Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Information leak
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Information leak

 Post Reply Post Reply Page  123>
Author
ilnar View Drop Down
Newbie
Newbie


Joined: 02 October 2003
Status: Offline
Points: 9
Post Options Post Options   Thanks (0) Thanks(0)   Quote ilnar Quote  Post ReplyReply Direct Link To This Post Topic: Information leak
    Posted: 02 October 2003 at 5:09am
sorry for my english.

Finded in webwiz forum v 7.01

If i hide forum for no permission users, forum is hided.
But i can get hided forums list in active_topics.asp - select active topics since month - i view list of hided forums and topics in these forums. Why?

I think, what is Information leak in forum.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 02 October 2003 at 5:56am
This is not a bug but done by design to improve performance.

This has also bee bought up many times before if you do a search of the forum.
Back to Top
b_bonnett View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Location: New Zealand
Status: Offline
Points: 275
Post Options Post Options   Thanks (0) Thanks(0)   Quote b_bonnett Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 2:07am

I think there is also a mod for this in the Mod's Forum...

Blair

Webmaster, The Plane Gallery
Greetings From Christchurch
Back to Top
fernan82 View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 17 November 2002
Location: United States
Status: Offline
Points: 362
Post Options Post Options   Thanks (0) Thanks(0)   Quote fernan82 Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 2:13am

Also in the last topic about this ljamal posted a query you can use that I think it should not cause a performance hit as if you would call the permissions function for every topic.... I've haven't yet seen the mod tho and I don't know how it works but I think ljamal's idea is the best way to fix this...

FeRnAN
Back to Top
ilnar View Drop Down
Newbie
Newbie


Joined: 02 October 2003
Status: Offline
Points: 9
Post Options Post Options   Thanks (0) Thanks(0)   Quote ilnar Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 2:23am
i disagree with design to improve performance.
Reasons:
1. if i hide several forum for user -> set of unhidded forums became less when before -> it is more comfortable for SELECT operation to database.
2. don't safe performance to reach the security
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 2:33am
At the present time it will be left as it is becuase the query to get it to run sucessfully was so long and had so many subquries it ment that if you had over around 50 posts in your forum the page took almost a minute to load.

The query in the post that fernan82 mentions that doesn't decrease performance only works if you have values entered into the permissions table for that forum otherwise the query completly fails to return any results, it also over looks the generic forum permisions and also over looks any permisions on that forum for that perticular user and so doesn't work very well.

Incase you still want to try this query it's in a post at:-

http://forums.webwiz.net/forum_posts.asp?TID=2165

But beaware that you need to enter group permisions for each forum and it will over look generic and user permisions.


Edited by -boRg-
Back to Top
ljamal View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Status: Offline
Points: 888
Post Options Post Options   Thanks (0) Thanks(0)   Quote ljamal Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 11:16am
The query I built (see http://forums.webwiz.net/forum_posts.asp?TID=5751) using a stored procedure can return 50 rows and render the page in 1 second or less and could be ported to a simple Access query.

It checks generic permissions on the forum as well as user and group specific permissions. I believe -borg- confused my post with Zamal's. If any one is interested in having a mod created for this, I will consider doing it, but I'm currently in the midst of 4 different projects all due by mid November so it may take some time.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 11:38am
I shall have a look at the stored procedure that you mention.
Back to Top
 Post Reply Post Reply Page  123>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.