Print Page | Close Window

HUGE SECURITY FLAW!! WARNING!!

Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=4314
Printed Date: 02 April 2026 at 6:36am
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: HUGE SECURITY FLAW!! WARNING!!
Posted By: ianturner
Subject: HUGE SECURITY FLAW!! WARNING!!
Date Posted: 18 July 2003 at 5:48am

Well,

Is it possible to delete the default account: administrator/letmein

 

i cant find it anywhere, this is serious!!!




Replies:
Posted By: b_bonnett
Date Posted: 18 July 2003 at 5:55am

No, you just change the username and password through the Admin menu .

At the top of the first page of the admin (i.e. http://www.yoursite.com/forum/admin/frame_set.asp - http://www.yoursite.com/forum/admin/frame_set.asp ) there is the following message:
For security it is highly recommended that you change the Admin Username and Password to stop others messing up your Forums!
(and a link to the appropriate page).

Blair



-------------
Webmaster, http://www.planegallery.net/ - The Plane Gallery
Greetings From Christchurch


Posted By: WebWiz-Bruce
Date Posted: 18 July 2003 at 5:56am

This is not a security problem at all!!!!!

The main admin account can not be deleted.

But if you took the time instead of posting a topic with a heading like this  you would find that you can change the username and password for this account in the admin section of the forum, which you should most certainly do.



-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: b_bonnett
Date Posted: 18 July 2003 at 6:00am

Heh, just too fast a typer for you -boRg-. Remember never to duel with me .

Blair



-------------
Webmaster, http://www.planegallery.net/ - The Plane Gallery
Greetings From Christchurch


Posted By: pam b
Date Posted: 18 July 2003 at 6:05am

before we all go off on a hissy fit, i think he's saying he cant locate it? if its a new forum perhaps upload got screwed and admin login is corrupted?

Try re uploading!



-------------
regards,pam


Posted By: b_bonnett
Date Posted: 18 July 2003 at 6:11am

Don't think so - he's saying he can't find how to delete it (can't because theres no such option). But anyway, if you can't see the link to change the username / password it won't be a database problem - it'll be some of the files in the /admin folder - try re-uploading them.

Blair



-------------
Webmaster, http://www.planegallery.net/ - The Plane Gallery
Greetings From Christchurch


Posted By: ianturner
Date Posted: 18 July 2003 at 6:18am
no it still allows me to log in with administrator/let me in, even when i changed the name and password. ???


Posted By: b_bonnett
Date Posted: 18 July 2003 at 6:28am

You should have said so earlier .

Well, its not a bug in the forum - I can't log in to these forums with the Administrator username, or onto my forums. Can you log in using the renamed account? After you have logged in with the Administrator / letmein, what username does it show in the Active Users? What about if / when you are using the renamed account - what username then?

Blair



-------------
Webmaster, http://www.planegallery.net/ - The Plane Gallery
Greetings From Christchurch


Posted By: WebWiz-Bruce
Date Posted: 18 July 2003 at 6:47am

What you need to do is login as the main admin account and then go to the admin section and change the username and password for the main admin account from there.

If the database then doesn't update with the new details it could be that you don't have sufficient permssions set to update the database, in which case contact your web hosts and ask them to set write permssions on the folder containing the database.

The reason for being upset is that topics in capital letters saying :-

HUGE SECURITY FLAW!! WARNING!!

Dosn't look very good and not particully true, it's more 'I've got a problem trying to change the username and pass for the admin account'



-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: ljamal
Date Posted: 18 July 2003 at 10:08am
Then why not just change the name of the topic?

-------------
L. Jamal Walton

http://www.ljamal.com/" rel="nofollow - L. Jamal Inc : Web/ Print Design and ASP Programming



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net