Special EVENTs

St. Pete Sat, Sep 4th
Pot-Luck Picnic Game Mon, Sep 6th
Sunday Swiss Sun, Sep 12th
Beginner Lessons Tue, Sep 14th, @9:30am - 11:30AM
No Game today Wed, Sep 15th
Home arrow News arrow Web-Site News arrow Vandals and Crooks
logoVandals and Crooks - Brooksville, Florida - Duplicate-Bridge Print E-mail
Pat Clark   
Friday, July 03, 2009
Some of you may wonder why I bother to require usernames and passwords. In the last month or so, there have been four [five as of 7/7/09] attempts to break into The Daily Recap.

Any time the user can enter text in the site, the potential exists that malicious users can enter special text that can circumvent the built-in protection against it. By restricting the entry of comments to registered users, who we trust, that route of trouble-making is blocked.

The comment system is perhaps the most vulnerable software.
You may remember the second comment system I had installed. One of the reasons I had to get rid of it was that a vandal found a vulnerability. He or she tried to damage the site, but I caught on quickly and stopped it.

Another tried to get into my home machine through the "Report to Administrator" function by crafting a message with special characteristics. This didn't work either, but just to be safe, I disabled the Report to Administrator function. You know who I am -- if you need to report something, just report it.

This week, two guys tried to register to see if they would get approved, and thus gain access to the comment system, I presume. One was from Zimbabwe and one from China. [Now one from Russia 7/7/09]  Naturally, their registration was approved -- with full administrative rights. :)
Comments
Search
Only registered users can write comments.

3.26 Copyright (C) 2008 Compojoom.com / Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."

 
< Prev   Next >

LOG IN

Click "Lost Login" below if you don't know your password or username. To register and gain full access to the site, contact any Director or Officer.