What the heck?!

Author Message

Noicokuna Niemoge

Wednesday 18 March 2009 1:20:42 am

Hi;

I have just received an information from my engine that a new user has been registered...

It wouldn't be strange if <b>all user information</b> were just... BLANK.

o_O O_O! How is that possible? How can I investigate this?

Shiki soku ze ku...

André R.

Wednesday 18 March 2009 1:41:47 am

Is the mail empty or the user object?
What version are you running? There where some security bugs fixed in 4.0.1 that might relate to this if you are still on 4.0.0.

eZ Online Editor 5: http://projects.ez.no/ezoe || eZJSCore (Ajax): http://projects.ez.no/ezjscore || eZ Publish EE http://ez.no/eZPublish/eZ-Publish-Enterprise-Subscription
@: http://twitter.com/andrerom

Piotrek Karaś

Wednesday 18 March 2009 2:54:14 am

Using ez.no forum search would be a good start, I think this topic has been already covered:
http://ez.no/developer/forum/general/security_issue_anonymous_user_without_user_name/re_security_issue_anonymous_user_without_user

--
Company: mediaSELF Sp. z o.o., http://www.mediaself.pl
eZ references: http://ez.no/partners/worldwide_partners/mediaself
eZ certified developer: http://ez.no/certification/verify/272585
eZ blog: http://ez.ryba.eu

Noicokuna Niemoge

Wednesday 18 March 2009 6:21:40 am

Hmm, my site is running on eZ 4.0.1 ... the whole user object was blank (hehe, of course with an exception of user ID) Well, maybe captcha plugin will work indeed. Thank you for reply. :)

Shiki soku ze ku...

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.