Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - Google Adsense
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Google Adsense

 Post Reply Post Reply Page  12>
Author
djlurchg View Drop Down
Groupie
Groupie


Joined: 31 March 2006
Status: Offline
Points: 40
Post Options Post Options   Thanks (0) Thanks(0)   Quote djlurchg Quote  Post ReplyReply Direct Link To This Post Topic: Google Adsense
    Posted: 10 April 2006 at 5:18am
Upgrading from 6 to 7 to 8 tonight.  Permissions were immediately were set to allow guest access. Because of the Google Adwords inclusion, google search spiders now have access to indexing what I had hoped would remain private information. My mistake though for trusting the software. I closed the hole myself.

Here's a brief sysnopsis of the hole:

Google Adwords found on page.
Code phones home with URL of calling page.
Forum not locked down.
Google indexes URL because it's not locked down.
Formerly hidden info now indexed and viewable by search engines.

Please tell me where I'm wrong. I'd be happy if I was. Seriously.


Edited by djlurchg - 11 April 2006 at 5:36pm
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 10 April 2006 at 11:05am
This is not a security hole, more a case of you not reading the instructions!!

If you had read the upgrade tools on screen instructions you would have seen that because a new permissions system is used in version 8 that once the database upgrade is complete you would need to reset any permissions as they would be set to default permissions.

This also has nothing to do with the Google Ads, that must be left in the software.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 10 April 2006 at 11:06am
Taken from upgrade tool instructions:-

10.    The database update will now be complete, forum Group and Member
permissions may have changed, so please check these before setting your
new forum live.
Back to Top
wistex View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 30 August 2003
Location: United States
Status: Offline
Points: 877
Post Options Post Options   Thanks (0) Thanks(0)   Quote wistex Quote  Post ReplyReply Direct Link To This Post Posted: 11 April 2006 at 1:30am
Also, just FYI.  Google has two bots, the Googlebot and AdSensebot.  AdSensebot visiting won't get you listed in the search engine, and Googlebot won't tell AdSense what ads to display on a page.  They work independently according to Google and from what I've seen on my and other websites.

Now, if you visited with the Google Toolbar, Googlebot would probably show up.  But viewing pages with AdSense on them does not necessarily call the Googlebot.

So you might have lucked out.
Back to Top
djlurchg View Drop Down
Groupie
Groupie


Joined: 31 March 2006
Status: Offline
Points: 40
Post Options Post Options   Thanks (0) Thanks(0)   Quote djlurchg Quote  Post ReplyReply Direct Link To This Post Posted: 11 April 2006 at 4:15pm
No, I didn't.  Content sensitive ads started showing up in spite of me manually adding lockout code (my own Session variable checker). I have contacted Google about the situation and am awaiting a response.

It's a mistake on my part for not securing the forum first. I should have know better. No national secrets, but just privacy concerns.
Back to Top
wistex View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 30 August 2003
Location: United States
Status: Offline
Points: 877
Post Options Post Options   Thanks (0) Thanks(0)   Quote wistex Quote  Post ReplyReply Direct Link To This Post Posted: 11 April 2006 at 4:42pm
It is possible that the AdSensebot did not visit those pages.  I have noticed that sometimes Google will display ads on pages it hasn't looked at yet (such as private pages which are locked to those without permission).  It bases the ads on other pages on the website or based on the URL.  It hasn't actually indexed or seen those pages.  I can tell because 1.) the pages cannot be viewed without being logged in (and with the correct permissions) and 2.) the ads usually are either a.) related to popular subject matter on the website or b.) related to what is in the URL of the page, but not necessarily the content of the page.  Sometimes it guesses so wrong that its obvious it hasn't looked at the content of the page at all.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 11 April 2006 at 5:01pm
Also, I have setup the Google Ads to display an ad from Web Wiz Guides own ad server if a relevant ad is not available.

I often notice that in Private forums, the Private Messaging system, or other pages that Google's Adsense spider can not enter, it still tries to index the page, but most of the time keeps displaying ads servers by Web Wiz Guide's own servers as it can not index the page to get it's content.


Back to Top
djlurchg View Drop Down
Groupie
Groupie


Joined: 31 March 2006
Status: Offline
Points: 40
Post Options Post Options   Thanks (0) Thanks(0)   Quote djlurchg Quote  Post ReplyReply Direct Link To This Post Posted: 11 April 2006 at 5:23pm
borg:

This is more a security concern that I have with google, not WWF. Don't sweat it. As mentioned I am contacting them. I'd like to see a post on Slashdot talking about this "hole" (at least I see it that way).
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.