i can suggest is take out the last 2 charecters from the usercode or use part of the encrypted password...</P><P>i would like to say it would take time to hack in but if they wanted to they could....</P><P>i know its&nbsp; a bit far fetched but its a protential security hole</P>]]>
   </description>
   <pubDate>Fri, 16 Jan 2004 14:28:12 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/protential-security-hole_topic8983_post47383.html#47383</guid>
  </item> 
 </channel>
</rss>